| File name: | 45085f479b048dd0ef48bef5b8c78618113bc19bde6349f61d184cdf4331bff0.zip |
| Full analysis: | https://app.any.run/tasks/2faa545c-a988-4529-a9f8-8e08c1592685 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | May 19, 2025, 06:33:47 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 9A1EB85791F0004CF1F93188B2CAFCFD |
| SHA1: | 015FC5EF85F1759428CA440E081918D90E58BAC5 |
| SHA256: | 45085F479B048DD0EF48BEF5B8C78618113BC19BDE6349F61D184CDF4331BFF0 |
| SSDEEP: | 98304:bHz3VVG+VbGEZDgHptXQUb8rsxy9psb0G/nugzDFV3QXcojNayttuduIVlMHk6i3:EJ3Nfvao3R |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:12:19 23:17:02 |
| ZipCRC: | 0x11cee5b2 |
| ZipCompressedSize: | 224736 |
| ZipUncompressedSize: | 257693 |
| ZipFileName: | API.sav |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 660 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1904 -parentBuildID 20240213221259 -prefsHandle 1824 -prefMapHandle 1812 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {22a48614-9fde-40af-807b-d87d97475021} 8032 "\\.\pipe\gecko-crash-server-pipe.8032" 23110de8c10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 896 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4788 -childID 4 -isForBrowser -prefsHandle 5000 -prefMapHandle 4872 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bce1fd06-db4b-4179-a3f9-d4b5d604ec98} 7660 "\\.\pipe\gecko-crash-server-pipe.7660" 2b01ce2ebd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3008 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3140 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5448 -childID 8 -isForBrowser -prefsHandle 5104 -prefMapHandle 2352 -prefsLen 31423 -prefMapSize 244583 -jsInitHandle 1464 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5d51e7c6-0d91-4760-bf13-b6a399b3c4f8} 8032 "\\.\pipe\gecko-crash-server-pipe.8032" 23118882f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3900 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4284 -childID 2 -isForBrowser -prefsHandle 4276 -prefMapHandle 4272 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1befddd3-94f1-4972-bb53-afbcb81ab74d} 7660 "\\.\pipe\gecko-crash-server-pipe.7660" 2b01ba604d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4008 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4892 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4900 -prefMapHandle 4904 -prefsLen 38209 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8c9ca73e-93e8-4eb6-b41a-08536cb12b70} 8032 "\\.\pipe\gecko-crash-server-pipe.8032" 2311a4de910 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 4268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4772 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4012 -prefMapHandle 4672 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {63e51332-725f-45ff-9181-623aac577873} 7660 "\\.\pipe\gecko-crash-server-pipe.7660" 2b01d3d1510 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 4408 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2696 -childID 1 -isForBrowser -prefsHandle 2692 -prefMapHandle 2688 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1464 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7064d12a-da69-4b69-9651-eddc636e8db9} 8032 "\\.\pipe\gecko-crash-server-pipe.8032" 23115736f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 4448 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\45085f479b048dd0ef48bef5b8c78618113bc19bde6349f61d184cdf4331bff0.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 4756 | "C:\Users\admin\Desktop\mfpmp.exe" | C:\Users\admin\Desktop\mfpmp.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Media Foundation Protected Pipeline EXE Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\45085f479b048dd0ef48bef5b8c78618113bc19bde6349f61d184cdf4331bff0.zip | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
| (PID) Process: | (4448) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7660 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\API.sav | binary | |
MD5:4DC9207D50F8568ECD0631B503F8345B | SHA256:FF08868559AAD0EF1829239525960C186D9AB11C9AC01D0B0794A3EE2A83C223 | |||
| 7660 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7660 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\microsoft.windows.kits.hardware.diagnostics.logannotation.dll | executable | |
MD5:39B1F04FEDD17691D63DD26407089831 | SHA256:281D0A99957A264B72C65DC30F66CC08F9CDD8DAD1F3A66E8A0F5F87B857749F | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\Microsoft.WTT.Log.dll | executable | |
MD5:862DB80AD522AD9C969B75CEE70C6218 | SHA256:BECB24CEF0164F4A0613B9D7359749A799ED5C7F056F77E6134A40281DF735BE | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\mfpmp.exe | executable | |
MD5:9CD65F38A2B4E53E8180395DE4988D6A | SHA256:FF7E8CCC41BC3A506103BDD719A19318BF711351AC0E61E1F1CF00F5F02251D5 | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\pnpcpu.sys | executable | |
MD5:79BDAD9CFBAEC2E665677806054B7A37 | SHA256:A39847ACC6E1E7D68D4532AC38A7A51B639FE512BC9C91C7E7779C4B1D9803E4 | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\mergemod.dll | executable | |
MD5:93E94A1E85F71C7B2D952ACDA3004646 | SHA256:B4C37E1E24C7460F66535E60FE2C0A8426039F2F8D4C016EC681D340AAB07ACA | |||
| 4448 | WinRAR.exe | C:\Users\admin\Desktop\protect.db | binary | |
MD5:F115DAA6E926B92C4AF2E02AE2654896 | SHA256:4A15585D6A44D965B5C393ACAA6FED5CA15C55044E592B54AB2B83D58488F3E5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7660 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
7660 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7660 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
7660 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
7660 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
7660 | firefox.exe | POST | 200 | 142.250.185.227:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
7660 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
8032 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |