File name:

ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe

Full analysis: https://app.any.run/tasks/5f95dbde-0c74-4a02-bf78-37f1f24d6480
Verdict: Malicious activity
Threats:

Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.

Analysis date: June 05, 2026, 05:29:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
vidar
stealer
stealc
golang
attachments
attc-unc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

6A0F86528D65BE2678978F3C70D2CC51

SHA1:

463A67C48F9015BE48C111D8B383822E8F19E1DC

SHA256:

CA326AF30C7CF7A23B8B05B821DA2A9FB741A25625CE37220F9B72EE1D0CBF0F

SSDEEP:

98304:hRh8Sub5lwUpL08o6YoQ1HIhjW5Vqhfk+UQnirw32YKu/P7:hR0FeGv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • VIDAR has been found (auto)

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Actions looks like stealing of personal data

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Steals credentials from Web Browsers

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • STEALC has been detected (SURICATA)

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • VIDAR has been detected (SURICATA)

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
  • SUSPICIOUS

    • Searches for installed software

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Possible stealing from crypto wallets

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Contacting a server suspected of hosting an CnC

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Possible stealing from password managers

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Possible stealing of email data

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Browser headless start

      • firefox.exe (PID: 5828)
      • chrome.exe (PID: 5916)
      • msedge.exe (PID: 7148)
      • msedge.exe (PID: 7316)
      • firefox.exe (PID: 9156)
      • msedge.exe (PID: 1552)
      • chrome.exe (PID: 8248)
    • Possible stealing from browsers

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Browser launch with unusual user-data-dir

      • chrome.exe (PID: 5916)
      • msedge.exe (PID: 7316)
      • msedge.exe (PID: 7148)
      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • The process verifies whether the antivirus software is installed

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Possible stealing of FTP data

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Starts CMD.EXE with special quote handling

      • cmd.exe (PID: 4288)
      • cmd.exe (PID: 7884)
      • cmd.exe (PID: 3096)
    • Possible stealing of cloud data

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • The process deletes folder without confirmation

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 7884)
      • cmd.exe (PID: 4288)
      • cmd.exe (PID: 3096)
    • Starts CMD.EXE with output disabled

      • cmd.exe (PID: 4288)
      • cmd.exe (PID: 7884)
      • cmd.exe (PID: 3096)
  • INFO

    • Checks supported languages

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
      • identity_helper.exe (PID: 1172)
      • identity_helper.exe (PID: 8452)
    • Reads the computer name

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
      • identity_helper.exe (PID: 1172)
      • identity_helper.exe (PID: 8452)
    • Reads Environment values

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
      • identity_helper.exe (PID: 1172)
      • identity_helper.exe (PID: 8452)
    • Reads product name

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Reads CPU info

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Application launched itself

      • chrome.exe (PID: 8644)
      • chrome.exe (PID: 8848)
      • msedge.exe (PID: 6936)
      • msedge.exe (PID: 5564)
      • msedge.exe (PID: 8808)
      • msedge.exe (PID: 2356)
      • msedge.exe (PID: 7316)
      • firefox.exe (PID: 5828)
      • chrome.exe (PID: 5916)
      • msedge.exe (PID: 7148)
      • firefox.exe (PID: 9156)
    • Application based on Golang

      • ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe (PID: 6944)
    • Manual execution by a user

