MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4c01725c8366f6efe1deeb4f7a718c1b0dca7e200c1a4fe8b12a2a52e234aeb1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AuraStealer


Vendor detections: 17


Intelligence 17 IOCs YARA 11 File information Comments

SHA256 hash: 4c01725c8366f6efe1deeb4f7a718c1b0dca7e200c1a4fe8b12a2a52e234aeb1
SHA3-384 hash: 1afd5e96f8e19e3a4950cc42cad8a3fd0ee5d045f0829ce339e531f7b1bbe0a76d0694ba4a12475560f83baf56e4d37b
SHA1 hash: 7bd52231171e19cbeda295fcef15f0a0adf1f14b
MD5 hash: 879e77a29d0ed7f760a3f2ed83f87779
humanhash: november-april-cola-colorado
File name:file
Download: download sample
Signature AuraStealer
File size:150'528 bytes
First seen:2025-12-25 14:10:08 UTC
Last seen:2025-12-26 00:29:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 4cea7ae85c87ddc7295d39ff9cda31d1 (103 x LummaStealer, 85 x RedLineStealer, 62 x Rhadamanthys)
ssdeep 1536:irae78zjORCDGwfdCSog01313zIs5gvhJh5tyhQYliY5h:KahKyd2n31Dh5nh
Threatray 72 similar samples on MalwareBazaar
TLSH T1AFE3F92676E4A0B6E4B5137889F6825356317CA05F7692FF32C4B7BD1E326C1A431B0B
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10522/11/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter Bitsight
Tags:AURAStealer c dropped-by-gcleaner exe ONE.file


Avatar
Bitsight
url: http://194.38.20.224/service

Intelligence


File Origin
# of uploads :
11
# of downloads :
126
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
Archives
Details
Archives
an extracted Cabinet archive from the resources and SFX parameters
Malware family:
n/a
ID:
1
File name:
file
Verdict:
Malicious activity
Analysis date:
2025-12-25 14:10:46 UTC
Tags:
stego payload ta558 apt stegocampaign loader reverseloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
xtreme shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context base64 CAB cmd installer installer lolbin microsoft_visual_cc obfuscated powershell rundll32 runonce sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2025-12-25T11:27:00Z UTC
Last seen:
2025-12-27T03:25:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Multi.Stego.gen Trojan-Downloader.SLoad.TCP.ServerRequest Trojan.JS.SAgent.sb Trojan-Downloader.PowerShell.NanoShield.sb Trojan.MSIL.Agentc.a HEUR:Trojan.Script.Generic
Verdict:
Malware
YARA:
5 match(es)
Tags:
CAB:COMPRESSION:LZX DeObfuscated Executable Obfuscated PDB Path PE (Portable Executable) PE File Layout T1059.005 VBScript Win 64 Exe WScript.Network WScript.Shell x64
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-12-25 14:10:24 UTC
File Type:
PE+ (Exe)
Extracted files:
70
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
aura_stealer
Score:
  10/10
Tags:
family:aura_stealer discovery execution persistence stealer
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
AuraStealer
Aura_stealer family
Detects AuraStealer stealer
Unpacked files
SH256 hash:
4c01725c8366f6efe1deeb4f7a718c1b0dca7e200c1a4fe8b12a2a52e234aeb1
MD5 hash:
879e77a29d0ed7f760a3f2ed83f87779
SHA1 hash:
7bd52231171e19cbeda295fcef15f0a0adf1f14b
Malware family:
AuraStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AuraStealer
Author:enzok
Description:AuraStealer Payload
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:NET
Author:malware-lu
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:win_lumma_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.lumma.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AuraStealer

Executable exe 4c01725c8366f6efe1deeb4f7a718c1b0dca7e200c1a4fe8b12a2a52e234aeb1

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments