🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46f605598488ded49527e9e6a3ea045c817833aecfb527c8f213ee0e0527a130. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 15


Intelligence 15 IOCs 1 YARA 4 File information Comments

SHA256 hash: 46f605598488ded49527e9e6a3ea045c817833aecfb527c8f213ee0e0527a130
SHA3-384 hash: 7632c0e0fae42e7b873ac26615e070713dabe9acd410ccc568857ba06e9e997eef4c5b7a911362f0ef488157bf862f05
SHA1 hash: 97a36aa533587627b8f0222cae1a72057063d22c
MD5 hash: a619be1e2c1936d372e94dbc946d23f8
humanhash: vegan-paris-washington-potato
File name:A619BE1E2C1936D372E94DBC946D23F8.exe
Download: download sample
Signature Stealc
File size:8'518'193 bytes
First seen:2026-02-12 10:30:18 UTC
Last seen:2026-02-12 11:17:05 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 40ab50289f7ef5fae60801f88d4541fc (81 x ValleyRAT, 59 x Gh0stRAT, 42 x OffLoader)
ssdeep 98304:nrRil0+nj3Rs61cgLoZXcG39SVkxsmlA8/Ufj2s3Fv4XHdDKYnZqqLrzMyydM:rRQe61nLo2wykx5N/Mj2CARTUmyu
TLSH T15486028BD38A2316E49137352D1AB154B33BF07442C6A91294ADE46C7E57CA83A3F7F4
TrID 60.0% (.EXE) Inno Setup installer (107240/4/30)
23.2% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
5.8% (.EXE) Win64 Executable (generic) (10522/11/4)
3.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
2.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon e498e8f8f8e896e0 (1 x RemcosRAT, 1 x Stealc)
Reporter abuse_ch
Tags:exe Stealc


Avatar
abuse_ch
Stealc C2:
http://89.208.106.114/7e1669c87b2a4f93.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://89.208.106.114/7e1669c87b2a4f93.php https://threatfox.abuse.ch/ioc/1746823/

Intelligence


File Origin
# of uploads :
2
# of downloads :
216
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
_46f605598488ded49527e9e6a3ea045c817833aecfb527c8f213ee0e0527a130.exe
Verdict:
Malicious activity
Analysis date:
2026-02-12 10:32:06 UTC
Tags:
anti-evasion delphi inno installer stealc stealer upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
injection dropper virus
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
DNS request
Using the Windows Management Instrumentation requests
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm base64 crypt crypto embarcadero_delphi evasive expand fingerprint inno installer installer installer-heuristic lolbin packed soft-404
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-02-08T16:09:00Z UTC
Last seen:
2026-02-12T21:20:00Z UTC
Hits:
~100
Detections:
Trojan.Win32.DLLhijack.aefv
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected AntiVM3
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.DllHijack
Status:
Suspicious
First seen:
2026-02-09 12:50:58 UTC
File Type:
PE (Exe)
Extracted files:
121
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc botnet:v12 defense_evasion discovery installer privilege_escalation stealer upx
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Access Token Manipulation: Create Process with Token
Enumerates physical storage devices
System Location Discovery: System Language Discovery
UPX packed file
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Stealc
Stealc family
Malware Config
C2 Extraction:
http://89.208.106.114
Unpacked files
SH256 hash:
46f605598488ded49527e9e6a3ea045c817833aecfb527c8f213ee0e0527a130
MD5 hash:
a619be1e2c1936d372e94dbc946d23f8
SHA1 hash:
97a36aa533587627b8f0222cae1a72057063d22c
SH256 hash:
51ce8a144eb6ad141b94eda1f19d42fb2175f59f4f175f7695433e6ef6801b95
MD5 hash:
27d60098c7e8b707a5f6b6f9290e928f
SHA1 hash:
20e48da466b38b15715e6299bfd4bb93109086cd
SH256 hash:
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
MD5 hash:
e4211d6d009757c078a9fac7ff4f03d4
SHA1 hash:
019cd56ba687d39d12d4b13991c9a42ea6ba03da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:pe_detect_tls_callbacks
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments