| File name: | 45085f479b048dd0ef48bef5b8c78618113bc19bde6349f61d184cdf4331bff0.zip |
| Full analysis: | https://app.any.run/tasks/664a3fd0-c1e5-4b80-853b-44d3bf5c9c82 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | May 18, 2025, 21:02:56 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 9A1EB85791F0004CF1F93188B2CAFCFD |
| SHA1: | 015FC5EF85F1759428CA440E081918D90E58BAC5 |
| SHA256: | 45085F479B048DD0EF48BEF5B8C78618113BC19BDE6349F61D184CDF4331BFF0 |
| SSDEEP: | 98304:bHz3VVG+VbGEZDgHptXQUb8rsxy9psb0G/nugzDFV3QXcojNayttuduIVlMHk6i3:EJ3Nfvao3R |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:12:19 23:17:02 |
| ZipCRC: | 0x11cee5b2 |
| ZipCompressedSize: | 224736 |
| ZipUncompressedSize: | 257693 |
| ZipFileName: | API.sav |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 960 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2820 -childID 1 -isForBrowser -prefsHandle 2812 -prefMapHandle 2560 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {afe65fba-d2b8-408e-bfc2-254073d5a061} 8128 "\\.\pipe\gecko-crash-server-pipe.8128" 24f420a0d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1012 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5436 -childID 5 -isForBrowser -prefsHandle 5356 -prefMapHandle 5360 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {dc6c3b74-9e80-4945-a410-686aa4848a8d} 8128 "\\.\pipe\gecko-crash-server-pipe.8128" 24f47aba150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1128 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5124 -childID 3 -isForBrowser -prefsHandle 5152 -prefMapHandle 5148 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e14f147a-a1c3-46ec-a136-8c05f5d14e90} 8128 "\\.\pipe\gecko-crash-server-pipe.8128" 24f46da0d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1196 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5472 -childID 6 -isForBrowser -prefsHandle 4732 -prefMapHandle 5380 -prefsLen 31359 -prefMapSize 244635 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0a112582-e3e5-4f70-b770-1fa350f29c8c} 3028 "\\.\pipe\gecko-crash-server-pipe.3028" 28dc73f9f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1240 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3312 -childID 1 -isForBrowser -prefsHandle 3308 -prefMapHandle 3304 -prefsLen 33121 -prefMapSize 244635 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e7c539d9-3bb7-4928-8bd0-9db600732180} 3028 "\\.\pipe\gecko-crash-server-pipe.3028" 28dc16c7f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5768 -parentBuildID 20240213221259 -prefsHandle 6080 -prefMapHandle 5648 -prefsLen 38461 -prefMapSize 244635 -appDir "C:\Program Files\Mozilla Firefox\browser" - {af74476c-3268-499a-a6d7-8b2a0e377546} 3028 "\\.\pipe\gecko-crash-server-pipe.3028" 28dc692fb10 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1764 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6532 -childID 8 -isForBrowser -prefsHandle 6556 -prefMapHandle 6220 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f939ac94-3f63-4d28-988c-5b4403b7cd10} 8128 "\\.\pipe\gecko-crash-server-pipe.8128" 24f46e45d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1812 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4256 -childID 2 -isForBrowser -prefsHandle 4272 -prefMapHandle 4268 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8ae0aa4d-e49d-4e15-a389-ab81ead7faae} 8128 "\\.\pipe\gecko-crash-server-pipe.8128" 24f445e7850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4812 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 2596 -prefMapHandle 2592 -prefsLen 38461 -prefMapSize 244635 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9d0a7ed9-1b43-4e04-855a-360f93634ca8} 3028 "\\.\pipe\gecko-crash-server-pipe.3028" 28dc4927710 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 2392 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5464 -childID 7 -isForBrowser -prefsHandle 5316 -prefMapHandle 5384 -prefsLen 31359 -prefMapSize 244635 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c644c258-6313-49d1-aa98-3e828e6b6ea1} 3028 "\\.\pipe\gecko-crash-server-pipe.3028" 28dc836d150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\45085f479b048dd0ef48bef5b8c78618113bc19bde6349f61d184cdf4331bff0.zip | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5972) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\rtworkq.dll | — | |
MD5:— | SHA256:— | |||
| 8128 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\Meal.wav | binary | |
MD5:607B605A5F721B9346CA8532F15C623D | SHA256:E344E562D0D3C9365D1154C5501EF7FA7E9158210CD28D4F9F778669DA44A0AE | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\mfpmp.exe | executable | |
MD5:9CD65F38A2B4E53E8180395DE4988D6A | SHA256:FF7E8CCC41BC3A506103BDD719A19318BF711351AC0E61E1F1CF00F5F02251D5 | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\pnpcpu.sys | executable | |
MD5:79BDAD9CFBAEC2E665677806054B7A37 | SHA256:A39847ACC6E1E7D68D4532AC38A7A51B639FE512BC9C91C7E7779C4B1D9803E4 | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\microsoft.windows.kits.hardware.diagnostics.logannotation.dll | executable | |
MD5:39B1F04FEDD17691D63DD26407089831 | SHA256:281D0A99957A264B72C65DC30F66CC08F9CDD8DAD1F3A66E8A0F5F87B857749F | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\protect.db | binary | |
MD5:F115DAA6E926B92C4AF2E02AE2654896 | SHA256:4A15585D6A44D965B5C393ACAA6FED5CA15C55044E592B54AB2B83D58488F3E5 | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\Microsoft.WTT.Log.dll | executable | |
MD5:862DB80AD522AD9C969B75CEE70C6218 | SHA256:BECB24CEF0164F4A0613B9D7359749A799ED5C7F056F77E6134A40281DF735BE | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\fileshredder.ico | image | |
MD5:D8E48DE3E5710FABD066C2BC02445C02 | SHA256:1D1E9558EDEF4CE724F93F80DC96FA5D7306D341F89BCBE61694900A409A2E9B | |||
| 5972 | WinRAR.exe | C:\Users\admin\Downloads\API.sav | binary | |
MD5:4DC9207D50F8568ECD0631B503F8345B | SHA256:FF08868559AAD0EF1829239525960C186D9AB11C9AC01D0B0794A3EE2A83C223 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.21:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7900 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7900 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
8128 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
8128 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
8128 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
8128 | firefox.exe | POST | 200 | 142.250.186.67:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 23.216.77.21:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6544 | svchost.exe | 40.126.31.0:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
7900 | SIHClient.exe | 4.175.87.197:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3028 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
3028 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
3028 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |