Malware analysis report: Stealc stealer - part 1
Tags
country: | Belgium Uzbekistan Russia |
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Python - T1059.006 Server - T1583.004 Server - T1584.004 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 3adc00b4-d261-41cb-8b3c-09f4000f36b7 |
Fingerprint | a9a2f0530fbca483 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Nov. 9, 2023, 9:05 p.m. |
Added to db | Aug. 31, 2024, 7:22 a.m. |
Last updated | Nov. 17, 2024, 6:53 p.m. |
Headline | Malware analysis report: Stealc stealer - part 1 |
Title | Malware analysis report: Stealc stealer - part 1 |
Detected Hints/Tags/Attributes | 65/3/16 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 175 | ✔ | MSSP Research Lab | https://mssplab.github.io/feed.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 7 | infile.read |
|
Details | Domain | 48 | pefile.pe |
|
Details | Domain | 13 | section.name |
|
Details | Domain | 1 | www.fff-ttt.com |
|
Details | Domain | 911 | any.run |
|
Details | Domain | 96 | malpedia.caad.fkie.fraunhofer.de |
|
Details | Domain | 4 | farghlymal.github.io |
|
Details | Domain | 1373 | twitter.com |
|
Details | File | 533 | ntdll.dll |
|
Details | File | 3 | kerenl32.dll |
|
Details | File | 748 | kernel32.dll |
|
Details | File | 5 | 984dd96064cb23d7.php |
|
Details | File | 4 | docia.docx |
|
Details | Url | 3 | https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc |
|
Details | Url | 3 | https://farghlymal.github.io/stealc-stealer-analysis |
|
Details | Url | 5 | https://twitter.com/farghlymal |