      • mspaint.exe (PID: 7316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 579584
InitializedDataSize: 40448
UninitializedDataSize: -
EntryPoint: 0x71f00
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
247
Monitored processes
93
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start #STEALC ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs chrome.exe msedge.exe no specs msedge.exe firefox.exe chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs mspaint.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
484"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3532,i,8604316020786078732,3773446103576415567,262144 --variations-seed-version --mojo-platform-channel-handle=3676 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
656"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\noeUpate\632f9740" --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3108,i,1033271662386003133,7884647635837173107,262144 --disable-features=PaintHolding --variations-seed-version --disable-logging --log-level=3 --mojo-platform-channel-handle=3096 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
996"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\noeUpate\86b0ed49" --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=14 --always-read-main-dll --field-trial-handle=4992,i,3290193460174139086,13735680107115246377,262144 --disable-features=PaintHolding --variations-seed-version --disable-logging --log-level=3 --mojo-platform-channel-handle=4980 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1136"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6248,i,8604316020786078732,3773446103576415567,262144 --variations-seed-version --mojo-platform-channel-handle=6196 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5776,i,8604316020786078732,3773446103576415567,262144 --variations-seed-version --mojo-platform-channel-handle=5872 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1552"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6436,i,8604316020786078732,3773446103576415567,262144 --variations-seed-version --mojo-platform-channel-handle=6248 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1552"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --headless --string-annotations --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\noeUpate\86b0ed49" --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2308,i,3290193460174139086,13735680107115246377,262144 --disable-features=PaintHolding --variations-seed-version --disable-logging --log-level=3 --mojo-platform-channel-handle=2184 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\noeUpate\86b0ed49 /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\noeUpate\86b0ed49\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x2a4,0x2a8,0x2ac,0x29c,0x2b4,0x7ffe256bf208,0x7ffe256bf214,0x7ffe256bf220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2320"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5776,i,8604316020786078732,3773446103576415567,262144 --variations-seed-version --mojo-platform-channel-handle=5872 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
Total events
3 205
Read events
3 175
Write events
29
Delete events
1

Modification events

(PID) Process:(6944) ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:TS_26b799fa
Value:
885EBBA
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:WindowPlacement
Value:
2C00000000000000010000000000000000000000FFFFFFFFFFFFFFFF870000004C000000C7040000B2020000
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:ShowThumbnail
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:BMPWidth
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:BMPHeight
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:ThumbXPos
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:ThumbYPos
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:ThumbWidth
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:ThumbHeight
Value:
0
(PID) Process:(7316) mspaint.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\View
Operation:writeName:UnitSetting
Value:
0
Executable files
0
Suspicious files
327
Text files
454
Unknown types
0

Dropped files

PID
Process
Filename
Type
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF15bbf7.TMP
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF15bc06.TMP
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF15bc06.TMP
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF15bc16.TMP
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF15bc06.TMP
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
8644chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF15bc16.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
159
TCP/UDP connections
101
DNS requests
107
Threats
40

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
GET
200
149.154.167.99:443
https://telegram.me/g75rit
VG
html
12.0 Kb
unknown
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
19.3 Kb
malicious
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
43 b
malicious
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
2.27 Kb
malicious
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
2.81 Kb
malicious
9108
svchost.exe
POST
200
20.190.160.20:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
440 b
malicious
9108
svchost.exe
POST
400
20.190.160.20:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
9108
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
POST
200
188.114.97.3:443
https://mub.matriculaflix.com/
US
text
2 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
6140
svchost.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
149.154.167.99:443
telegram.me
TELEGRAM
VG
whitelisted
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
188.114.97.3:443
mub.matriculaflix.com
CLOUDFLARENET
US
whitelisted
9108
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
9108
svchost.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.189
  • 57.153.246.3
  • 48.209.138.168
  • 48.209.133.15
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.20.100
  • 142.251.20.139
  • 142.251.20.102
  • 142.251.20.113
  • 142.251.20.101
  • 142.251.20.138
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
cap.xyzsm188.top
malicious
telegram.me
  • 149.154.167.99
whitelisted
mub.matriculaflix.com
  • 188.114.97.3
  • 188.114.96.3
unknown
login.live.com
  • 20.190.160.20
  • 20.190.160.66
  • 40.126.32.72
  • 20.190.160.14
  • 40.126.32.136
  • 20.190.160.4
  • 20.190.160.3
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1
6140
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
A Network Trojan was detected
ET MALWARE Vidar Stealer Form Exfil
6944
ca326af30c7cf7a23b8b05b821da2a9fb741a25625ce37220f9b72ee1d0cbf0f.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local directory exists )
msedge.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\noeUpate directory exists )