🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1cd581c687e1f8d9995d50b4200b6db4010c2c7d76b5b48642ae4ed0a55019e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 13


Intelligence 13 IOCs YARA 11 File information Comments

SHA256 hash: a1cd581c687e1f8d9995d50b4200b6db4010c2c7d76b5b48642ae4ed0a55019e
SHA3-384 hash: 974540697608c015cd2acf779f8f53bd974055e459021ae9ae249692a2606f3c5283ebd3a41b03e51db726c21f7dda8a
SHA1 hash: 44f8946a19fc76a510ad088f1cb853a12c69f395
MD5 hash: 43f14a2f33a1f7f4c60ccf995576799e
humanhash: paris-yellow-wyoming-may
File name:file
Download: download sample
Signature Stealc
File size:10'060'605 bytes
First seen:2026-09-26 00:07:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (80 x RemusStealer, 8 x ValleyRAT, 6 x SalatStealer)
ssdeep 196608:rf9zIkduo+u3Nzko4drZUoftl1VX4VWVTchhcHJkc8zfQuD+Ak8ePwWEvNpUSY7h:JUk4o+u3Nw/HLf31yWVTchhcHJkVzfq3
TLSH T1ECA63348E7F505FDD0B3E478CDA24C21F772B84A4762DBDB136025AA5E236E09D3AB11
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (918 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter Bitsight
Tags:c dropped-by-gcleaner exe MIX5.file Stealc


Avatar
Bitsight
url: http://91.92.242.236/service

Intelligence


File Origin
# of uploads :
1
# of downloads :
200
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-26 00:11:52 UTC
Tags:
auto-sch auto-reg stealc stealer salatstealer miner pastebin loader ms-smartcard

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Running batch commands
Launching a process
Creating a file
Adding an exclusion to Microsoft Defender
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug expired-cert fingerprint installer installer installer-heuristic microsoft_visual_cc overlay packed packed reconnaissance sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-25T22:45:00Z UTC
Last seen:
2026-09-27T18:14:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win64.Trojan.AgentTesla
Status:
Suspicious
First seen:
2026-09-26 00:08:19 UTC
File Type:
PE+ (Exe)
Extracted files:
67
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc defense_evasion discovery execution persistence stealer upx
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Delays execution with timeout.exe
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Views/modifies file attributes
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
Program crash
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Hide Artifacts: Hidden Files and Directories
UPX packed file
Adds Run key to start application
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Detects Stealc stealer Version 3
Family: Stealc
Malware Config
C2 Extraction:
https://api.mb2-rrfdnb-ip38z5.shop
Unpacked files
SH256 hash:
a1cd581c687e1f8d9995d50b4200b6db4010c2c7d76b5b48642ae4ed0a55019e
MD5 hash:
43f14a2f33a1f7f4c60ccf995576799e
SHA1 hash:
44f8946a19fc76a510ad088f1cb853a12c69f395
SH256 hash:
69886daa4054d4462d97e7f05bff115d76628dc66abd7103ba7dbe78822893e7
MD5 hash:
420d40ec8775abcfe2feaa3aee3d74da
SHA1 hash:
49421960c49c48552a0c48cbabc992cd46f12b55
SH256 hash:
97046f3ad0cbfe20db3174a89d4b5a542c0418515b81b26f6a4afebdc791751a
MD5 hash:
2cbd0251fd0e49f241ccff7d8ac16da3
SHA1 hash:
3805a545f3eb5bbad70ac8978cc86cf0f96cfff8
SH256 hash:
b7c6792a2bde2ec74ad4b3bd0e5c245c86ee3103b98a2e10cd13350edb0a630c
MD5 hash:
c922321c42ee032b0660bdb465fe53b5
SHA1 hash:
40d9a406748eb1e2ff946e25852875dba79bdf9e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe a1cd581c687e1f8d9995d50b4200b6db4010c2c7d76b5b48642ae4ed0a55019e

(this sample)

  
Dropped by
Gcleaner
  
Delivery method
Distributed via web download

Comments