File name:

bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe

Full analysis: https://app.any.run/tasks/ff85fc60-5f13-4313-8cf6-e15780163db6
Verdict: Malicious activity
Threats:

Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.

Analysis date: October 03, 2025, 18:19:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
vidar
stealer
stealc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

86159FF6D151C5E151FAA4087A3BA518

SHA1:

D8AAC6143A7028623C7593599B80FA73D381BF14

SHA256:

BEF1FFAF2BC30913BE9732270A44607BB15F53C7FD83FF53E6BCCD4CD33C0E21

SSDEEP:

49152:XvpUHAigEZsBQkn5/i1/uxOY0EFToi5Vrbh5hTU10iH+71Qddfe8VIQshQ5o9rD+:XoAmsBQsMY02omVrN5hTFiHRe8V4Q52+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • VIDAR has been detected (YARA)

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Actions looks like stealing of personal data

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Steals credentials from Web Browsers

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
  • SUSPICIOUS

    • Application launched itself

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3264)
    • There is functionality for taking screenshot (YARA)

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Reads security settings of Internet Explorer

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Searches for installed software

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
  • INFO

    • Checks supported languages

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3264)
    • Reads the computer name

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Reads the machine GUID from the registry

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Checks proxy server information

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
      • slui.exe (PID: 7808)
    • Reads the software policy settings

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
      • slui.exe (PID: 7808)
    • Creates files in the program directory

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Reads Environment values

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Reads CPU info

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
    • Reads product name

      • bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:10:03 17:36:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 992768
InitializedDataSize: 109056
UninitializedDataSize: -
EntryPoint: 0xcf3b4
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
3000"C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe"C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3264"C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe" C:\Users\admin\Desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
7808C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 310
Read events
7 307
Write events
3
Delete events
0

Modification events

(PID) Process:(3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3000) bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3000bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exeC:\ProgramData\2dba1\phlnohtext
MD5:DC6628321C3435AA0F90DF4C0195E43B
SHA256:287A1C5A56E967AAAFAC0102CCCD4764CCE47F2F6591E7FFD0112150D507B0C2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
22
DNS requests
6
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
149.154.167.99:443
https://telegram.me/dobbl7
GB
html
12.0 Kb
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
5.69 Kb
unknown
GET
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
62 b
unknown
POST
500
4.154.185.43:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
5 b
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
2.13 Kb
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
108 b
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
2 b
unknown
POST
200
49.13.34.131:443
https://ma.gulfscholarships.com/
DE
text
11.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
62.115.252.35:443
www.bing.com
Telia Company AB
ES
whitelisted
6016
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2280
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5948
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7208
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3000
bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
149.154.167.99:443
telegram.me
Telegram Messenger Inc
GB
whitelisted
3000
bef1ffaf2bc30913be9732270a44607bb15f53c7fd83ff53e6bccd4cd33c0e21.bin.exe
49.13.34.131:443
ma.gulfscholarships.com
Hetzner Online GmbH
DE
unknown
7808
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 62.115.252.35
  • 62.115.252.56
  • 62.115.252.51
  • 62.115.252.57
  • 62.115.252.41
  • 62.115.252.50
  • 62.115.252.34
  • 62.115.252.25
  • 62.115.252.58
whitelisted
google.com
  • 142.250.185.238
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
activation-v2.sls.microsoft.com
  • 4.154.209.85
whitelisted
telegram.me
  • 149.154.167.99
whitelisted
ma.gulfscholarships.com
  • 49.13.34.131
unknown

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
No debug info