
Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction. Includes cookies.sqlite, ShellExecuteEx, and multiple C2 IP addresses.
Process Hacker memory analysis reveals that StealC Stealer performs process hollowing on RuntimeBroker.exe and establishes connections to multiple C2 servers.
RuntimeBroker.exe (PID 14900).http://87.120.196.171/http://95.85.251.18/http://193.148.56.97/https://31.77.9.121/
Process Hacker view showing RuntimeBroker.exe strings with C2 IP addresses.
Process Hacker memory analysis reveals an extensive list of C2 domains used by StealC Stealer for data exfiltration and command delivery.
easyjet.com – C2 domain.easythe.com – C2 domain.ebookers.com – C2 domain.ecomlead.com – C2 domain.ecruises.com – C2 domain.egroupware-italia.it – C2 domain.egroupware.de – C2 domain.egroupware.net – C2 domain.egroupware.org – C2 domain.einheiten-umrechnen.de – C2 domain.einmalmitprofits.at – C2 domain.elmerchocolate.net – C2 domain.elsevierfctch.com – C2 domain.emedixus.com – C2 domain.enverity.com – C2 domain.easyjet.com) help avoid detection.
Process Hacker view showing C2 domains used by StealC Stealer.
Process Hacker memory analysis of RuntimeBroker.exe reveals that StealC Stealer targets browser cookies and uses system manipulation APIs.
cookies.sqlite – Targets browser cookie databases (Firefox).ShellExecuteExA – Executes programs or opens files.GetSystemTimes – Retrieves system timing information.wow64base.dll – 32-bit compatibility layer (evasion).agent_version – Malware version identifier.browser_type – Identifies targeted browser.FindWindowA – Locates windows (UI interaction).CreatePipe – Creates pipes for inter-process communication.LoadLibraryA – Loads additional DLLs.cookies.sqlite confirms cookie data theft.ShellExecuteExA and CreatePipe indicate command execution.wow64base.dll helps bypass 64-bit security controls.
Process Hacker view showing cookies.sqlite, ShellExecuteExA, and other system APIs.
Binary Ninja analysis of the cookies.sqlite file reveals a list of API calls and system functions used by StealC Stealer.
GetClassNameA – Retrieves window class names (UI interaction).ShellExecuteExW – Executes programs or opens files.VirtualAlloc – Allocates memory (injection).VirtualFree – Frees memory (cleanup).GetMenuItemID – Retrieves menu item IDs (UI manipulation).IsWow64Process – Detects 32-bit process on 64-bit OS (evasion).upload_file – Uploads stolen data to C2.update_cookies – Updates cookie data (persistence).ShellExecuteExW and VirtualAlloc enable code execution.IsWow64Process helps bypass 64-bit security.upload_file confirms data theft.
Binary Ninja view showing ShellExecuteExW, VirtualAlloc, and other APIs in cookies.sqlite.
Binary Ninja analysis of the ShellExecuteEx function reveals a list of system processes, C2 communication functions, and data theft APIs used by StealC Stealer.
winlogon.exe – Targets the Windows logon process (privilege escalation).vdrsvc.exe – Targets a service process (evasion).HttpQueryInfoA – Retrieves HTTP headers (C2 communication).cookies.sqlite – Targets browser cookies (data theft).vncdll – VNC-related DLL (remote access).PeekNamedPipe – Reads data from named pipes (IPC).VirtualFree – Frees memory (cleanup).UnmapViewOfFile – Unmaps files (cleanup).GetSystemTimes – Retrieves system times (anti-debug).winlogon.exe is a high-value target.HttpQueryInfoA is used for HTTP-based C2.cookies.sqlite confirms cookie theft.vdrsvc.exe and GetSystemTimes help avoid detection.
Binary Ninja view showing winlogon.exe, HttpQueryInfoA, cookies.sqlite, and other APIs.
This analysis uncovered StealC Stealer, a sophisticated info-stealer that uses process hollowing on RuntimeBroker.exe, multiple C2 servers, and extensive data theft capabilities.
RuntimeBroker.exe (PID 14900).87.120.196.171, 95.85.251.18, 193.148.56.97, 31.77.9.121) and domains (easyjet.com, ebookers.com, ecomlead.com, etc.).cookies.sqlite for browser cookie data.ShellExecuteExA, VirtualAlloc, IsWow64Process, and GetSystemTimes.upload_file and update_cookies for sending stolen data.87.120.196.171, 95.85.251.18, 193.148.56.97, 31.77.9.121.easyjet.com, ebookers.com, ecomlead.com, etc.cookies.sqlite access from unusual processes.ShellExecuteExA and VirtualAlloc calls in RuntimeBroker.exe.The analyzed StealC Stealer sample is available on MalwareBazaar for those who wish to conduct their own analysis:
🔗 StealC Stealer Sample on MalwareBazaar
Tools Used: Process Hacker, Binary Ninja, x64dbg