MB-4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed
high
📛 Threat Title
Stealc: SacramentoZum.exe
Description
File type: exe. Size: 2240000 bytes. Tags: 160-20-109-90, AsgardProtector, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:59.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
013c74198fc6e42dcf33737d6c40c012
IOC database
- Type
- hash_imphash
- Value
013c74198fc6e42dcf33737d6c40c012- First seen
- Last seen
- Attached to this threat
- Appears in
- 27 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed
IOC database
- Type
- hash_sha256
- Value
4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Stealc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
03e70215222767e6fde4a379b7979d31bf5f12ef
IOC database
- Type
- hash_sha1
- Value
03e70215222767e6fde4a379b7979d31bf5f12ef- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
25d4dc16ff90dad6221c7846336f357f
IOC database
- Type
- hash_md5
- Value
25d4dc16ff90dad6221c7846336f357f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2240000 bytes. Tags: 160-20-109-90, AsgardProtector, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:59.
Remediations (10)
-
web:airheads.hpe.com
StealC is a commodity information‑stealer offered as Malware‑as‑a‑Service (MaaS). It emerged in early 2023 and has evolved with newer versions introducing RC4‑protected strings and traffic.
-
web:cybersecuritynews.com
This shellcode then loads a custom PE downloader compiled with Microsoft Visual C++ that retrieves the final StealC payload and injects it into svchost.exe, a legitimate Windows service process. StealC communicates with its command-and-control server using HTTP traffic encrypted with Base64 and RC4 encoding.
-
web:dailysecurityreview.com
StealC malware receives major upgrade with advanced stealth, encryption, and data theft tools, including real-time Telegram alerts and full desktop screenshot capabilities.
-
web:foresiet.com
By December 2025, Stealc's V2 iteration has amplified its reach through innovative distribution vectors, including 3D modeling assets and malvertising. This analysis dissects Stealc's mechanics, campaigns, indicators of compromise (IOCs), and mitigation strategies, highlighting its role in the broader infostealer ecosystem.
-
web:socprime.com
Attack Narrative & Commands: An adversary has successfully dropped a malicious executable named StealC .exe. To evade simple signature-based detection and attempt to hide its injection routine, the malware is designed to call its internal functions by passing the name of the required Windows APIs as command-line arguments to a sub-process.
-
web:www.microsoft.com
To defend against attacks from infostealers like StealC and malware families like Amadey, Microsoft recommends the following mitigation measures: Read the human-operated ransomware threat overview for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations.
-
web:www.pcrisk.com
Stealc is designed to steal vulnerable data from infected systems and the applications and extensions installed on them. Typically, these kinds of infections can result in severe privacy issues, financial losses, and identity theft.
-
web:www.s2w.inc
Recommended Threat Detection and Mitigation Actions: StealC V2 is a highly advanced infostealer equipped with dynamic configuration, server-side decryption, evasion techniques, and support for flexible payload execution.
-
web:www.shadowserver.org
StealC Historical Bot Infections - Data Analysis Our new one-off StealC Historical Bot Infections Special Report contained information provided by the Dutch National High Tech Crime Unit (NHTCU) covering the period between 4th July 2025 and 16th June 2026.
-
web:www.zscaler.com
New features StealC V1 was capable of executing EXE and DLL files. StealC V2 now supports downloading and executing payloads in three formats: executable (EXE) files, Microsoft Software Installer (MSI) packages, and PowerShell scripts.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.