StarFish
- First seen
- 2022-03-15 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 14:34:37
Context
According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Starfish (report)
- ibm.com — Hive0145 Back In German Inboxes With Strela Stealer (report)