🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7e2c82354f06b92c115df9f87ba3dd53014148b4869f20ec8eb59563dba1839. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



StrelaStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: d7e2c82354f06b92c115df9f87ba3dd53014148b4869f20ec8eb59563dba1839
SHA3-384 hash: 888381613040cd5001647e1929c114d73c216ad35d0be7cebabe27eb710efc72c1f941df5bd803e507f1382f0576c471
SHA1 hash: ac8ef80474ac7d16abf4f51d933f567449bbea9e
MD5 hash: 3a7538436507a1920311f25ce23130e2
humanhash: march-failed-iowa-mike
File name:Knödelfein_B2B_Produktblatt.pdf
Download: download sample
Signature StrelaStealer
File size:2'417 bytes
First seen:2025-01-23 08:07:43 UTC
Last seen:2025-01-23 08:07:56 UTC
File type: zip
MIME type:application/zip
ssdeep 48:9n7QGSXocV5+XDDYhPbRDpT+eTZKlbcQiGZUjH21kjwve2/:FQGShV5+mTRDpTvKl/bam
TLSH T114413BD0F36A1BCCCA7224BF288421E363173F1208A3D59E4024CFF5405315A6E701BB
Magika zip
Reporter cocaman
Tags:pdf StrelaStealer zip


Avatar
cocaman
Malicious email (T1566.001)
From: "=?utf-8?B?SW5mbyB8IEtuw7ZkZWxmZWlu?= <no-reply@artegur.com>" (likely spoofed)
Received: "from artegur.com (static-host119-73-110-249.link.net.pk [119.73.110.249]) "
Date: "Thu, 23 Jan 2025 06:39:34 +0000"
Subject: "
=?utf-8?B?UmVjaG51bmc6IFJFODg5NyB2b20gMTEuMTEuMjQgICYgd2VpdGVyZSBJbmZv?=
=?utf-8?B?cm1hdGlvbmVuIHp1IEtuw7ZkZWxmZWlu?="
Attachment: "SEPA-Formular_Knödelfein_2024.pdf"

Intelligence


File Origin
# of uploads :
2
# of downloads :
152
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:1381588752653310337.js
File size:29'760 bytes
SHA256 hash: f38bfbe36f6b184d79b16dae57c197851f784580a29dcb2714a0373630efa84f
MD5 hash: d93a215776017621e3c7e22e77e3c7d7
MIME type:text/plain
Signature StrelaStealer
Vendor Threat Intelligence
Threat name:
Script-JS.Trojan.StrelaStealer
Status:
Malicious
First seen:
2025-01-23 08:07:46 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

StrelaStealer

zip d7e2c82354f06b92c115df9f87ba3dd53014148b4869f20ec8eb59563dba1839

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments