s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed high

📛 Threat Title

Stealc: SacramentoZum.exe

Category: Stealc Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2240000 bytes. Tags: 160-20-109-90, AsgardProtector, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:59.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 013c74198fc6e42dcf33737d6c40c012

IOC database

Type
hash_imphash
Value
013c74198fc6e42dcf33737d6c40c012
First seen
Last seen
Attached to this threat
Appears in
27 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed

IOC database

Type
hash_sha256
Value
4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Stealc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 03e70215222767e6fde4a379b7979d31bf5f12ef

IOC database

Type
hash_sha1
Value
03e70215222767e6fde4a379b7979d31bf5f12ef
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 25d4dc16ff90dad6221c7846336f357f

IOC database

Type
hash_md5
Value
25d4dc16ff90dad6221c7846336f357f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2240000 bytes. Tags: 160-20-109-90, AsgardProtector, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:59.

Remediations (10)

  • web:airheads.hpe.com

    StealC is a commodity information‑stealer offered as Malware‑as‑a‑Service (MaaS). It emerged in early 2023 and has evolved with newer versions introducing RC4‑protected strings and traffic.

  • web:cybersecuritynews.com

    This shellcode then loads a custom PE downloader compiled with Microsoft Visual C++ that retrieves the final StealC payload and injects it into svchost.exe, a legitimate Windows service process. StealC communicates with its command-and-control server using HTTP traffic encrypted with Base64 and RC4 encoding.

  • web:dailysecurityreview.com

    StealC malware receives major upgrade with advanced stealth, encryption, and data theft tools, including real-time Telegram alerts and full desktop screenshot capabilities.

  • web:foresiet.com

    By December 2025, Stealc's V2 iteration has amplified its reach through innovative distribution vectors, including 3D modeling assets and malvertising. This analysis dissects Stealc's mechanics, campaigns, indicators of compromise (IOCs), and mitigation strategies, highlighting its role in the broader infostealer ecosystem.

  • web:socprime.com

    Attack Narrative & Commands: An adversary has successfully dropped a malicious executable named StealC .exe. To evade simple signature-based detection and attempt to hide its injection routine, the malware is designed to call its internal functions by passing the name of the required Windows APIs as command-line arguments to a sub-process.

  • web:www.microsoft.com

    To defend against attacks from infostealers like StealC and malware families like Amadey, Microsoft recommends the following mitigation measures: Read the human-operated ransomware threat overview for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations.

  • web:www.pcrisk.com

    Stealc is designed to steal vulnerable data from infected systems and the applications and extensions installed on them. Typically, these kinds of infections can result in severe privacy issues, financial losses, and identity theft.

  • web:www.s2w.inc

    Recommended Threat Detection and Mitigation Actions: StealC V2 is a highly advanced infostealer equipped with dynamic configuration, server-side decryption, evasion techniques, and support for flexible payload execution.

  • web:www.shadowserver.org

    StealC Historical Bot Infections - Data Analysis Our new one-off StealC Historical Bot Infections Special Report contained information provided by the Dutch National High Tech Crime Unit (NHTCU) covering the period between 4th July 2025 and 16th June 2026.

  • web:www.zscaler.com

    New features StealC V1 was capable of executing EXE and DLL files. StealC V2 now supports downloading and executing payloads in three formats: executable (EXE) files, Microsoft Software Installer (MSI) packages, and PowerShell scripts.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.