🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 992221ef0c2f7c48366c7abc69771bc1a5ce8da3571ff6f2995534eb8284ea2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



StrelaStealer


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 992221ef0c2f7c48366c7abc69771bc1a5ce8da3571ff6f2995534eb8284ea2f
SHA3-384 hash: 66af2a916455cd725d151bf998b300ecc461e81d9fbf78acba0a967dd186e2eaf84a03c10d25dfd7562f50fc5fac671a
SHA1 hash: 2452fbff52a5a45f537dc3c1b0bc4cbc1ebc96f8
MD5 hash: f92d34a5983c7db09c14638fb6bf6dd8
humanhash: illinois-hamper-arkansas-spaghetti
File name:RÜ24-01-0056_99841.pdf
Download: download sample
Signature StrelaStealer
File size:3'453 bytes
First seen:2025-01-16 09:09:19 UTC
Last seen:2025-01-16 09:09:29 UTC
File type: zip
MIME type:application/zip
ssdeep 96:wtbyH6Yl9PB4ywU1bA3g6YrVEGw2ww/GEssDer:+Y6Yl9JpwU5Qg1rmIwEJsRr
TLSH T1CE616E45B59930C5FC6740B2859719174CA0D09F993FB702B9C9A2ADEB4C1246E61183
Magika zip
Reporter cocaman
Tags:pdf StrelaStealer zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Waldbesitzervereinigung Bamberg e.V. <no-reply@juanfernandoaristizabal.com>" (likely spoofed)
Received: "from juanfernandoaristizabal.com (unknown [38.255.111.157]) "
Date: "Thu, 16 Jan 2025 04:27:56 +0000"
Subject: "Abrechnung Teil 1 Hieb Kemmern "
Attachment: "RÜ24-01-0057_99841.pdf"

Intelligence


File Origin
# of uploads :
2
# of downloads :
198
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:19733185115407135.js
File size:34'225 bytes
SHA256 hash: d0de0e423dc367457c282564ec49d21c50482e3597c80de6377a771d56317bac
MD5 hash: 26618cc4d865ed0118b16afb1d9a70ec
MIME type:text/plain
Signature StrelaStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
malware
Threat name:
Script-JS.Trojan.StrelaStealer
Status:
Malicious
First seen:
2025-01-16 09:09:21 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

StrelaStealer

zip 992221ef0c2f7c48366c7abc69771bc1a5ce8da3571ff6f2995534eb8284ea2f

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
StrelaStealer

Comments