StarFish

First seen
2022-03-15 00:00:00
Malware type
rat
Profile updated
2026-07-07 14:34:37

Context

According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Starfish (report)
  • ibm.com — Hive0145 Back In German Inboxes With Strela Stealer (report)

External references