Open-source atomic malware analysis

Analyze another

fa608193e8f5c475f7120317f319eb77ea199ddb7d8ddef58b4580181d4b763b

PE
Verdict: HOSTILE
AI Stealer with anti-analysis and importless loader
Mal-ecule
O₂(AlAs)Md(Bi₂)
Size 1.0 MB download
First seen 1 day ago
Analyzed 1 day ago
Ecosystem windows
Source abuse.ch
Also detected by 2 sources
Importless PE combines PEB or NT anti-debugging with executable memory: mystic_stealer.exe:0x0
Importless PE resolves APIs through a PEB hash loader: mystic_stealer.exe:0x0
mystic_stealer.exe pe
0x0 4d5a90000300000004000000ffff0000 MZ..............Importless PE combines PEB or NT anti-debugging with executable memory
0x10 b8000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000080020000 ................
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!Th
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 742062652072756e20696e20444f5320 t be run in DOS
0x70 6d6f64652e0d0d0a2400000000000000 mode....$.......
0x80 58d22d721cb343211cb343211cb34321 X.-r..C!..C!..C!
0x90 d4c640201d ..@ .
0x14a0 62e8fe8a0800488b5d58488bd04c8bc3 b.....H.]XH..L..
0x14b0 41b940000000498bcde802a70f00e835 A.@...I........5Importless PE resolves APIs through a PEB hash loader
0x14c0 8d0800488bd04c8d434041b980000000 ...H..L.C@A.....
0x14d0 498b I.
0x49de 587d33db498943184c8bc9c644246652 X}3.I.C.L...D$fR
0x49ee 65488b0425600000004885c90f849300 eH..%`...H......Importless PE combines PEB or NT anti-debugging with executable memory
0x49fe 000085d20f8e8b0000004885c00f8482 ..........H.....
0x4a0e 000000488b40204885c074794c8b5868 ...H.@ H..tyL.Xh
0x4a1e 4d85db74706639586074 M..tpf9X`t
0x6144 0300004981f217885a224c8954246044 ...I....Z"L.T$`D
0x6154 8b4b3c4533c0c7859003000082cba29b .K<E3...........Importless PE resolves APIs through a PEB hash loader
0x6164 8b8d900300008b8590030000c1f91f33 ...............3
0x6174 c149 .I
0x104b7 8bc3b901000000e84d24ffff8d041f41 ........M$.....A
0x104c7 ba070000008986002000004c8d45dcc7 ........ ..L.E..Importless PE combines PEB or NT anti-debugging with executable memory
0x104d7 45d824362ce74c8d4dd8c745dc280d82 E.$6,.L.M..E.(..
0x104e7 22c745e0e5546322c745e45575ff ".E..Tc".E.Uu.

Objectives

Micro-behaviors

Metadata

Identity

SHA-256 fa608193e8f5c475f7120317f319eb77ea199ddb7d8ddef58b4580181d4b763b
Filename mystic_stealer.exe
Package fa608193e8f5c475f7120317f319eb77ea199ddb7d8ddef58b4580181d4b763b

Origin

Source harvest
Feed malwarebazaar
Ecosystem windows
Domain abuse.ch

Timeline

First seen 23 Jul 2026 10:38 UTC
First analyzed 23 Jul 2026 10:48 UTC
Last analyzed 23 Jul 2026 12:37 UTC
Last updated 23 Jul 2026 12:37 UTC

Labeling

Label bad
Label source harvest
Traits version 2065e