| File name: | 250429-a5s1watpv7_pw_infected.zip |
| Full analysis: | https://app.any.run/tasks/2e237c2f-6e17-44da-b617-1192e4786b86 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | April 29, 2025, 07:10:52 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=AES Encrypted |
| MD5: | 8483E4A47B2294EAEEFB616368485BFB |
| SHA1: | 289F2055815303A5D85529BF78C663CB8C4E1CFB |
| SHA256: | 9A3A0C36310465A6B3AE492ACD797BCE7607FD51D3BFAAC434F66234989B4E2A |
| SSDEEP: | 49152:ZPJBF7H26sv4wMgr+vNIyTJtza7Kl6TdUQ09X3UgFlZLKYgtGMtIO6Rjywv0GZnA:ZPJb7H2VvZMOuWynO7KITSUgFlsXLtW+ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 1980:00:00 00:00:00 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | 1084586 |
| ZipUncompressedSize: | 1169408 |
| ZipFileName: | 29042025_0048_7456f63a46cc318334a70159aa3c4291.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1228 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.1379\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.1379\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Rgcrx Exit code: 4294967295 Version: 1.0.2765.29451 Modules
| |||||||||||||||
| 1676 | C:\WINDOWS\system32\WerFault.exe -u -p 4724 -s 1212 | C:\Windows\System32\WerFault.exe | — | InstallUtil.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4724 | "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe" | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: .NET Framework installation utility Exit code: 3221226505 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 4880 | C:\WINDOWS\system32\WerFault.exe -u -p 8160 -s 968 | C:\Windows\System32\WerFault.exe | — | InstallUtil.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5008 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7556 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\250429-a5s1watpv7_pw_infected.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 7676 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7712 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7916 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.47335\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.47335\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Rgcrx Exit code: 4294967295 Version: 1.0.2765.29451 Modules
| |||||||||||||||
| 8160 | "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe" | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: .NET Framework installation utility Exit code: 3221226505 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\250429-a5s1watpv7_pw_infected.zip | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (7556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (7916) 29042025_0048_7456f63a46cc318334a70159aa3c4291.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\29042025_0048_7456f63a46cc318334a70159aa3c4291_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4880 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_InstallUtil.exe_1323bf91467d8342e797628f80518b741ce8350_3d87e84d_2d12fc58-8d64-4700-b242-862db1bf580f\Report.wer | — | |
MD5:— | SHA256:— | |||
| 1676 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_InstallUtil.exe_1323bf91467d8342e797628f80518b741ce8350_3d87e84d_8eb046df-a8d8-49ed-b210-acff4c889d7f\Report.wer | — | |
MD5:— | SHA256:— | |||
| 1676 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER8481.tmp.xml | xml | |
MD5:A4632BF7DBB5D19DC6422CB8B0A22D8F | SHA256:63BF605C7B87DA663EF607C1B68425AFD9414292945046DD2A14892F7844AC81 | |||
| 7556 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.1379\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe | executable | |
MD5:3D35FEB1304CF3AD007269AF5258B950 | SHA256:C3F20C6B73E715D59D88A9A30AD59E758F8D8A2DE99001D01BA31EB393742F9B | |||
| 1676 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER83C3.tmp.dmp | binary | |
MD5:D13C5E5FA0D992A8E8FF9C97DC19E3A6 | SHA256:DAD4D8124B5C22512F20F0082F13D58A3305AF33317BCB3DCE8FC80DBA9A1461 | |||
| 4880 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WEREE0C.tmp.WERInternalMetadata.xml | xml | |
MD5:4B0753091ADD336D8B6CDFB7B3C30B1E | SHA256:009BD7432E7A9913D8FA8F229D8CC651DEA1D629A9E58CCEAC80D391539EB868 | |||
| 1676 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER8451.tmp.WERInternalMetadata.xml | xml | |
MD5:2AD9B8EBE9E7E7705DE2AF232C1CCF6D | SHA256:C1A5EB29B685778546299E9A9D6AB5687D485717817BF41EC45EFE1FCCCD4F93 | |||
| 4880 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WEREE2C.tmp.xml | xml | |
MD5:6C200234E5B38C6787077F272FD9F954 | SHA256:5AC3759366701AE062B24BD3E4F11EB82D967A7B7E69718DF13FD4F75926A01D | |||
| 7556 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb7556.47335\29042025_0048_7456f63a46cc318334a70159aa3c4291.exe | executable | |
MD5:3D35FEB1304CF3AD007269AF5258B950 | SHA256:C3F20C6B73E715D59D88A9A30AD59E758F8D8A2DE99001D01BA31EB393742F9B | |||
| 4880 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\InstallUtil.exe.8160.dmp | binary | |
MD5:4B553B7E121C715077793BEBACCDEF48 | SHA256:62E82878EBF277D7E465FCEB92DFCD63584E91A45C08D8801A0B7C832C8469D2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.25:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.25:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.216.77.25:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.25:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.160.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
samsplaying.vip |
| unknown |
wallsekker.store |
| unknown |
slscr.update.microsoft.com |
| whitelisted |