Classification: Malicious
Hellion.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. IoC context and downloadable threat intel on Maltiverse.
Detection summary
- 0 antivirus detections
- 1 IDS alerts
- 12 processes observed
- 3 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Exelastealer |
Triage |
2026-09-02 22:30:16 |
2026-09-02 22:30:16 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2024-12-03 17:15:05 |
2024-12-03 17:23:09 |
|
|
Tags
evasive
exelastealer
collection
credential_access
defense_evasion
discovery
execution
persistence
privilege_escalation
spyware
stealer
Sample information
- Filenames
- Hellion.exe, loader.exe
- File type
- PE32+ executable (GUI) x86-64, for MS Windows
- Size
- 40106496 bytes
- MD5
83a8afdf31aeab3345d33e250d67031f
- SHA-1
8764f19dc5ff8aff6e81d8981de131c7fa8babbf
- SHA-256
3070f046294bd3e358d00022f20434a3f03ca17fcf3466d4243c36f4af940a02
- First indexed
- 2024-12-03 16:47:41
- Last updated
- 2026-09-02 22:55:54
Process list
| Name | Command line |
| loader.exe | |
| Stub.exe | C:\loader.exe |
| cmd.exe | /c "ver" |
| cmd.exe | /c "wmic path win32_VideoController get name" |
| WMIC.exe | wmic path win32_VideoController get name |
| cmd.exe | /c "wmic computersystem get Manufacturer" |
| WMIC.exe | wmic computersystem get Manufacturer |
| cmd.exe | /c "gdb --version" |
| cmd.exe | /c "tasklist" |
| tasklist.exe | |
| cmd.exe | /c "wmic path Win32_ComputerSystem get Manufacturer" |
| WMIC.exe | wmic path Win32_ComputerSystem get Manufacturer |