File name:

1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3

Full analysis: https://app.any.run/tasks/bbd19aaf-f2e0-4968-a745-25323745c7a8
Verdict: Malicious activity
Threats:

Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.

Analysis date: September 03, 2025, 16:47:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealc
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

D8DF2134FCCE8D076018D83B8644E650

SHA1:

5879598CA665DFFDCCF77FBE68ABCA0D37F8E12A

SHA256:

1A102B793F4CAD2E1BFFC0A7E25FFD3601744A616D19F7F5DBD57C8A116538B3

SSDEEP:

6144:eOfp9GYYthpE+R39PhVNPvZpsXt1mexXSfNYV9ekDmaZh0Q00NzJVFVMVlV:ZhDYHhJhPPv/sXqqzJVFVMVlV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • STEALC has been detected

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
    • STEALC mutex has been found

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
  • SUSPICIOUS

    • Windows Defender mutex has been found

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
    • Executes application which crashes

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
  • INFO

    • Reads the computer name

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
    • Checks supported languages

      • 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe (PID: 4648)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2276)
    • Checks proxy server information

      • WerFault.exe (PID: 2276)
    • Reads the software policy settings

      • WerFault.exe (PID: 2276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:10:30 05:20:46+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 42496
InitializedDataSize: 42076672
UninitializedDataSize: -
EntryPoint: 0x15b0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 75.0.0.0
ProductVersionNumber: 30.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug, Pre-release, Patched, Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #STEALC 1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe werfault.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2276C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4648 -s 384C:\Windows\SysWOW64\WerFault.exe
1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4648"C:\Users\admin\AppData\Local\Temp\1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe" C:\Users\admin\AppData\Local\Temp\1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msimg32.dll
6388C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 317
Read events
3 317
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
6
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2276WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_1a102b793f4cad2e_768cb72df7aaaccc31547b4b4e590c032bc41d_5b135268_5e48ca96-a952-479c-a12a-1b7fbaed04fe\Report.wer
MD5:
SHA256:
2276WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCFDF.tmp.WERInternalMetadata.xmlxml
MD5:D33F97D3EB491AEDDC3918BE11A73A71
SHA256:0F6055CF8D180C4D44FA0FC7B9A35DAFA939898AAA6AD8BC37391A86A9942955
2276WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCF90.tmp.dmpbinary
MD5:8A4FFC163042749856C860E26A949EE9
SHA256:BB6D7B5E6E3CB92DE917660A1128EA8092BF4AF0680B549DB0D5C4FBECBBE288
2276WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCFFF.tmp.xmlxml
MD5:D77EC0CB98AB3355C50ABDDCB2730EE9
SHA256:B875B45DBA88E88AB338D244DCBE2EDEDE76092DA4CAF4BF9ACFFAB8230BE0E0
2276WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:399B8A260A3FE6BB6F2D2DAE89FB82BB
SHA256:0DC7CEC07635BC159BA8B7FB1D7FC9AA00DE1C0C045BD688351878B65EAFF57B
2276WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:D310523737A0D4D05066857AC157F458
SHA256:0A0520D498306689AFA3CAC09ACE82E09229108FC9FABA5A906291D077004484
2276WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:F279AADC1AEB7E9D598CA06F3470598C
SHA256:7C919140B5AEA86ACA06371FCDEF9E411D22B3B0863EB742760AB5A3EFB34883
2276WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:FB35DED699D726F2DFDF559BF4DAB4DC
SHA256:8F9DF77DD438F371C631FC01597493C3294414C01123C6F6E9590ACFB378E481
2276WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\1a102b793f4cad2e1bffc0a7e25ffd3601744a616d19f7f5dbd57c8a116538b3.exe.4648.dmpbinary
MD5:72F85223F444B94334A513FAEBC8EA7E
SHA256:19E644A1698958CBDD5E5E270DE9E79BA613A104AB34BC6601F25921F6445B82
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2276
WerFault.exe
GET
200
2.17.251.99:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
2276
WerFault.exe
GET
200
23.200.197.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
1268
svchost.exe
GET
200
23.200.197.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
3644
svchost.exe
GET
200
23.203.176.221:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
1268
svchost.exe
GET
200
2.17.251.99:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
4664
SIHClient.exe
GET
200
23.200.197.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
US
binary
419 b
whitelisted
4664
SIHClient.exe
GET
200
23.200.197.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
US
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3480
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2276
WerFault.exe
135.234.160.244:443
watson.events.data.microsoft.com
LUCENT-CIO
US
whitelisted
2276
WerFault.exe
2.17.251.99:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2276
WerFault.exe
23.200.197.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
3644
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3644
svchost.exe
23.203.176.221:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.46
whitelisted
watson.events.data.microsoft.com
  • 135.234.160.244
whitelisted
crl.microsoft.com
  • 2.17.251.99
  • 2.17.251.116
whitelisted
www.microsoft.com
  • 23.200.197.152
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.3
  • 20.190.159.68
  • 20.190.159.4
  • 40.126.31.67
  • 40.126.31.2
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 23.203.176.221
whitelisted
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
self.events.data.microsoft.com
  • 104.208.16.91
whitelisted

Threats

No threats detected
No debug info