MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 981971db686e5a41abb733e19246a02f12d9f38d84c2b8b3a2f33f93aa5e5d76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SantaStealer


Vendor detections: 3


Intelligence 3 IOCs YARA 3 File information Comments

SHA256 hash: 981971db686e5a41abb733e19246a02f12d9f38d84c2b8b3a2f33f93aa5e5d76
SHA3-384 hash: e34c2ae936e197afb5ef44c29cad23fc138d1117e33cd0dba6738e49148e8b6dc4e43fb6d00b87ab9e3d93033cd340d1
SHA1 hash: 55fd6836fec4146feb0b8c6affe368c1a0b47911
MD5 hash: 8d2cd221772f2f2e46e13d302a0e67bb
humanhash: early-muppet-wisconsin-carpet
File name:StakePredictorFull-2026.rar
Download: download sample
Signature SantaStealer
File size:19'332'286 bytes
First seen:2026-02-03 20:01:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: stake2026
ssdeep 393216:+WagSdFGt3eplTC2i7hyOibxvrIYKHFh+X/NEhs:+WagWFGRe/TUJgxvcYKHL+X/NEu
TLSH T12D1733CDE84A973E705E4EAB02F8FA8FD581033A0D4F061964DDDD82117A27BF592726
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter aachum
Tags:pw-stake2026 rar SantaStealer


Avatar
iamaachum
https://www.mediafire.com/file/uqp96mkdsnq0cfv/StakePredictorFull-2026.rar/file

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
ES ES
File Archive Information

This file archive contains 23 file(s), sorted by their relevance:

