MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 17


Intelligence 17 IOCs YARA 18 File information Comments

SHA256 hash: 711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
SHA3-384 hash: 1189a1428da7c19cf334526a39599bf183c80092aac65554d396adff6eb3a0bb2b78464995058675c29d6a86eb788add
SHA1 hash: ec1875f605e5856ab101bfbdb4bdbb29733fc366
MD5 hash: 1a130a9975c3f5ad8977a58fbfe06e18
humanhash: mars-tango-april-solar
File name:sunwukongs.exe
Download: download sample
Signature Stealc
File size:1'128'128 bytes
First seen:2026-04-24 23:13:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 24576:/CUYZcuL5nZWtds61LuD0Ax8M1Phrw5dJYP1T:/3YZcAItd1uHnP1T
Threatray 1 similar samples on MalwareBazaar
TLSH T1963548F850087458D0CAAB750740BB1DB474ACAD6BB00AB3DAB7FE65CB3EA83761D154
TrID 21.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
21.2% (.EXE) Win64 Executable (generic) (6522/11/2)
16.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
14.6% (.EXE) Win32 Executable (generic) (4504/4/1)
6.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon e8f4b269ccd4f0f0 (1 x Stealc, 1 x ZigClipper)
Reporter aachum
Tags:83-217-208-25 dropped-by-OffLoader exe signed Stealc SunWukong

Code Signing Certificate

Organisation:Larson LLC
Issuer:Larson LLC Intermediate CA 1
Algorithm:sha256WithRSAEncryption
Valid from:2025-10-23T13:09:08Z
Valid to:2028-04-23T13:09:08Z
Serial number: 017fa0d19b3f1822
Thumbprint Algorithm:SHA256
Thumbprint: 799020d50fd64ce318c7f74de7b7c1b7bf8a3cbf5a997ead1808959a4fe3d05a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
iamaachum
http://plasteredplayn.com/sunwukongs.exe

Stealc C2: http://83.217.208.25/c3647b9e019546539abe.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
BIGFILMS 8211 INFERNO Pack Create Epic Blockbuster Scenes.exe
Verdict:
Malicious activity
Analysis date:
2026-04-24 23:01:33 UTC
Tags:
auto generic adware advancedinstaller loader stealc stealer takemyfile clickfix delphi inno installer websocket etherhiding arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
cobalt crypt shell sage
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Launching a process
Сreating synchronization primitives
Connecting to a non-recommended domain
Connection attempt
Sending an HTTP POST request
Creating a window
Launching a service
Creating a file
DNS request
Searching for synchronization primitives
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive packed signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-04-24T11:43:00Z UTC
Last seen:
2026-04-25T11:39:00Z UTC
Hits:
~100
Detections:
Trojan-PSW.Win64.Stealc.on BSS:Trojan.Win32.Generic Trojan-PSW.Win64.StealC.sb
Result
Threat name:
EtherHiding, Stealc v2
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
AI detected suspicious PE digital signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Injects a PE file into a foreign processes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Self deletion via cmd or bat file
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected EtherHiding
Yara detected Stealc v2
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1904528 Sample: sunwukongs.exe Startdate: 25/04/2026 Architecture: WINDOWS Score: 100 44 k8s-ingressn-bscmainn-3f9a19480b-888004326.us-east-1.elb.amazonaws.com 2->44 46 dcdivas.com 2->46 48 2 other IPs or domains 2->48 60 Suricata IDS alerts for network traffic 2->60 62 Found malware configuration 2->62 64 Antivirus detection for URL or domain 2->64 66 7 other signatures 2->66 9 sunwukongs.exe 3 23 2->9         started        14 0eWwfjJD.exe 2->14         started        16 0eWwfjJD.exe 2->16         started        signatures3 process4 dnsIp5 56 83.217.208.25, 49694, 80 INF-NET-ASRU Russian Federation 9->56 58 dcdivas.com 158.106.138.96, 443, 49712 PRIVATESYSTEMSUS United States 9->58 40 C:\Users\user\AppData\...\qU4LgnRekbN2.exe, PE32+ 9->40 dropped 42 C:\Users\user\AppData\Local\...\Decred[1].exe, PE32+ 9->42 dropped 76 Found many strings related to Crypto-Wallets (likely being stolen) 9->76 78 Self deletion via cmd or bat file 9->78 80 Tries to harvest and steal browser information (history, passwords, etc) 9->80 86 8 other signatures 9->86 18 qU4LgnRekbN2.exe 9->18         started        23 Acrobat.exe 55 9->23         started        25 cmd.exe 9->25         started        27 4 other processes 9->27 82 Multi AV Scanner detection for dropped file 14->82 84 Unusual module load detection (module proxying) 14->84 file6 signatures7 process8 dnsIp9 50 celebration-internet.cc 172.67.131.195, 443, 49714, 49715 CLOUDFLARENETUS United States 18->50 52 k8s-ingressn-bscmainn-3f9a19480b-888004326.us-east-1.elb.amazonaws.com 54.205.242.99, 443, 49713 AMAZON-AESUS United States 18->52 38 C:\Users\user\AppData\...\0eWwfjJD.exe, PE32+ 18->38 dropped 68 Multi AV Scanner detection for dropped file 18->68 70 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 18->70 72 Found stalling execution ending in API Sleep call 18->72 74 Found direct / indirect Syscall (likely to bypass EDR) 18->74 29 AcroCEF.exe 105 23->29         started        31 conhost.exe 25->31         started        33 timeout.exe 25->33         started        file10 signatures11 process12 process13 35 AcroCEF.exe 5 29->35         started        dnsIp14 54 23.197.44.135, 443, 49704 AKAMAI-ASUS United States 35->54
Gathering data
Threat name:
Win32.Spyware.Stealc
Status:
Suspicious
First seen:
2026-04-24 16:56:33 UTC
File Type:
PE (Exe)
Extracted files:
18
AV detection:
16 of 38 (42.11%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:stealc adware defense_evasion discovery persistence spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Detects Stealc stealer Version 2
Family: Stealc
Unpacked files
SH256 hash:
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
MD5 hash:
1a130a9975c3f5ad8977a58fbfe06e18
SHA1 hash:
ec1875f605e5856ab101bfbdb4bdbb29733fc366
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Detections:
win_stealc_auto
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
243aa79d0616ce126bd21133e2a06326eeb81104613e298a22d2cffaa292e2e7
4ed3931ab5bddd24ce23fd0d5546ae45b52a0cd0124afe7cb3692a56510ac1ed
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
0c16963f43604246e81f006d1f7df0a7258b36b929252c1502d92fea573d86aa
39e07fb60fbf206b06d1b5b2b74848d9d393c6bd66fd11e003436cd7ee6b5788
cea15fe7edd6b1b26f4326901781c16034ebe195cdb89ede2338e91c1d7ce6ac
16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
798b6a521d6763f1b684f6d2a6c91e3eab92425dbd9265372a132aba1e213c5f
f901e1a138129e819f4759f30102e94a9987409f0978c9505c2d679d1a0880e2
ee2169a39bff9da6e3152e80a13b0bd9dc1e55c3ab191ca387bf8ede1ebdcd8d
8802527c317068b4b824d7bc1843dee0e52e047c7fae4997d577c11349c1ef01
de5b161afabe16c6de6a329454fb6bc2503a016431881e1a152b1ab755afc447
83dc123d31c5be60e541eaee0b9808bf895988fe9654a56c9d4f16caba9a44c0
4a997d7569f5d3ff1b7435712afac59b83a2b91ed57bd7790b3dfb7212e652e6
7e9edf7a77d11ff29677dd2d1af644930b7b5f8c8632b4fd393d06c0e48149b3
d490ac7dc0854bea4728b0a4497727fdf74a8b1a4a9dc10d040c71b1814586bd
3e79cc9aee9a74b4fb131db1222d3649db21edf776e071737a0644e69c62dba6
dff83bede85f33f1229e21cabc1b159f8b11230c9b4b6d2e46432d7094c7a917
5c61c977440dd7e870c1a63037558dd3fc2c41c8fd9d6ab67acff1c7d35abe01
8eae625c47b072f1f34afb5033d51a3d17820322f8bae6cbd5fbd83ba2d8c95d
c12fd900f32944623823f5087ef3eb146586a9339c0262333ac9c9bc08c06e84
41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478
SH256 hash:
7d15d27ba340e3c5f48a9defd8fa94b9d2bf56f124551dd9c93d5c99cc0fe5b8
MD5 hash:
4d0c0ddedddc12d3bfa20485c6eca76a
SHA1 hash:
8684e6bcda3f37ef2c180ba106e04c4e08588f6a
Detections:
win_stealc_auto stealc
Malware family:
Stealc.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:Heuristics_ChromeABE
Author:Still
Description:attempts to match instructions related to Chrome App-bound Encryption elevation service; possibly spotted amongst infostealers
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:StealcV2
Author:kevoreilly
Description:Stealc V2 Payload
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Stealc_41db1d4d
Author:Elastic Security
Rule name:win_stealc_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.stealc.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685

(this sample)

  
Dropped by
OffLoader
  
Delivery method
Distributed via web download

Comments