Task Information
Task ID: 377c1fa4-2071-11f1-b47f-42010aa4000b
File name: 400000.xb7165e7214e7c7b16a35095f8649f1ec7e13541395f1.exe
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: command_and_control
Alert
Author: CD_R0M_
Description: This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
TLP: TLP:WHITE
Repository: CD-R0M
Rule name: DebuggerCheck__API
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: DebuggerCheck__QueryInfo
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: Detect_PowerShell_Obfuscation
Alert
Author: daniyyell
Description: Detects obfuscated PowerShell commands commonly used in malicious scripts.
TLP: TLP:WHITE
Repository: YARAify
Rule name: DetectEncryptedVariants
Alert
Author: Zinyth
Description: Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP: TLP:WHITE
Repository: YARAify
Rule name: FreddyBearDropper
Alert
Author: Dwarozh Hoshiar
Description: Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP: TLP:WHITE
Repository: YARAify
Rule name: infostealer_win_stealc_standalone
Alert
Description: Find standalone Stealc sample based on decryption routine or characteristic strings
Reference: https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/
TLP: TLP:WHITE
Repository:
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Rule name: malware_Stealc_str
Alert
Author: JPCERT/CC Incident Response Group
Description: Stealc infostealer
TLP: TLP:WHITE
Repository: JPCERTCC
Rule name: Stealc
Alert
Author: kevoreilly
Description: Stealc Payload
TLP: TLP:WHITE
Repository: CAPE
Rule name: Stealer_Stealc
Alert
Author: Still
Description: attempts to match instructions/strings found in Stealc
TLP: TLP:WHITE
Repository: YARAify
Rule name: Sus_CMD_Powershell_Usage
Alert
Author: XiAnzheng
Description: May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: Suspicious_Process
Alert
Author: Security Research Team
Description: Suspicious process creation
TLP: TLP:WHITE
Repository: YARAify
Rule name: WIN_FileFix_Detection
Alert
Author: dogsafetyforeverone
Description: Detects FileFix social engineering technique that launches chained PowerShell and PHP commands from file explorer typed paths
Reference: FileFix social engineering with PowerShell and PHP commands
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
TLP : TLP:AMBER
Rule name: win_stealc_w0
Alert
Author: crep1x
Description: Find standalone Stealc sample based on decryption routine or characteristic strings
Reference: https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/
TLP: TLP:WHITE
Repository: Malpedia
Rule name: WIN_WebSocket_Base64_C2_20250726
Alert
Author: dogsafetyforeverone
Description: Detects configuration strings used by malware to specify WebSocket command-and-control endpoints inside Base64-encoded data. It looks for prefixes such as '#ws://' or '#wss://' that were found in QuasarRAT configuration data.
TLP: TLP:WHITE
Repository: YARAify
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter