🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5c72359e365ae0f4306fa0097ea72f9d9a917e9a642bfbb25ac681e9086098c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 3


Intelligence 3 IOCs YARA 16 File information Comments

SHA256 hash: d5c72359e365ae0f4306fa0097ea72f9d9a917e9a642bfbb25ac681e9086098c
SHA3-384 hash: 01b56a113969f8826bfb9e2bacb8ac7989b98bf76897eccd7da28b3783e169a803e90a9710c7dda2db152201f6190d5a
SHA1 hash: f095d1071f5cf5a422f15e45c2339e7a6ca1a1b1
MD5 hash: 8d8be810611aaac7cba2d1b29eb6fdc1
humanhash: freddie-floor-jupiter-juliet
File name:file.7z
Download: download sample
Signature Stealc
File size:3'529'731 bytes
First seen:2025-11-19 15:43:19 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 8714
ssdeep 98304:ig7ibAmM5MHyvg4p85N7xCSoc0iANT2Dcz:1GbAmVS5p+Nlac0fqY
TLSH T1DFF533071F59EE7C282E84816563C5278B073BD82E664CF8049DB2FDC6EB0651D5D2EE
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:7z 80-97-160-107 file-pumped pw-8714 Stealc


Avatar
iamaachum
https://media.share2git.quest/file.zip =>https://arch.git33share.beauty/soap/media/[x]/file.zip

Stealc Build ID: MIXDEAD
Stealc C2: http://80.97.160.107/2d75495e54d741c1.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:file.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:857'029'083 bytes
SHA256 hash: b3ffdf250e33b9c957a1fcbc4b7c29b7e146c4fdf6af324d5ba87e9802ddd2cf
MD5 hash: 55563498cfc3de863f551381f332a62a
De-pumped file size:3'483'136 bytes (Vs. original size of 857'029'083 bytes)
De-pumped SHA256 hash: a849d1769b7f67ac1d0872e5b2f6f2fc58554ce634f916e15462ba5a6a2f1b29
De-pumped MD5 hash: 954257841e40007a6d51754693436eed
MIME type:application/x-dosexec
Signature Stealc
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive SFX 7z
Result
Malware family:
Score:
  10/10
Tags:
family:stealc botnet:mixdead stealer
Behaviour
Stealc
Stealc family
Malware Config
C2 Extraction:
http://80.97.160.107
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Any_SU_Domain
Author:you
Description:Detect any reference to .su domains or subdomains
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Golang_Binary
Author:Andrew Morrow
Description:Detects binaries compiled with Go
Rule name:GoBinTest
Rule name:golang
Rule name:Golangmalware
Author:Dhanunjaya
Description:Malware in Golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:golang_duffcopy_amd64
Rule name:HiveRansomware
Author:Dhanunjaya
Description:Yara Rule To Detect Hive V4 Ransomware
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

7z d5c72359e365ae0f4306fa0097ea72f9d9a917e9a642bfbb25ac681e9086098c

(this sample)

  
Delivery method
Distributed via web download

Comments