| File name: | 87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe |
| Full analysis: | https://app.any.run/tasks/596039d7-7297-4481-b63a-f164905c2e47 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | October 03, 2025, 17:10:48 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 9 sections |
| MD5: | D5A635EDB78BBDA4F2AE360763074D5C |
| SHA1: | 1F8E451A7CE4C5EFCEF91FECF88EDA165B1418C7 |
| SHA256: | 87AAA5CACDB412C8A461D519803913215D4D1AFE69803EE5BDC9768D9F097677 |
| SSDEEP: | 49152:8E950vA1jRp4Ukhf/wwwzxPbe0YYQvpwn+jANfBjsOImN0xy3bznUzc0sXfRUcFC:5hRrWQP60W7Ubx6xO3 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, No debug |
| PEType: | PE32+ |
| LinkerVersion: | 2.36 |
| CodeSize: | 1051648 |
| InitializedDataSize: | 2917888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x73420 |
| OSVersion: | 6.1 |
| ImageVersion: | 1 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.2.4.8581 |
| ProductVersionNumber: | 5.2.4.8581 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | ideaMaker 5.2.4 - www.raise3d.com |
| CompanyName: | Raise3D |
| FileDescription: | ideaMaker 5.2.4 - www.raise3d.com |
| FileVersion: | 5.2.4.8581 |
| InternalName: | ideaMaker_5.2.4.8581.exe |
| LegalCopyright: | Copyright (C) 2023 Raise3D Technologies Inc. All rights reserved. |
| OriginalFileName: | ideaMaker_5.2.4.8581.exe |
| ProductName: | ideaMaker Installer |
| ProductVersion: | 5.2.4.8581 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2364 | "C:\Users\admin\Desktop\87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe" | C:\Users\admin\Desktop\87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe | explorer.exe | ||||||||||||
User: admin Company: Raise3D Integrity Level: MEDIUM Description: ideaMaker 5.2.4 - www.raise3d.com Exit code: 0 Version: 5.2.4.8581 Modules
| |||||||||||||||
| 2428 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7780 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2364) 87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2364) 87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2364) 87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2364 | 87aaa5cacdb412c8a461d519803913215d4d1afe69803ee5bdc9768d9f097677.exe | C:\ProgramData\1vsri\89zcba | text | |
MD5:DC6628321C3435AA0F90DF4C0195E43B | SHA256:287A1C5A56E967AAAFAC0102CCCD4764CCE47F2F6591E7FFD0112150D507B0C2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.19.122.26:443 | https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%205%3A11%3A05%20PM | unknown | binary | 60.1 Kb | unknown |
— | — | POST | 200 | 20.190.159.73:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 200 | 40.126.31.130:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.159.129:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 20.190.159.64:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | GET | 200 | 2.19.122.31:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | unknown | image | 4.62 Kb | unknown |
— | — | POST | 200 | 40.126.31.1:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | POST | 204 | 2.19.122.42:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | POST | 200 | 40.126.31.71:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | GET | 200 | 49.13.36.184:443 | https://pp.jullianacalhau.com.br/ | DE | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4472 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5948 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5224 | SearchApp.exe | 2.19.122.26:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
6916 | svchost.exe | 20.190.159.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1588 | backgroundTaskHost.exe | 2.19.122.26:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
7468 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
arc.msn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
telegram.me |
| whitelisted |
pp.jullianacalhau.com.br |
| malicious |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | A Network Trojan was detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 |
— | — | A Network Trojan was detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Misc activity | ET HUNTING EXE Base64 Encoded potential malware |
— | — | Misc activity | ET HUNTING EXE Base64 Encoded potential malware |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |