Threat Database Trojans Trojan.Stelpak.A

Trojan.Stelpak.A

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Stelpak.A
Signature status: No Signature

Known Samples

MD5: 03026e78fd4616c8bb6a2847c957ce0d
SHA1: 8688cfc123234b8abf9d41e83ca869f31df5854b
SHA256: 266225722A9A978E56E824D28BD7C8908C1D95326F65D3908E2E1A8C83672F67
File Size: 783.87 KB, 783872 bytes
MD5: 54e7e12486248e0d06b0a61cd1c17e51
SHA1: a5de63d6c0682f573053536b9f06d2555060774c
SHA256: 5386AF6B4FBC057A092CE7FBE3B52702AAE6242FF24C0486D7B073DC4A078687
File Size: 783.36 KB, 783360 bytes
MD5: 28fab82263ad2ab5447014fa140f18db
SHA1: 53823aef9f9f432eed6e3d713be8f5d39efc0004
SHA256: 1031C415F9BBB4F3CAEFA01CC76EB634D892A6B7F011B473C7A4156611BE08D0
File Size: 5.48 MB, 5475328 bytes
MD5: 61782466ef941444a8e659bf746a2e63
SHA1: 910732764c9595928f51af2b4c1bf2b85d1c7a46
SHA256: A008AE28B2BCDF610EA35A6D12C4BA260E5B26CE706E46EAED940B5E76DDB906
File Size: 468.99 KB, 468992 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • fptable
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 676
Potentially Malicious Blocks: 3
Whitelisted Blocks: 664
Unknown Blocks: 9

Visual Map

? ? ? ? 0 ? ? ? ? 0 x x ? x 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Emotet.RECL
  • Lumma.JA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\delays.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider
User Data Access
  • GetUserObjectInformation
  • OpenClipboard
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...