Strela Stealer, first identified by DCSO in late 2022, is a type of information-stealing malware primarily designed to exfiltrate email account credentials from widely used email clients, including Microsoft Outlook and Mozilla Thunderbird. This malware initially targeted Spanish-speaking users through spam email campaigns containing malicious ISO attachments, which included a .lnk file and a polyglot file. When executed, the .lnk file triggered the polyglot file, executing both the lure html and Strela stealer DLL using “rundll32.exe”. Author: AlienVault
Related Tags:
zip file
Strela
Financial Services
webdav
Germany
dll file
Healthcare
Spain
T1560
Associated Indicators:
0E2263D4F239A5C39960FFA6B6B688FAA7FC3075E130FE0D4599D5B95EF20647
7FCF23AD9D241CCD8F46A9A65BDD99741BADE2BF323599F5639EBF160D35AA1E
662A2A870928DC42D9CD04DBBB7A948300C98496BF4F68AA7CE1320D93DA3180
50C9BD0F5DECA0B2EDBC4128AA7895EC0268A246E536110EFE81E3A3DA696B0C
70F500E1941CE7F0AE0D4C12C44F3E265C701C1169193A55E5F842C093F303CC
59894ED00AAA9F8AB743EA09A1C7ADD38B7BF378B073AEA978FB1703EA9AACDD
9EB4A88BC7BA156AF849FCD956744C65677372DB5E5CB09115DF8EC900928CBB
4781F4C8A8A43B559D1C1452E0E967CD23F7FD3D41A1065E5A3EC3366E3BF496
2C447B38BC71B6B68234E3F7EA389807A9D61597AAB5A11CC60133EE01FB7B79