Stealc Infostealer: Reverse Engineering
ID: 2c6a1f32-23eb-5d13-8050-ff2ccb14c2cc
STIX ID: report--2c6a1f32-23eb-5d13-8050-ff2ccb14c2cc
Feed Name: Sekoia.com
This Sekoia technical analysis details the Stealc information stealer—an infostealer resembling Vidar and Raccoon—covering its anti-analysis tricks, RC4+base64 string obfuscation, dynamic API resolution, host and environment checks, extensive targeting of browsers/wallets/plugins and file grabber functionality, HTTP-based C2 with base64-encoded POST forms, DLL download/loading for data access, next-stage payload capability (e.g., a Laplas Clipper), trace removal behavior, and provides SHA-256 samples, C2 patterns, and scripts to extract/deobfuscate configuration and strings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
