MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 960d16e2fdf3b4684b2a60851b0f85cc975adca8e80881f7e869986f06f4f078. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 12


Intelligence 12 IOCs YARA 3 File information Comments

SHA256 hash: 960d16e2fdf3b4684b2a60851b0f85cc975adca8e80881f7e869986f06f4f078
SHA3-384 hash: 370a15b4a25ee731204452648f0691de7a8e575a756acf253caeb03d1bfa5636605e298bd06f2db6642f121b261b171e
SHA1 hash: 63b8553408373041851bcbd6107704277927e2f6
MD5 hash: 5a0217a2a9b0ebab4056da79b99e1322
humanhash: rugby-tango-dakota-aspen
File name:Voicemail.vbs
Download: download sample
Signature Stealc
File size:994 bytes
First seen:2025-10-24 09:06:27 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:9AyqaAXaMjOcB9iwATdrwmzVVdOtEsDY9/L:ebjOg+dj6dDY9/L
TLSH T16211C002FC07D8B60B7356A4DB075529DC65B22B141A5426BA4CDC5A2F309ACB0607F7
Magika vba
Reporter abuse_ch
Tags:Stealc vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
SE SE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
obfuscate vmdetect extens xtreme
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm dropper hacktool obfuscated
Verdict:
Malicious
File Type:
vbs
First seen:
2025-09-19T10:44:00Z UTC
Last seen:
2025-10-22T16:08:00Z UTC
Hits:
~100000
Detections:
Trojan-PSW.Lumma.HTTP.C&C Trojan.Win32.Eb.a Trojan.MSIL.Taskun.sb Trojan.JS.SAgent.sb Backdoor.Agent.HTTP.C&C Trojan.Win32.Crypt.sb UDS:DangerousObject.Multi.Generic Trojan-Downloader.VBS.SLoad.sb Trojan-PSW.Win32.Stelega.sb Trojan-PSW.Win32.Stealer.sb Trojan.MSIL.Crypt.sb Trojan.Agent.TCP.C&C PDM:Trojan.Win32.Generic VHO:Trojan-PSW.Win32.Crypt.gen VHO:Trojan.Win64.Convagent.gen Trojan-PSW.Win32.StealC.v2 Trojan-PSW.MSIL.Agent.sb HEUR:Trojan.MSIL.Taskun.gen VHO:Trojan.Win64.Kryptik.gen HEUR:Trojan.Win64.Generic Trojan-Downloader.JS.SLoad.sb Trojan-Downloader.JS.Cryptoload.sb HEUR:Trojan-Downloader.VBS.SLoad.gen
Result
Threat name:
Amadey, AsyncRAT, Chrome Injector, Clipb
Detection:
malicious
Classification:
spre.troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Contains functionality to disable the Task Manager (.Net Source)
Contains functionality to spread to USB devices (.Net source)
Found malware configuration
Found Tor onion address
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (has network functionality)
Sample uses string decryption to hide its real strings
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected Amadeys Clipper DLL
Yara detected AsyncRAT
Yara detected Chrome Injector
Yara detected Clipboard Hijacker
Yara detected Costura Assembly Loader
Yara detected Dacic
Yara detected Generic MinerDownloader
Yara detected Njrat
Yara detected Quasar RAT
Yara detected Stealc v2
Yara detected TinyNuke
Yara detected XenoRAT
Yara detected XRat
Yara detected XWorm
Behaviour
Behavior Graph:
Gathering data
Verdict:
Malicious
Threat:
VHO:Trojan-PSW.Win32.Crypt
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-19 15:54:12 UTC
File Type:
Text (VBS)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc botnet:tr1pernn defense_evasion discovery spyware stealer themida trojan
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Checks whether UAC is enabled
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Themida packer
Badlisted process makes network request
Downloads MZ/PE file
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Stealc
Stealc family
Malware Config
C2 Extraction:
http://178.16.54.175
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments