MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d4c14345863b9fb83682e0290bcaf631f7143638c86669b71f0221b58ba4e224. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Stealc
Vendor detections: 16
| SHA256 hash: | d4c14345863b9fb83682e0290bcaf631f7143638c86669b71f0221b58ba4e224 |
|---|---|
| SHA3-384 hash: | 4606390576634c1fa080775f5f6ccc30e8c7644f8d5ce88750cc10b7bd2502999fd43ff713121473a0abd5a3051e7197 |
| SHA1 hash: | cec1ee24d309f9c26587ecb9ceb05646540b1ffa |
| MD5 hash: | 30211bf5a5bad0bb5b6024830737e071 |
| humanhash: | michigan-lithium-nitrogen-hydrogen |
| File name: | 30211bf5a5bad0bb5b6024830737e071.exe |
| Download: | download sample |
| Signature | Stealc |
| File size: | 282'624 bytes |
| First seen: | 2024-09-17 14:00:16 UTC |
| Last seen: | 2024-09-17 14:27:54 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | e65a8357ca24d261f7849f444ec396fa (2 x Smoke Loader, 1 x Stealc, 1 x RemcosRAT) |
| ssdeep | 3072:rLZJbrsRO/oPOob5lWNIMjmG/k6pqmsRN0UDMUFRDBEy8n35QCT5+aXDGwODOcEM:rLXPKO/omob5lNN6MNNboYR9w9jIR |
| TLSH | T1B6547D506AF1B15AE2FB85B4C971DEA07A3FB8E26971816E3604161F2CF16C04943F9F |
| TrID | 46.6% (.CPL) Windows Control Panel Item (generic) (57583/11/19) 25.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 8.5% (.EXE) Win64 Executable (generic) (10523/12/4) 5.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.0% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 004a632181340200 (1 x Stealc) |
| Reporter | |
| Tags: | exe Stealc |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
d84778c4ba83c52a6dc1aa034cd2638e89703e7cda002789ef03d63516ea37b4
b14840ed30290073cbce2dc18ab0073920881cbb647ac5eeda36e5bd8b3efa6c
3f8dd2323ff45d0ca3690bf5bfe6d518f053ee9e15211cac230a9639ed712e6c
5d7f8b38a4d31ff73c36b0d3d0bbd52b0de8574127bfdc22bae0b84e440c595b
ecdb8210cf706d7c0650b25f83a28b63a08d8d9adecccd7d5ca87c177cacb1f8
07b8972ecab0d6a49d2319054d81a2b239a107b9f746f204bd47ed26f1cdafe9
d4c14345863b9fb83682e0290bcaf631f7143638c86669b71f0221b58ba4e224
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerHiding__Active |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | pe_detect_tls_callbacks |
|---|
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::LoadLibraryW KERNEL32.dll::LoadLibraryA KERNEL32.dll::GetVolumeInformationW KERNEL32.dll::GetStartupInfoW KERNEL32.dll::GetStartupInfoA |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::FillConsoleOutputCharacterA KERNEL32.dll::WriteConsoleOutputA KERNEL32.dll::WriteConsoleW KERNEL32.dll::WriteConsoleA KERNEL32.dll::SetConsoleTitleA KERNEL32.dll::SetStdHandle |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CopyFileExW KERNEL32.dll::CreateDirectoryW KERNEL32.dll::CreateFileA KERNEL32.dll::GetFileAttributesW |
| WIN_BASE_USER_API | Retrieves Account Information | KERNEL32.dll::GetComputerNameW KERNEL32.dll::QueryDosDeviceA |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.