
One Build, Four AV Labels: Inside a Stealer Masquerade Pipeline
Four files carrying different antivirus family labels—Injuke, ClipBanker, StealC, Mikey—share an identical imphash and rich header hash, revealing a single build pipeline masquerading as svchost.exe and other core Windows processes. The operation pairs this fragmentation trick with a signed-but-expired BYOVD driver and a CMSTP UAC bypass, backstopped by disposable AS214351 infrastructure.
Four files carrying four different antivirus threat labels — trojan.injuke/hrgx, trojan.clipbanker/hrgz, trojan.stealc/stealer, and trojan.mikey/clipbanker — turn out, on closer inspection, to be the same binary wearing different clothes. All four share an identical import-table hash (75c410d3cdd17cf4a33ccaf94384484f) and an identical rich PE header hash (dee6ab558f324ac40038942e3c424ed4), a level of structural identity that has nothing to do with coincidence and everything to do with a single…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read