Managed XDR

scratch-zoo-2025-04-22...c6fca9d9cf26ad0fcafe72 (Stealc) — malware analysis report

File info

Filename
scratch-zoo-2025-04-22-4cf06a23b9c6fca9d9cf26ad0fcafe72
File type
gzip compressed data
File size
128.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
99aa79d9295050efc21872f0028ac9e959f18aab
SHA256
907c045df13697423ca0cdcd2778e07743e1bddf740cb942598d76b260e4523e
MD5
4cf06a23b9c6fca9d9cf26ad0fcafe72

Malwares

  • Stealc

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
origin_langid: Unconventional language of the executable file

Related reports