Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.015 Compression |
MalwareStrelaStealer | StrelaStealer has been delivered via JScript files in a ZIP archive. |
| T1027.016 Junk Code Insertion |
MalwareStrelaStealer | StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1059.003 Windows Command Shell |
MalwareStrelaStealer | StrelaStealer has included BAT files in some instances for installation. |
| T1059.007 JavaScript |
MalwareStrelaStealer | StrelaStealer has been distributed as a malicious JavaScript object. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1119 Automated Collection |
MalwareStrelaStealer | StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStrelaStealer | StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1480.002 Mutual Exclusion |
MalwareStrelaStealer | StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStrelaStealer | StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1614.001 System Language Discovery |
MalwareStrelaStealer | StrelaStealer variants check system language settings via keyboard layout or similar mechanisms. |
| T1622 Debugger Evasion |
MalwareStrelaStealer | StrelaStealer variants include functionality to identify and evade debuggers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.