MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82bee273347b6e752d229b8fd3e5fed68cfc49f0f7145a8e457bf3ca0c91b5df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RustyStealer


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: 82bee273347b6e752d229b8fd3e5fed68cfc49f0f7145a8e457bf3ca0c91b5df
SHA3-384 hash: c12422c18a1a60a817367b640c5de65390431295e05e33373e320cd0a1bd9c61af3868723f5eac970eeb716ec9383140
SHA1 hash: 5c606f8197926499d2787b4a1ff7d7b9230191ee
MD5 hash: c4885e5bf108e892c5d0e0b644b75ca8
humanhash: wolfram-angel-zebra-virginia
File name:file
Download: download sample
Signature RustyStealer
File size:5'905'408 bytes
First seen:2026-08-29 12:54:05 UTC
Last seen:2026-08-30 18:06:46 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 4cea7ae85c87ddc7295d39ff9cda31d1 (103 x LummaStealer, 85 x RedLineStealer, 62 x Rhadamanthys)
ssdeep 98304:SSt2ufUg9K6BNufl5YecdyaCrIeXRqPuiAtaQlZFYz4G3HVkUxuuKgDhBRCg:SSBULcNolyetaCrDRqmlMQlo4G3KgDh
TLSH T1B856337231EE816BE5615F7B01FA8B4FF6713C361F2489AF5790692C38A1781903978E
TrID 45.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
18.0% (.EXE) Win64 Executable (generic) (6522/11/2)
13.9% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.6% (.ICL) Windows Icons Library (generic) (2059/9)
5.6% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon f1ccf8d9e6e2e8f0 (1 x RustyStealer)
Reporter Bitsight
Tags:dropped-by-gcleaner exe RustyStealer U UNIQ.file


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
5
# of downloads :
167
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
Archives AutoIt
Details
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-29 13:04:15 UTC
Tags:
autoit stealer loader auto-reg stealc rust

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process with a hidden window
Creating a process from a recently created file
Creating a window
DNS request
Unauthorized injection to a recently created process
Deleting a recently created file
Сreating synchronization primitives
Creating a file
Launching a process
Using the Windows Management Instrumentation requests
Launching the process to create tasks for the scheduler
Unauthorized injection to a recently created process by context flags manipulation
Launching a tool to kill processes
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug at autoit CAB expired-cert explorer fingerprint installer installer installer-heuristic keylogger lolbin microsoft_visual_cc packed reconnaissance rundll32 runonce sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-29T10:31:00Z UTC
Last seen:
2026-08-30T05:50:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
6 match(es)
Tags:
AutoIt CAB:COMPRESSION:LZX Decompiled Executable PDB Path PE (Portable Executable) PE File Layout Suspect Win 64 Exe x64
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-08-29 12:54:28 UTC
File Type:
PE+ (Exe)
Extracted files:
67
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion execution persistence spyware stealer
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Unpacked files
SH256 hash:
82bee273347b6e752d229b8fd3e5fed68cfc49f0f7145a8e457bf3ca0c91b5df
MD5 hash:
c4885e5bf108e892c5d0e0b644b75ca8
SHA1 hash:
5c606f8197926499d2787b4a1ff7d7b9230191ee
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RustyStealer

Executable exe 82bee273347b6e752d229b8fd3e5fed68cfc49f0f7145a8e457bf3ca0c91b5df

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments