🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d494bdc4eb4e2d873a00c46fa4993450a580ca0495fe94efa870c5593eb606f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 12


Intelligence 12 IOCs YARA 4 File information Comments

SHA256 hash: d494bdc4eb4e2d873a00c46fa4993450a580ca0495fe94efa870c5593eb606f2
SHA3-384 hash: 19b3c59296528f97645dc5b73dec3e10900f7d450ca6545515f1ed57ad1c5f2e5b82f7a1ed2f4140bcd10983e58ba08e
SHA1 hash: 0f67422c84ad10d4bf6f6779d939a14b55147cd6
MD5 hash: fa53c61ff65dcb2feeb8b13d49b9800e
humanhash: early-six-xray-east
File name:d494bdc4eb4e2d873a00c46fa4993450a580ca0495fe94efa870c5593eb606f2
Download: download sample
Signature Stealc
File size:2'491'640 bytes
First seen:2025-11-12 12:22:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 77f62e8c6858bdb8e1d43a9c6ff0e9cc (2 x Stealc)
ssdeep 6144:gAXYtUokCu2yMSSrmLKHzjOIKBvhjR5Il3KOpRUzhU/0on3oQ9:AtUoHu0kHnvJR5Il64RUtU9
TLSH T12DB58D2266F56896FA739B34192A969CDBEFBC71DE38565E72002D0F0C723B1CD21712
TrID 39.5% (.EXE) InstallShield setup (43053/19/16)
28.6% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
9.6% (.EXE) Win64 Executable (generic) (10522/11/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon 0010324430161000 (2 x Stealc)
Reporter Anonymous
Tags:exe Stealc

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
EG EG
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
d494bdc4eb4e2d873a00c46fa4993450a580ca0495fe94efa870c5593eb606f2
Verdict:
No threats detected
Analysis date:
2025-11-12 12:23:13 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
malware
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Gathering data
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-11-11T14:12:00Z UTC
Last seen:
2025-11-14T05:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-PSW.Win32.Stealerc.pef HEUR:Trojan-PSW.Win32.Stealerc.gen
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Verdict:
Malicious
Threat:
Trojan-PSW.Win32.Stealerc
Threat name:
Win32.Trojan.StealC
Status:
Malicious
First seen:
2025-11-11 19:01:22 UTC
File Type:
PE (Exe)
Extracted files:
64
AV detection:
27 of 38 (71.05%)
Threat level:
  5/5
Verdict:
Malicious
Tags:
Win.Packed.Stealerc-10039048-0
YARA:
n/a
Unpacked files
SH256 hash:
d494bdc4eb4e2d873a00c46fa4993450a580ca0495fe94efa870c5593eb606f2
MD5 hash:
fa53c61ff65dcb2feeb8b13d49b9800e
SHA1 hash:
0f67422c84ad10d4bf6f6779d939a14b55147cd6
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Windows_Infostealer_Generic_acde9261
Author:Elastic Security
Description:Observed in Stealc/Vidar samples

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments