MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ada30fda2eb4b937a0101d9c533f49fb10fea29a72655d1696a850d6e2435dbf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SVCStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 30 File information Comments

SHA256 hash: ada30fda2eb4b937a0101d9c533f49fb10fea29a72655d1696a850d6e2435dbf
SHA3-384 hash: 92c4ca05da71ba9ca4106b261fc5cd2bb949bba3dc4fae892f05d841a7a4b8b7c9bc2e2b2646628fe6f7bb1f274af754
SHA1 hash: c9c04f152ba5132ddd74dc6bc6681504debed9f2
MD5 hash: 6667d0fd4a325f5a0fd7d071f780e1fb
humanhash: south-violet-mike-xray
File name:ada30fda2eb4b937a0101d9c533f49fb10fea29a72655d1696a850d6e2435dbf
Download: download sample
Signature SVCStealer
File size:11'784'192 bytes
First seen:2026-08-10 15:00:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a1bbfb9ef9eed40038fab925f62024db (1 x SVCStealer)
ssdeep 196608:HCrdC92o0axnXVOfX6IGBmJ27C5aivv2yN39iwFgvznOD7E2jzwD6:HqdC92laxXV+J2u5au2eEznJ2jt
TLSH T1E7C633A990B18872E19169305B457EDF680CBC321B9F25B89F0EFBC998F8AD0D543D47
TrID 63.4% (.EXE) UPX compressed Win32 Executable (27066/9/6)
11.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.5% (.EXE) Win32 Executable (generic) (4504/4/1)
4.7% (.EXE) OS/2 Executable (generic) (2029/13)
4.6% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 01e0d8ccccf47081 (1 x SVCStealer)
Reporter adrian__luca
Tags:exe SVCStealer UPX
File size (compressed) :11'784'192 bytes
File size (de-compressed) :34'471'936 bytes
Format:win32/pe
Unpacked file: 535eb88d35afcd8050dd928944ea5a7edaea2662d1333b76e49aaac42882c9d9

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
4363463463464363463463463.exe
Verdict:
Malicious activity
Analysis date:
2026-06-14 01:13:48 UTC
Tags:
loader auto vidar stealer github adware stealc lumma amadey botnet autoit hausbomber python meterpreter remus blankgrabber evasion screenconnect rdp rmm-tool ip-check metasploit backdoor generic xworm screenshot delphi discord phorpiex pastebin qrcode m0yv phishing arch-doc tool remote smb scan smbscan njrat braodo ransomware cryptolocker donutloader exfiltration guloader seetrol zigcryptostealer coinminer miner tinynuke bruteratel xmrig rat bladabindi quasar rustystealer clickfix cryptowall ammy

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
Deleting a recently created file
Replacing files
Сreating synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto fingerprint keylogger microsoft_visual_cc overlay packed packed reconnaissance reconnaissance upx
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-18T17:30:00Z UTC
Last seen:
2026-08-08T12:06:00Z UTC
Hits:
~100
Gathering data
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-19 06:46:05 UTC
File Type:
PE (Exe)
Extracted files:
34
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery upx
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
System Location Discovery: System Language Discovery
UPX packed file
Unpacked files
SH256 hash:
ada30fda2eb4b937a0101d9c533f49fb10fea29a72655d1696a850d6e2435dbf
MD5 hash:
6667d0fd4a325f5a0fd7d071f780e1fb
SHA1 hash:
c9c04f152ba5132ddd74dc6bc6681504debed9f2
SH256 hash:
881155b8c33919abc75b280f0377b311ce45c0f1e1f7c85f9d7e6a96d1aea32e
MD5 hash:
fd66e6700a8fd0f9821b8258e7cc3ba5
SHA1 hash:
434c3f93e3374d9ddb426a4b17622ac83aec1e3a
SH256 hash:
73d741afd6a114314308031ec8873e8de6056057b01cc284e9c9391da97b20ea
MD5 hash:
c4113909ac3e06358452efde9a182920
SHA1 hash:
91677f962e658f0c9e81c36451ec145c681d4f88
SH256 hash:
01aa278b07b58dc46c84bd0b1b5c8e9ee4e62ea0bf7a695862444af32e87f1fd
MD5 hash:
2d8e4f38b36c334d0a32a7324832501d
SHA1 hash:
f6f11ad2cd2b0cf95ed42324876bee1d83e01775
SH256 hash:
535eb88d35afcd8050dd928944ea5a7edaea2662d1333b76e49aaac42882c9d9
MD5 hash:
092273b7140ec66aa391ded63742dc79
SHA1 hash:
b3c719a3117c30b58d5e43ae495d2858d3db5b61
Detections:
win_svcready_a0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_All_Windows_PE_Malware
Author:DiegoAnalytics
Description:Detects Windows PE malware of all types, avoids non-executables like .html
Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:test_rule_vldslv
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:upx_largefile
Author:k3nr9
Rule name:virustotal
Author:Tracel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SVCStealer

Executable exe ada30fda2eb4b937a0101d9c533f49fb10fea29a72655d1696a850d6e2435dbf

(this sample)

Comments