Hellion.exe

Classification: Malicious

Hellion.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. IoC context and downloadable threat intel on Maltiverse.

Detection summary

  • 0 antivirus detections
  • 1 IDS alerts
  • 12 processes observed
  • 3 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Exelastealer Triage 2026-09-02 22:30:16 2026-09-02 22:30:16 malicious-activity
Generic Malware Hybrid-Analysis 2024-12-03 17:15:05 2024-12-03 17:23:09

Tags

evasive exelastealer collection credential_access defense_evasion discovery execution persistence privilege_escalation spyware stealer

Sample information

Filenames
Hellion.exe, loader.exe
File type
PE32+ executable (GUI) x86-64, for MS Windows
Size
40106496 bytes
MD5
83a8afdf31aeab3345d33e250d67031f
SHA-1
8764f19dc5ff8aff6e81d8981de131c7fa8babbf
SHA-256
3070f046294bd3e358d00022f20434a3f03ca17fcf3466d4243c36f4af940a02
First indexed
2024-12-03 16:47:41
Last updated
2026-09-02 22:55:54

Network contacts

34.117.59.81 162.159.134.233 162.159.135.233

DNS requests

discordapp.com ipinfo.io

Process list

NameCommand line
loader.exe
Stub.exeC:\loader.exe
cmd.exe/c "ver"
cmd.exe/c "wmic path win32_VideoController get name"
WMIC.exewmic path win32_VideoController get name
cmd.exe/c "wmic computersystem get Manufacturer"
WMIC.exewmic computersystem get Manufacturer
cmd.exe/c "gdb --version"
cmd.exe/c "tasklist"
tasklist.exe
cmd.exe/c "wmic path Win32_ComputerSystem get Manufacturer"
WMIC.exewmic path Win32_ComputerSystem get Manufacturer