File name:ini.bin
File size:1'663'189 bytes
SHA256 hash: 2b6ac0d6e2c2952334c6035bf4985db89aec8e2d31b0c2b73b739d209dd6e5da
MD5 hash: 897e753e2615fbb55cce792f6119e419
MIME type:application/octet-stream
Signature SantaStealer
File name:mvc.bin
File size:1'065'479 bytes
SHA256 hash: eae1ce7391e50e8e30ba719f290eae9bee0c7f8aea7d552237d48fac57ea3204
MD5 hash: 5d4444ba4fdaad81438dd06877e30b30
MIME type:application/octet-stream
Signature SantaStealer
File name:analyzer.cpp
File size:464'679 bytes
SHA256 hash: 2095a614a32dea7350a409afb63827d018ebfdb7cb10792ef558647efea1eaff
MD5 hash: 6bea588eb443b3d1d7de57c435152732
MIME type:application/octet-stream
Signature SantaStealer
File name:injectable.bin
File size:1'991'191 bytes
SHA256 hash: 70987fa8f90e2266b61456f125de864941ce03ed332a6a67b85e37e30006d59c
MD5 hash: d12341781893cc81d83a110fd6219bc3
MIME type:application/octet-stream
Signature SantaStealer
File name:webdriver.c
File size:1'787'375 bytes
SHA256 hash: 94621dc916312495d150d53560548c998a7714bb17e9fe7b017e93b8e4d07cb3
MD5 hash: 6d4772fb4be030e18847ff437ae27684
MIME type:application/octet-stream
Signature SantaStealer
File name:pagecontroller.cpp
File size:1'603'731 bytes
SHA256 hash: 9e9f44e0e6eb8c2c4b4e2fabdd95f0a78e2ab03a23fffcff18e783fb80aa31b9
MD5 hash: 2ffa8cc5da2493bde47bf8f89cb474c8
MIME type:application/octet-stream
Signature SantaStealer
File name:FaceRecognitionEngineAdapterResourcesCore.dll
File size:140'512 bytes
SHA256 hash: e2b82f14796e39563b8a59c7ba23da24429a5564f2d1bee729b060c58bd5a3e8
MD5 hash: dce8b50a3291dda119c994b819d29d34
MIME type:application/x-dosexec
Signature SantaStealer
File name:headerbuilder.bin
File size:1'016'055 bytes
SHA256 hash: 885400cec7f680e657b765f87641b1c2eed596e9d447fc05ce3bef2ade2b3716
MD5 hash: 47c9f9b5f0a1049b6c1e99ec7df7576a
MIME type:application/octet-stream
Signature SantaStealer
File name:MSOpusDecoder.dll
File size:166'912 bytes
SHA256 hash: 67035a0bf74547ea11446336f311b79faf02baf86d9919a10d1a368739161f1a
MD5 hash: 3de6d482eefbb5c90b3efe527b2bbeb1
MIME type:application/x-dosexec
Signature SantaStealer
File name:gpprefcl.dll
File size:786'944 bytes
SHA256 hash: b8763299f547e39d1d8674fb91853de57c2b11bc006ef58ead795c36fcf4db10
MD5 hash: 1f1b4046d870fb7be211c7d263524c96
MIME type:application/x-dosexec
Signature SantaStealer
File name:setup.exe
File size:81'920 bytes
SHA256 hash: 7b0334c329e40a542681bcaff610ae58ada8b1f77ff6477734c1b8b9a951ef4c
MD5 hash: d25a9e160e3b74ef2242023726f15416
MIME type:application/x-dosexec
Signature SantaStealer
File name:TEEManagement64.dll
File size:323'080 bytes
SHA256 hash: d74326a5fe0a35f99dd7e975a7f25993f7f0a46a605c8365dba26cf44ff9480e
MD5 hash: ddf6c835f522081a6468f5ed8161d71e
MIME type:application/x-dosexec
Signature SantaStealer
File name:install.exe
File size:150'833 bytes
SHA256 hash: 1c6e5f18b8802d7b71b7c9e6781afe6cc67f5535490d928757e2782dbdd9d0b3
MD5 hash: 800c782abebe71bae89f6677fbda976c
MIME type:application/x-dosexec
Signature SantaStealer
File name:drprov.dll
File size:26'624 bytes
SHA256 hash: 8aebe17b2466a62a3e332372777775fdf626764869abea54fb12606b01662876
MD5 hash: d196f6035b7923f8defe66e6ba6ca635
MIME type:application/x-dosexec
Signature SantaStealer
File name:bulkhead.bin
File size:837'282 bytes
SHA256 hash: 99812bce89b4fd91472205d6726f865bd2458ee6966af4add248806ed7537d0e
MD5 hash: 9833ce768ed7cd4baffd0d3bac73f8bf
MIME type:application/octet-stream
Signature SantaStealer
File name:classifier.c
File size:581'440 bytes
SHA256 hash: 169cab2194b88d463ed5f50d55696f0204d2508b8dad06076b3546fd72687ceb
MD5 hash: e78551fad61b10af1b3b6ff2f74e739d
MIME type:application/octet-stream
Signature SantaStealer
File name:imapi.dll
File size:176'128 bytes
SHA256 hash: 27b34f8b35bca152be2a1005090aa26fdba3dbd96f977621e63a83eb8d2da759
MD5 hash: 7f7dc4bb95a869ebcbfb0ef052ac1555
MIME type:application/x-dosexec
Signature SantaStealer
File name:prototype.c
File size:1'661'109 bytes
SHA256 hash: 8897d086968a46f62075f36a33773eeb11baf176627040683b8ea9cf4b5dc76e
MD5 hash: 914e0bf81b51fd8b5a87aee74a3694d1
MIME type:application/octet-stream
Signature SantaStealer
File name:executorfactory.cpp
File size:1'974'489 bytes
SHA256 hash: 20ac3538da2a7569061ac2c35f09ee4318ac77ec5b39aee8c86863fc434d8a1b
MD5 hash: fe34ce8b3a0bc422dc917a42d2b752fc
MIME type:application/octet-stream
Signature SantaStealer
File name:flagsmith.c
File size:912'583 bytes
SHA256 hash: 1cf687102dd45359900b4b4725e4d41d748dbdf790f4fa406caf2aded040a4de
MD5 hash: 0e4f98bd75cdf5273a7b862eefcd2cbb
MIME type:application/octet-stream
Signature SantaStealer
File name:query.c
File size:1'966'597 bytes
SHA256 hash: 9f26eccd94ac129126476f84b15b31ebc16ec24add062b7a9c14d092e405fbb0
MD5 hash: 877be7f7216015ecd054fabb4e6f142f
MIME type:application/octet-stream
Signature SantaStealer
File name:vault.cpp
File size:926'357 bytes
SHA256 hash: ca2566e831825e7aaefde93c8d7cb91f86bf75fc567d8440618da755daf15282
MD5 hash: 6562e3e5933176cd01298d7038737388
MIME type:application/octet-stream
Signature SantaStealer
File name:propsys.dll
File size:288'768 bytes
SHA256 hash: 9819b8bcb72df8cbfb081e848b0105a7e5f38a520db29f10d199430874c94b45
MD5 hash: 1f186fc73f106373b7744cb909d32df4
MIME type:application/x-dosexec
Signature SantaStealer
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HUNTING_SUSP_TLS_SECTION
Author:chaosphere
Description:Detect PE files with .tls section that can be used for anti-debugging
Reference:Practical Malware Analysis - Chapter 16
Rule name:pe_detect_tls_callbacks

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SantaStealer

rar 981971db686e5a41abb733e19246a02f12d9f38d84c2b8b3a2f33f93aa5e5d76

(this sample)

Comments