🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ff506f881ba60dce7f16d35a7a460f0bb3899acd6a52ba9a6604f25e2a6ff4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 17


Intelligence 17 IOCs YARA 14 File information Comments

SHA256 hash: 4ff506f881ba60dce7f16d35a7a460f0bb3899acd6a52ba9a6604f25e2a6ff4e
SHA3-384 hash: cc382a8b7c13cfbf3e068472971a4377d6c303ca9fbeb85cb4e028dc84e46f2d92203bae09226a87d7dc74c9a58bc95e
SHA1 hash: 7af636420275bc31bb339f174b10d43a3b9d1498
MD5 hash: e13186fb08baa9cd0e32334a594bfaba
humanhash: seventeen-texas-five-happy
File name:4ff506f881ba60dce7f16d35a7a460f0bb3899acd6a52ba9a6604f25e2a6ff4e
Download: download sample
Signature Stealc
File size:13'224'960 bytes
First seen:2025-09-12 15:49:48 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d2041a85a3c9c69fcd9bb51fef19f6db (2 x Stealc)
ssdeep 98304:7F6EtgLXrpozloF6EtgLXrpVX2jHiFKVlkwREnBAAh21RX2T0WV2Z:7UR7popoUR7pIjselcnBgJDWQ
Threatray 3 similar samples on MalwareBazaar
TLSH T102D6D015FD268089ECE34135BFB5C121D8733D27DF28663F81DC8D981925CEE6A2E16A
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 44ccb2a2d4e871b2 (1 x QuasarRAT, 1 x Stealc)
Reporter mazznrz
Tags:exe Stealc

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
ID ID
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
4ff506f881ba60dce7f16d35a7a460f0bb3899acd6a52ba9a6604f25e2a6ff4e
Verdict:
Malicious activity
Analysis date:
2025-09-12 16:00:44 UTC
Tags:
stealc stealer auto-reg diamotrix clipper telegram lumma amadey botnet

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect emotet
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %AppData% directory
Creating a process from a recently created file
Сreating synchronization primitives
Creating a file in the %temp% subdirectories
Creating a window
Sending an HTTP POST request to an infection source
Searching for synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Launching a process
Creating a file
Moving a recently created file
DNS request
Connection attempt
Sending a custom TCP request
Loading a suspicious library
Using the Windows Management Instrumentation requests
Connection attempt to an infection source
Unauthorized injection to a recently created process by context flags manipulation
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 cmd fingerprint lolbin microsoft_visual_cc packed
Verdict:
Malicious
Labled as:
Dropper.Generic.Shellcode.Loader.Marte.X
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-09-04T14:21:00Z UTC
Last seen:
2025-09-04T14:21:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Spyware.Lummastealer
Status:
Malicious
First seen:
2025-09-05 03:27:32 UTC
File Type:
PE (Exe)
Extracted files:
27
AV detection:
29 of 37 (78.38%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:lumma family:stealc botnet:rtbl botnet:xufckv discovery persistence spyware stealer
Behaviour
Enumerates system info in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Lumma Stealer, LummaC
Lumma family
Stealc
Stealc family
Malware Config
C2 Extraction:
http://176.46.152.46
https://t.me/quincyplayer6
https://starexs.bet/tskx
https://mastwin.in/qsaz
https://digitbasket.com/pqox
https://voando26.com/iwnn
https://iaed.link/ndbh
https://pyscalp.com/iqop
https://lzh.fr/mnsn
https://streamin.style/iqzb
https://phoenix-brands.dev/qyzb
Verdict:
Malicious
Tags:
Win.Malware.Generic-9871124-0
YARA:
n/a
Unpacked files
SH256 hash:
4ff506f881ba60dce7f16d35a7a460f0bb3899acd6a52ba9a6604f25e2a6ff4e
MD5 hash:
e13186fb08baa9cd0e32334a594bfaba
SHA1 hash:
7af636420275bc31bb339f174b10d43a3b9d1498
SH256 hash:
88c7bd96ef6bb633c35e1828678b2303c44a17aeb78a0746c5d5fd41222f1ded
MD5 hash:
7e5c58528455d4fb16ea259ddcee0d19
SHA1 hash:
46b8093816d662c1e85ac3af1fb04e92076d6b3f
SH256 hash:
7e6dc92e535f06db876097f68a52ec9ee2b119473a780033e03c5d4be4091a7f
MD5 hash:
e0b89d4714c859df9a6a25a80c67ea7a
SHA1 hash:
e810286c8ac38a080cf2dfcc97ae0a7e5eb0c733
SH256 hash:
ad52e5b2d0b1b65293d176475f983d84a59880f08a651a5073dfb6c32505ae01
MD5 hash:
13bd6acefb142dbc5778cb86fdd42887
SHA1 hash:
b4b78257a9d4e235cfc8327482c1d54b2516d98f
Malware family:
Stealc.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:aachum_Stealcv2
Author:aachum
Description:Detects new version of Stealc.
Rule name:Borland
Author:malware-lu
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Heuristics_ChromeABE
Author:Still
Description:attempts to match instructions related to Chrome App-bound Encryption elevation service; possibly spotted amongst infostealers
Rule name:INDICATOR_SUSPICIOUS_ReflectiveLoader
Author:ditekSHen
Description:Detects Reflective DLL injection artifacts
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:ReflectiveLoader
Author:Florian Roth (Nextron Systems)
Description:Detects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommended
Reference:Internal Research
Rule name:StealcV2
Author:Still
Description:attempts to match the instructions found in StealcV2
Rule name:StealcV2
Author:kevoreilly
Description:Stealc V2 Payload

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments