MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8719cf81d8557b035fadbeed2c2e14389ef9c6196ececd56c5a98ea49086f925. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 15


Intelligence 15 IOCs YARA 13 File information Comments

SHA256 hash: 8719cf81d8557b035fadbeed2c2e14389ef9c6196ececd56c5a98ea49086f925
SHA3-384 hash: 6363ca2b800be6e634795c23e18dfffabe75be3c323601b43db909f1c808bafa79824158609988cb2ab027f4b6beaa3f
SHA1 hash: c4b8d4360fa3b7a5555750c2beb04e2202b2e07d
MD5 hash: 7d8b0b96f6ac622f490373872364e2ca
humanhash: charlie-mobile-march-mirror
File name:file
Download: download sample
Signature Stealc
File size:785'920 bytes
First seen:2026-05-12 13:12:45 UTC
Last seen:2026-05-12 14:21:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c5a49d74dbeba2b4cb56b327e236efe3 (3 x Stealc)
ssdeep 12288:VrHqQr5XgvVozsROaYzPIP17vMKroQyxBlDetAqxSv:1PgvVqsI0d70eoQyb
Threatray 423 similar samples on MalwareBazaar
TLSH T15FF47C1EF7A612F8D0B7C274CA428553E77278465370968F03E15AAA1F3B6905F3EB21
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-gcleaner exe f MIX4.file Stealc


Avatar
Bitsight
url: http://91.92.241.242/service

Intelligence


File Origin
# of uploads :
2
# of downloads :
200
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
Stealc
Details
Stealc
decrypted strings, an RC4 key, c2 url, url paths, and possibly a missionid and a separate network RC4 key
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-05-12 13:15:05 UTC
Tags:
stealer stealc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
shellcode cobalt packed crypt
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 cmd crypto fingerprint lolbin microsoft_visual_cc overlay stealc stealer
Verdict:
Malicious
Labled as:
Shellcode.Loader.Marte.X.Generic
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-12T10:23:00Z UTC
Last seen:
2026-05-12T12:03:00Z UTC
Hits:
~10
Detections:
Trojan-PSW.Win64.StealC.sb Trojan-PSW.Win32.StealC.v2
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.StealC
Status:
Malicious
First seen:
2026-05-12 13:13:37 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
22 of 24 (91.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc botnet:first discovery spyware stealer
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Malware Config
C2 Extraction:
http://cdntestconnect.com
Unpacked files
SH256 hash:
8719cf81d8557b035fadbeed2c2e14389ef9c6196ececd56c5a98ea49086f925
MD5 hash:
7d8b0b96f6ac622f490373872364e2ca
SHA1 hash:
c4b8d4360fa3b7a5555750c2beb04e2202b2e07d
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
243aa79d0616ce126bd21133e2a06326eeb81104613e298a22d2cffaa292e2e7
Malware family:
Stealc.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Heuristics_ChromeABE
Author:Still
Description:attempts to match instructions related to Chrome App-bound Encryption elevation service; possibly spotted amongst infostealers
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:StealcV2
Author:Still
Description:attempts to match the instructions found in StealcV2
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Stealc_41db1d4d
Author:Elastic Security
Rule name:win_mal_StealC_v2
Author:AlexMM
Description:Detects StealC v2
Rule name:win_stealc_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.stealc.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 8719cf81d8557b035fadbeed2c2e14389ef9c6196ececd56c5a98ea49086f925

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments