File name:

a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09

Full analysis: https://app.any.run/tasks/7d06fae2-33e7-42cf-93c1-42a31793f757
Verdict: Malicious activity
Threats:

Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.

Analysis date: September 03, 2025, 16:10:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealc
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

04D39EAC1B5F7CDF1BF48FE31073F1A8

SHA1:

2F8CD1C64AC352DFD4100B4EF43ECFF1252656D8

SHA256:

A16A269613B2FBA53277BDF23CEE4DFB87754329437A7EA468CF4FE8EF656B09

SSDEEP:

6144:ENrKivwkYLGss0HfMKuBPubybrDVwamZblsSnQfBxjp+IV/VFUg1YqwVVHbfb:+t4kYL8WMKYPuMHp1V/V+VVHbfb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • STEALC has been detected

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
    • STEALC mutex has been found

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
  • SUSPICIOUS

    • Windows Defender mutex has been found

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
    • Executes application which crashes

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
  • INFO

    • Reads the computer name

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
    • Checks supported languages

      • a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe (PID: 4648)
    • Checks proxy server information

      • WerFault.exe (PID: 1100)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 1100)
    • Reads the software policy settings

      • WerFault.exe (PID: 1100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:01:20 16:51:51+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 41984
InitializedDataSize: 42079232
UninitializedDataSize: -
EntryPoint: 0x1941
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 75.0.0.0
ProductVersionNumber: 30.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug, Pre-release, Patched, Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #STEALC a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe werfault.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4648 -s 380C:\Windows\SysWOW64\WerFault.exe
a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1508C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4648"C:\Users\admin\AppData\Local\Temp\a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe" C:\Users\admin\AppData\Local\Temp\a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225621
Modules
Images
c:\users\admin\appdata\local\temp\a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msimg32.dll
Total events
3 561
Read events
3 561
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_a16a269613b2fba5_35346c93950df9b47c16bcf4e4086cb83b0242_5c6ae9f4_1bdedb05-44d2-4317-b066-7297e8bff10b\Report.wer
MD5:
SHA256:
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCB4A.tmp.dmpbinary
MD5:753B1A8523187C6497CD476FBC31A290
SHA256:463D91BB72EE74E9A83A426AEA1CD5119F9C0FFE2B580C7F0A5CD11635079BB0
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCBC9.tmp.xmlxml
MD5:5935BDB8B84BC2E20EB2DE47F045987D
SHA256:0C4BB8856C989B766DD2365EBE9E39CD54CA55E73962898374376C7535683C97
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCB89.tmp.WERInternalMetadata.xmlxml
MD5:3E09A68C3B7C7B0BD179ABAB5837D689
SHA256:1E98C335570BE73DD42E3056E721DBA7DB4B9186D36AA0301729703A741C3F8E
1100WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\a16a269613b2fba53277bdf23cee4dfb87754329437a7ea468cf4fe8ef656b09.exe.4648.dmp
MD5:3DA19CEE0EA2380DB48C76EB38D088C3
SHA256:3166D6E284E76EE244662F2632C6CB5F8A780555EAB2EFE26A8FCDFB8A864D79
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:D310523737A0D4D05066857AC157F458
SHA256:0A0520D498306689AFA3CAC09ACE82E09229108FC9FABA5A906291D077004484
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:FE857AB4082A3BBC9A0AE0B5748F68B3
SHA256:D30B2EA3D1ADD2B6059D843B0C93D8942B55A75DF2F04F1EF7D44FF069616E42
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:399B8A260A3FE6BB6F2D2DAE89FB82BB
SHA256:0DC7CEC07635BC159BA8B7FB1D7FC9AA00DE1C0C045BD688351878B65EAFF57B
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:0E8B4880ED276C96ED0BF4851A1429E3
SHA256:A75FDD8ADC2636F6B0D1431C5308B42BCAAB04F89D528F5B0EA516825A7D203D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
104.103.72.96:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
AT
binary
825 b
whitelisted
1100
WerFault.exe
GET
200
104.103.72.96:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
AT
binary
825 b
whitelisted
1100
WerFault.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
1268
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
2528
svchost.exe
GET
200
23.39.28.44:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4684
SIHClient.exe
GET
200
2.17.245.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
4684
SIHClient.exe
GET
200
2.17.245.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4836
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1100
WerFault.exe
135.233.45.222:443
watson.events.data.microsoft.com
LUCENT-CIO
US
whitelisted
1100
WerFault.exe
104.103.72.96:80
crl.microsoft.com
Akamai International B.V.
AT
whitelisted
4
System
192.168.100.255:138
whitelisted
1100
WerFault.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2528
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2528
svchost.exe
23.39.28.44:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted
watson.events.data.microsoft.com
  • 135.233.45.222
whitelisted
crl.microsoft.com
  • 104.103.72.96
  • 2.23.154.57
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 2.17.245.133
whitelisted
login.live.com
  • 40.126.31.131
  • 20.190.159.71
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.128
  • 20.190.159.0
  • 20.190.159.4
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 23.39.28.44
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
self.events.data.microsoft.com
  • 52.182.143.214
whitelisted

Threats

No threats detected
No debug info