🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80309845ae5fd64631d90cdc27cb20b71dabc8d9ba995b6a9227db802ba364ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



StrelaStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 80309845ae5fd64631d90cdc27cb20b71dabc8d9ba995b6a9227db802ba364ea
SHA3-384 hash: ce8863c42c06eeb860d12e868e77c44828e9105027417b990f81fd75b7023e0249b4751d0386fbaa43443069b185d96d
SHA1 hash: 5a167a06ae4ca755678cc5ad3ccf157d1c83586e
MD5 hash: 966a8bce0e8334e7a11ce28108be7679
humanhash: aspen-fifteen-quebec-uranus
File name:1964927648555326306.js
Download: download sample
Signature StrelaStealer
File size:253'630 bytes
First seen:2024-12-02 10:52:34 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:2dGOQJ1DAeBCrjAqi4ri0hMsvbjQ6T/ioQ6nbyfqeya2bldeNc7syIoSFWa7/GME:s
TLSH T1D844E1F08622B6BD7532D3381606080B9691FACF3DFC1E6CDC19649A25F637E0177A99
Magika javascript
Reporter cocaman
Tags:js StrelaStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
449
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Clean
Score:
89.3%
Tags:
spawn sage hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin net regsvr32 timeout
Result
Threat name:
Strela Downloader
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
72 / 100
Signature
Gathers information about network shares
JScript performs obfuscated calls to suspicious functions
Sigma detected: WScript or CScript Dropper
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected Strela Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1566537 Sample: 1964927648555326306.js Startdate: 02/12/2024 Architecture: WINDOWS Score: 72 26 Yara detected Strela Downloader 2->26 28 Uses known network protocols on non-standard ports 2->28 30 Sigma detected: WScript or CScript Dropper 2->30 8 wscript.exe 1 1 2->8         started        process3 signatures4 32 JScript performs obfuscated calls to suspicious functions 8->32 34 Windows Scripting host queries suspicious COM object (likely to drop second stage) 8->34 36 Gathers information about network shares 8->36 11 cmd.exe 1 8->11         started        process5 signatures6 38 Gathers information about network shares 11->38 14 cmd.exe 1 11->14         started        17 conhost.exe 11->17         started        19 timeout.exe 1 11->19         started        process7 signatures8 40 Gathers information about network shares 14->40 21 net.exe 1 14->21         started        process9 dnsIp10 24 94.159.113.84, 49730, 8888 NETCOM-R-ASRU Russian Federation 21->24
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution
Behaviour
Delays execution with timeout.exe
Runs net.exe
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

StrelaStealer

Java Script (JS) js 80309845ae5fd64631d90cdc27cb20b71dabc8d9ba995b6a9227db802ba364ea

(this sample)

  
Delivery method
Other

Comments