MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 14


Intelligence 14 IOCs YARA 4 File information Comments

SHA256 hash: 41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478
SHA3-384 hash: ddfd782f92432bb2466800bba244324904d77c849ad90c8e30c6cd3c1b7bfe98f1ebe66b09bc82e457aabaa047b2551e
SHA1 hash: 687ce6f9816eb8ad80f532ba2c832cf5476bdca0
MD5 hash: cdf69e3345e9e518a03633c28358268b
humanhash: lemon-jig-victor-carbon
File name:FLStudio2025_v248_Win.exe
Download: download sample
Signature Stealc
File size:1'476'608 bytes
First seen:2026-08-19 00:35:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'194 x AgentTesla, 20'345 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 24576:h4d+K3jGBJ8sRJWmMFbXZUUlwvuQOKs/NvRDmZ6fcmAOEiDwrggF8bwQR+io:h4d+6jG8sRJWNZTlFx/9RDOmjcMuQRa
TLSH T174651258336BDC06C5295F741C31E3F81FB85D98A561E2039EEABFEBB935A0068152C7
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter aachum
Tags:exe Stealc svhost-update-service-casa


Avatar
iamaachum
https://omantel.help/fast.php

Stealc C2:
svhost-update-service.casa (23.94.252.4:443)

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-19 00:50:56 UTC
Tags:
auto-reg stealc stealer netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated packed vbnet
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Creates / moves files in alternative data streams (ADS)
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Deletes itself after installation
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Stealc
Yara detected Stealc v2
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1960038 Sample: FLStudio2025_v248_Win.exe Startdate: 19/08/2026 Architecture: WINDOWS Score: 100 50 svhost-update-service.casa 2->50 52 mitraperijinan.co.id 2->52 64 Suricata IDS alerts for network traffic 2->64 66 Malicious sample detected (through community Yara rule) 2->66 68 Antivirus detection for URL or domain 2->68 70 14 other signatures 2->70 8 FLStudio2025_v248_Win.exe 1 6 2->8         started        12 powershell.exe 11 2->12         started        14 powershell.exe 2->14         started        signatures3 process4 file5 42 C:\Users\user\AppData\Roaming\KYg.exe, PE32 8->42 dropped 44 C:\Users\...\FLStudio2025_v248_Win.exe.log, ASCII 8->44 dropped 72 Found many strings related to Crypto-Wallets (likely being stolen) 8->72 74 Creates autostart registry keys with suspicious values (likely registry only malware) 8->74 76 Creates an autostart registry key pointing to binary in C:\Windows 8->76 78 4 other signatures 8->78 16 FLStudio2025_v248_Win.exe 87 8->16         started        21 powershell.exe 23 8->21         started        23 conhost.exe 12->23         started        25 conhost.exe 14->25         started        signatures6 process7 dnsIp8 46 mitraperijinan.co.id 54.39.70.216, 443, 49725 OVHFR Canada 16->46 48 svhost-update-service.casa 23.94.252.4, 443, 49702, 49704 DEDIK-IODEDIKSERVICESLIMITEDDEDIKIOGB United States 16->48 40 C:\Users\user\AppData\...\uQbwlhdCFGdj.exe, PE32+ 16->40 dropped 54 Creates / moves files in alternative data streams (ADS) 16->54 56 Found many strings related to Crypto-Wallets (likely being stolen) 16->56 58 Tries to harvest and steal browser information (history, passwords, etc) 16->58 62 6 other signatures 16->62 27 uQbwlhdCFGdj.exe 16->27         started        30 msedge.exe 16->30         started        32 msedge.exe 16->32         started        38 4 other processes 16->38 60 Loading BitLocker PowerShell Module 21->60 34 WmiPrvSE.exe 21->34         started        36 conhost.exe 21->36         started        file9 signatures10 process11 signatures12 80 Multi AV Scanner detection for dropped file 27->80
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.40 Win 32 Exe x86
Threat name:
Win32.Trojan.PhantomStealer
Status:
Malicious
First seen:
2026-08-19 00:37:37 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478
MD5 hash:
cdf69e3345e9e518a03633c28358268b
SHA1 hash:
687ce6f9816eb8ad80f532ba2c832cf5476bdca0
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Detections:
win_stealc_auto
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
243aa79d0616ce126bd21133e2a06326eeb81104613e298a22d2cffaa292e2e7
4ed3931ab5bddd24ce23fd0d5546ae45b52a0cd0124afe7cb3692a56510ac1ed
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
0c16963f43604246e81f006d1f7df0a7258b36b929252c1502d92fea573d86aa
39e07fb60fbf206b06d1b5b2b74848d9d393c6bd66fd11e003436cd7ee6b5788
cea15fe7edd6b1b26f4326901781c16034ebe195cdb89ede2338e91c1d7ce6ac
16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
798b6a521d6763f1b684f6d2a6c91e3eab92425dbd9265372a132aba1e213c5f
f901e1a138129e819f4759f30102e94a9987409f0978c9505c2d679d1a0880e2
ee2169a39bff9da6e3152e80a13b0bd9dc1e55c3ab191ca387bf8ede1ebdcd8d
8802527c317068b4b824d7bc1843dee0e52e047c7fae4997d577c11349c1ef01
de5b161afabe16c6de6a329454fb6bc2503a016431881e1a152b1ab755afc447
83dc123d31c5be60e541eaee0b9808bf895988fe9654a56c9d4f16caba9a44c0
4a997d7569f5d3ff1b7435712afac59b83a2b91ed57bd7790b3dfb7212e652e6
7e9edf7a77d11ff29677dd2d1af644930b7b5f8c8632b4fd393d06c0e48149b3
d490ac7dc0854bea4728b0a4497727fdf74a8b1a4a9dc10d040c71b1814586bd
3e79cc9aee9a74b4fb131db1222d3649db21edf776e071737a0644e69c62dba6
dff83bede85f33f1229e21cabc1b159f8b11230c9b4b6d2e46432d7094c7a917
5c61c977440dd7e870c1a63037558dd3fc2c41c8fd9d6ab67acff1c7d35abe01
8eae625c47b072f1f34afb5033d51a3d17820322f8bae6cbd5fbd83ba2d8c95d
c12fd900f32944623823f5087ef3eb146586a9339c0262333ac9c9bc08c06e84
41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478
SH256 hash:
6ac81517d87b0b157487a1ffe060f26c4c7e858dc9a4223fa756c68d9e030767
MD5 hash:
0c07212a88c1123d616fe2f06dabdde6
SHA1 hash:
2aa2f82f45b8b728f1eb493b8803e673e2fb7baa
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
49baffd57a2753b9b97346e3d9b7c896900bdf92e9cacc5c6e1526c90e6e696d
MD5 hash:
407f7273447577aaaa1abe8ac8df8876
SHA1 hash:
62672d83b00e66016789a758c7133b1b1b55137d
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
bd272ade659825489680409b8203fa0849a67e415b3b27b3a84af278c11ae94b
MD5 hash:
d71d6dc27d6a6ebb77b89f4c4d9916d5
SHA1 hash:
8c87820d733b32f62a8beaeda7f0fac3d6aff6b1
Detections:
win_stealc_auto
Malware family:
Stealc.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478

(this sample)

  
Delivery method
Distributed via web download

Comments