typeanalysisfamilystealcconfidencehighcreated2026-07-26updated2026-07-26
SHA-256: cace58e8cbbc1ea316d590f6762c516aecd314bc8499f9b819f3f76cfd4d84d3

cace58e8 — Stealc Infostealer (C++ MSVC 14.43)

1. Build / RE

Toolchain: MSVC 14.43 (VS 2022) C++ console PE32, compiled Mon Mar 9 08:25:13 2026 UTC ^[rabin2-info.txt]. Linker version 14.43 / 0xE2B, COMPILER=msvc-1943 string confirms VS 2022 toolchain ^[strings.txt:1082]. Genuine timestamp — no evidence of backdating.

Packing / Obfuscation: None. No packer, crypter, or obfuscator. PE sections are clean: .text entropy 6.67, .rdata 5.70, .data 2.68 ^[pefile.txt]. No encrypted overlay, no reflective loader shellcode. Raw binary is the payload.

Anti-analysis: None observed. No anti-VM, anti-debug, timing gates, or sandbox checks. IsDebuggerPresent imported (standard UCRT) but not used in a detection loop. No TLS callbacks, no SEH anti-disasm.

Code quality: High-quality C++ with full MSVC RTTI (Type Descriptor, Class Hierarchy Descriptor, Complete Object Locator) ^[strings.txt:979-983]. POGO (Profile-Guided Optimization) debug directory present (IMAGE_DEBUG_TYPE_POGO) ^[pefile.txt:623]. GuardCF enabled (GuardFlags: 0x100) ^[pefile.txt:583]. Canary (__security_cookie) at 0x51D080 ^[pefile.txt:576]. These are legitimate compiler hardening features, not anti-analysis.

Embedded resources: Massive SQLite 3.x engine statically linked. Full SQLite virtual-machine opcode strings (SeekLT, SorterSort, InitCoroutine, VUpdate, OpenPseudo, etc.) span lines 1118-1235 ^[strings.txt]. sqlite_master, sqlite_sequence, sqlite_rename_table, sqlite_altertab_%s all present ^[strings.txt:1424-1514]. Binwalk confirms SQLite 3.x database signature at raw offset 0x116CF4 ^[binwalk.txt]. This suggests local credential/database staging in an embedded SQLite store.

Signing: Unsigned. Checksum zero in optional header; no security directory ^[pefile.txt:66].

VS_VERSIONINFO: Absent. .rsrc section contains only one RT_MANIFEST resource (0x18 bytes of XML manifest data) ^[pefile.txt:519-553]. No RT_VERSION block — stripped or never compiled with version info.

Notable functions: main at 0x405E50 ^[rabin2:entrypoint]. Entrypoint 0x4AD241 is standard UCRT CRT startup (__scrt_common_main_seh). main opens a named pipe \\.\\pipe\\ssstealer via CreateFileW ^[r2:main@0x405E50], builds %TEMP%\\keyboard.txt and %TEMP%\\keylogall.txt paths via wsprintfW, and checks existence with PathFileExistsW.

2. Deploy / ATT&CK

TTPs:

Technique ID Evidence
Input Capture: Keylogging T1056.001 %s:keyboard.txt: and %s:keylogall.txt: format strings; temp-path construction in main ^[strings.txt:1041-1042] ^[r2:main]
Credentials from Password Stores T1555 %ws\\AppData\\Local\\%ws\\User Data\\%ws\\Local Extension Settings\\%ws — targets Chromium extension local storage ^[strings.txt:1045]
Steal Crypto Wallet T1649 BIP-39 seed-phrase regex: ([a-z]{1,3}\\S?[a-z0-9]{2,7}\\s){11} and variants ^[strings.txt:1078-1081]; %hs:ledger format string ^[strings.txt:1072]
Inter-Process Communication T1559 Named pipe \\.\\pipe\\ssstealer opened in main ^[r2:main]
Application Layer Protocol: Web T1071.001 WINHTTP.dll imports (WinHttpOpen, WinHttpConnect, WinHttpSendRequest, WinHttpReadData) ^[rabin2:imports]
Exfiltration Over C2 T1041 HTTPS C2 sport-zb.osptoe.cn/ ^[strings.txt:1065]; backup/alternate exfil cgres.oss-cn-hongkong.aliyuncs.com (Aliyun OSS) ^[strings.txt:1068]
Data Encrypted for Impact T1486 CryptEncrypt, CryptDecrypt, CryptImportKey, CryptSetKeyParam via ADVAPI32 ^[rabin2:imports]
Data Encoding T1132 CryptBinaryToStringA (Base64) via CRYPT32 ^[rabin2:imports]
OS Credential Dumping T1003 GetUserNameW ^[rabin2:imports]; SQLite local store for credential aggregation

Persistence: None observed statically. No registry Run keys, no scheduled tasks, no service creation. Stealc typically relies on the loader (often an AutoIt or NSIS dropper) to establish persistence; this binary is the payload, not the dropper.

C2 Protocol: WINHTTP-based HTTPS. Primary domain sport-zb.osptoe.cn/ ^[strings.txt:1065]. Secondary/alternate exfil endpoint cgres.oss-cn-hongkong.aliyuncs.com — Aliyun Object Storage Service in Hong Kong region ^[strings.txt:1068]. No hardcoded port or full URL path recovered; likely constructed at runtime. from_client_type and presence- strings suggest structured JSON/protobuf C2 messaging ^[strings.txt:1052-1053].

Lateral movement: None observed. Single-process infostealer; no SMB, RDP, PSExec, or WMI imports.

Attribution: High-confidence Stealc family. The ssstealer pipe name is a known Stealc artifact. Seed-phrase regex, Chromium extension targeting, SQLite local store, and WINHTTP C2 all align with public Stealc analysis (e.g., Sekoia, Group-IB reports). The xp.dll init finish string ^[strings.txt:1070] and rkbf,3 ^[strings.txt:1055] are also Stealc plugin/debug markers observed in other samples. The Longrun Financial Group Limited string ^[strings.txt:1047] and \\foundertype\\ path ^[strings.txt:1048] suggest a builder-generated fake company masquerade.

Static vs dynamic: This is a static-only analysis (CAPE skipped — no Windows guest). All C2, keylogging, and credential-theft capabilities are inferred from strings and import table. The actual exfil payload format, encryption scheme, and C2 response protocol would require runtime confirmation.

Indicators

  • C2 domain: sport-zb.osptoe.cn
  • Exfil/alternate: cgres.oss-cn-hongkong.aliyuncs.com
  • Named pipe: \\.\\pipe\\ssstealer
  • Keylog files: %TEMP%\\keyboard.txt, %TEMP%\\keylogall.txt
  • Builder masquerade: Longrun Financial Group Limited
  • Compiler: MSVC 14.43 (VS 2022), Mar 2026 build
  • YARA: Suspicious_Crypto_Imports ^[yara.txt]