File name:

52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe

Full analysis: https://app.any.run/tasks/464ec6fd-ad2e-428f-a79b-3a30a5188769
Verdict: Malicious activity
Threats:

Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.

Analysis date: April 28, 2024, 17:21:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
stealc
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4C1211CA6ACF41A9A2282C3291384BC5

SHA1:

0D405A8E2C8DF1621A10ADF984C836E29F0A51C5

SHA256:

52AA0C072E5C7FEF19391A933CB34B085BF34D258D3FD7603A99907B262D547D

SSDEEP:

12288:l6FWJqcyMUQ6FXeSDWGmbhB4vu1Oq4VtD5VVVVVMD:l6FWeMUzFOSDRmbhB4vuuUD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • STEALC has been detected (SURICATA)

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Connects to the CnC server

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
  • SUSPICIOUS

    • Windows Defender mutex has been found

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Reads security settings of Internet Explorer

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Executes application which crashes

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Contacting a server suspected of hosting an CnC

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
  • INFO

    • Reads the computer name

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Checks supported languages

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
    • Checks proxy server information

      • 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe (PID: 6376)
      • WerFault.exe (PID: 6496)
    • Reads the software policy settings

      • WerFault.exe (PID: 6496)
      • slui.exe (PID: 4724)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:05 12:10:38+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 69120
InitializedDataSize: 23084032
UninitializedDataSize: -
EntryPoint: 0x4382
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 23.0.0.0
ProductVersionNumber: 69.0.0.0
FileFlagsMask: 0x950a
FileFlags: (none)
FileOS: Unknown (0x20823)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Farsi
CharacterSet: Unknown (24E6)
FileVersions: 71.30.9.93
InternalName: Holly
FileDescription: Billi
LegalCopyright: Copyright (C) 2022, Cry
OriginalFileName: Firezer
ProductName: Badabum
ProductVersions: 42.16.56.29
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start #STEALC 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe werfault.exe sppextcomobj.exe no specs slui.exe slui.exe no specs filecoauth.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4724"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4920C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6232C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe -EmbeddingC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDriveFile Co-Authoring Executable
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\19.043.0304.0013\filecoauth.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6376"C:\Users\admin\AppData\Local\Temp\52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe" C:\Users\admin\AppData\Local\Temp\52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msimg32.dll
6480C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6496C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6376 -s 1092C:\Windows\SysWOW64\WerFault.exe
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
5 200
Read events
5 188
Write events
12
Delete events
0

Modification events

(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6376) 52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6480) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
Executable files
0
Suspicious files
4
Text files
2
Unknown types
2

Dropped files

PID
Process
Filename
Type
6496WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_52aa0c072e5c7fef_781bc49ccc1add2cd42ad08bf0afb35d39a978_019ac508_08207993-b7c1-4ba5-8622-084239507368\Report.wer
MD5:
SHA256:
6496WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER2E14.tmp.xmlxml
MD5:344C2763481C82B751D386E621F32415
SHA256:C3792743E155B5CA5772D3DF823C9D2DEC474B8F7B071D9DD67E91B0588B0883
6496WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER2C6C.tmp.dmpdmp
MD5:6B27A5E983FB5887E8D4AAA7AABD9D45
SHA256:14A65E183F06DB744C59F17CD6131D9E66EED64AD3BE59FD752DE528375C799A
6496WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:FC8597EA72599AC3010632CBF52916CC
SHA256:3A765F778A837BC791D2D34138844AD9FEE5F7E4CD6CA3E780CFE2E0601C2C5B
6496WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:23E663AD81C9272BE5114F8C7E4DD1D5
SHA256:E8A891BD9CC0448A7E7A33E03CF14A184069FEE7BF1E2EB853FE06E517562948
6496WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER2DE4.tmp.WERInternalMetadata.xmlxml
MD5:11D14C82110FC844E14202F2B85E06A4
SHA256:6F8953167B9E835FC17E3A2A784039307A5E88DB06A72EFC07A2B84BEE14971C
6496WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe.6376.dmpbinary
MD5:B749452FDCF92698DE24CF9BEB06B484
SHA256:34794C7FC75D8431E173251C8B17E5F752391F38E2E4C560F9D4EB834878D49A
6232FileCoAuth.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-04-28.1722.6232.1.odlbinary
MD5:377DD21B017416D66EF664ADDE406FD1
SHA256:E0AE65ACA82BEEFF185173D2EEB8123E99C8AEB0B3E205B9B5F907FA8B3599E2
6232FileCoAuth.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-04-28.1722.6232.1.aodlbinary
MD5:28DCA2FF4B34B5A52A2E59DF202A6ED3
SHA256:33BACCB7296F1ED1F995FC77A23049F261CF391AC0388F9E8DD161F8C17B7F94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
54
DNS requests
20
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6496
WerFault.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
unknown
6376
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
POST
200
185.172.128.150:80
http://185.172.128.150/c698e1bc8a2f5e6d.php
RU
text
8 b
unknown
4680
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
US
binary
312 b
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
US
binary
471 b
unknown
5576
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
unknown
6036
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
unknown
1728
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
unknown
1728
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
409 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5576
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1744
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5140
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6376
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
185.172.128.150:80
OOO Nadym Svyaz Service
RU
unknown
4364
svchost.exe
239.255.255.250:1900
unknown
6496
WerFault.exe
13.89.179.12:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6496
WerFault.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5576
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4680
SearchApp.exe
2.19.120.21:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
watson.events.data.microsoft.com
  • 13.89.179.12
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.19.120.21
  • 2.19.120.32
whitelisted
r.bing.com
  • 2.19.120.32
  • 2.19.120.21
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.71
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.43.62.58
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

PID
Process
Class
Message
6376
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 32
6376
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
Malware Command and Control Activity Detected
STEALER [ANY.RUN] Stealc
6376
52aa0c072e5c7fef19391a933cb34b085bf34d258d3fd7603a99907b262d547d.exe
Malware Command and Control Activity Detected
ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in
No debug info