MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 777a54bfc70de07fee25e9f2d527a242fb7681f6e86231811f69f030ab00c961. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Stealc
Vendor detections: 16
| SHA256 hash: | 777a54bfc70de07fee25e9f2d527a242fb7681f6e86231811f69f030ab00c961 |
|---|---|
| SHA3-384 hash: | aad3d10b9e1d67330b25dbdfdf4f14a234c32c3e4f5c767a4e4623ad99b8d65aff4703286555e85c1f05e6488dabd928 |
| SHA1 hash: | aade1d44df4950bf807fe44c30ef419e2a9a22b6 |
| MD5 hash: | 298c2dd860d8e3133d9cf250741eeeaa |
| humanhash: | princess-seven-saturn-quebec |
| File name: | file |
| Download: | download sample |
| Signature | Stealc |
| File size: | 424'448 bytes |
| First seen: | 2024-09-21 13:07:43 UTC |
| Last seen: | 2024-09-21 13:11:05 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | aa1df04aa31b8b76e6674a21e4ac0295 (1 x Stealc, 1 x Tofsee) |
| ssdeep | 6144:3N1zTVURDtYOCQSiumTaYkK2xspAbtlXS5FXCnFk:9FTVUFtpCnpfKxAzXESC |
| TLSH | T19E948E6342A17E45F9224F728E1EE6E936DFF9608E1977271214EA1F24713F2D163B20 |
| TrID | 37.3% (.EXE) Win64 Executable (generic) (10523/12/4) 17.8% (.EXE) Win16 NE executable (generic) (5038/12/1) 15.9% (.EXE) Win32 Executable (generic) (4504/4/1) 7.3% (.ICL) Windows Icons Library (generic) (2059/9) 7.2% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 103260c0c488c800 (1 x Stealc) |
| Reporter | |
| Tags: | exe Stealc |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
9d31c2bafa4ceb5151e4eb8f6b8ed45c7f131d2a74f382a8f577aab7444a4cbd
9c13d9a449fa5fbc115dc21ac0f8854fc68790685f6cf88e697692d1c6a8117a
c3b324d0b36b98ea3cd50498ed0c5b5b850b80a1521d8898626d736375977ec1
40df2b2bfe36a9954e3b4ee4a5aa089e166ea61da0d933f973a69b6f8245d16d
1996a7a79e6ce7906689e931fcd89febd9be1f6d4abe18a9116a5c3425fd5891
7fad1d5bf3c2d3837f16a6fdf5f5be2af4bcdb2033d4b5124746f642affa00ae
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | BitcoinAddress |
|---|---|
| Author: | Didier Stevens (@DidierStevens) |
| Description: | Contains a valid Bitcoin address |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::FindNextVolumeMountPointW KERNEL32.dll::LoadLibraryW KERNEL32.dll::LoadLibraryExA KERNEL32.dll::GetStartupInfoW KERNEL32.dll::GetDiskFreeSpaceExW |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::WriteConsoleW KERNEL32.dll::PeekConsoleInputW KERNEL32.dll::SetStdHandle KERNEL32.dll::GetConsoleDisplayMode KERNEL32.dll::GetConsoleAliasExesLengthA KERNEL32.dll::GetConsoleAliasExesA KERNEL32.dll::GetConsoleCP KERNEL32.dll::GetConsoleMode |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CreateHardLinkA KERNEL32.dll::CreateFileMappingA KERNEL32.dll::CreateFileW KERNEL32.dll::GetWindowsDirectoryW KERNEL32.dll::GetFileAttributesA KERNEL32.dll::SetVolumeMountPointW |
| WIN_HTTP_API | Uses HTTP services | WINHTTP.dll::WinHttpConnect |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.