ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe |
| Full analysis: | https://app.any.run/tasks/ff85fc60-5f13-4313-8cf6-e15780163db6 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | October 03, 2025, 18:19:55 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 86159FF6D151C5E151FAA4087A3BA518 |
| SHA1: | D8AAC6143A7028623C7593599B80FA73D381BF14 |
| SHA256: | BEF1FFAF2BC30913BE9732270A44607BB15F53C7FD83FF53E6BCCD4CD33C0E21 |
| SSDEEP: | 49152:XvpUHAigEZsBQkn5/i1/uxOY0EFToi5Vrbh5hTU10iH+71Qddfe8VIQshQ5o9rD+:XoAmsBQsMY02omVrN5hTFiHRe8V4Q52+ |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:10:03 17:36:42+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14 |
| CodeSize: | 992768 |
| InitializedDataSize: | 109056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xcf3b4 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3000 | "C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe" | C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3264 | "C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe" | C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 7808 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3000 | bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | C:\ProgramData\2dba1\phlnoh | text | |
MD5:DC6628321C3435AA0F90DF4C0195E43B | SHA256:287A1C5A56E967AAAFAC0102CCCD4764CCE47F2F6591E7FFD0112150D507B0C2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 149.154.167.99:443 | https://telegram.me/dobbl7 | GB | html | 12.0 Kb | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 5.69 Kb | unknown |
— | — | GET | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | — | — | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 62 b | unknown |
— | — | POST | 500 | 4.154.185.43:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 5 b | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 2.13 Kb | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 108 b | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 2 b | unknown |
— | — | POST | 200 | 49.13.34.131:443 | https://ma.gulfscholarships.com/ | DE | text | 11.3 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 62.115.252.35:443 | www.bing.com | Telia Company AB | ES | whitelisted |
6016 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2280 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7208 | slui.exe | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3000 | bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | 149.154.167.99:443 | telegram.me | Telegram Messenger Inc | GB | whitelisted |
3000 | bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe | 49.13.34.131:443 | ma.gulfscholarships.com | Hetzner Online GmbH | DE | unknown |
7808 | slui.exe | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
telegram.me |
| whitelisted |
ma.gulfscholarships.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
— | — | A Network Trojan was detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 |
— | — | A Network Trojan was detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |
— | — | Malware Command and Control Activity Detected | ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2 |