🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7f35155b793eecfb8dc33d0505af7383ef492ce3b3cb7721e1270f2cb02e941. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



StrelaStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: f7f35155b793eecfb8dc33d0505af7383ef492ce3b3cb7721e1270f2cb02e941
SHA3-384 hash: d4a20391ed85d7bd69bceddc74d21f5014743911295ba7333e6fbcfcd6c4b2b6b393f52dcdf7ba08dd0cbdb67ed80a23
SHA1 hash: 1c51c0f46b2ad09c867c7693ceec0bea179dfe89
MD5 hash: 9a1aa0c7b509364e728c1abb3c5b8ec6
humanhash: angel-fanta-glucose-violet
File name:Rg 241105 Engin Neurologe Speyer B.pdf
Download: download sample
Signature StrelaStealer
File size:13'770 bytes
First seen:2024-12-02 10:52:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:v0xwQ0cEAzPZzHf3hlC849QiFWsVZQhzY:vkL0izfxll49Qi5KzY
TLSH T15F52C0C5AE5153E35D7C83FF3C6BCF4A296E58E214936AC6091A4A02D7DBB983CF9000
Magika zip
Reporter cocaman
Tags:pdf StrelaStealer zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Mohammad zaher Ghafar <no-reply@cynoia.app>" (likely spoofed)
Received: "from cynoia.app (unknown [41.140.17.120]) "
Date: "Sun, 01 Dec 2024 13:52:47 +0000"
Subject: "Rechnung"
Attachment: "Rg 241105 Engin Neurologe Speyer B.pdf"

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:1964927648555326306.js
File size:253'630 bytes
SHA256 hash: 80309845ae5fd64631d90cdc27cb20b71dabc8d9ba995b6a9227db802ba364ea
MD5 hash: 966a8bce0e8334e7a11ce28108be7679
MIME type:text/plain
Signature StrelaStealer
Vendor Threat Intelligence
Verdict:
Clean
Score:
89.3%
Tags:
spawn sage hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin net regsvr32 timeout
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution
Behaviour
Delays execution with timeout.exe
Runs net.exe
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

StrelaStealer

zip f7f35155b793eecfb8dc33d0505af7383ef492ce3b3cb7721e1270f2cb02e941

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
StrelaStealer

Comments