September 22, 2023

Researchers have detailed out about the information-stealing malware that is rapidly growing in popularity on dark web marketplaces, called Stealc.

The malware was first spotted being offered on a forum by a user named Plymouth. Stealc was advertised as a fully featured and ready-to-use stealer and has similarities with other info stealer malware such as Vidar, Raccoon, Mars, and Redline.

Advertisements

Stealc targets sensitive data from web browsers, extensions for cryptocurrency wallets, desktop cryptocurrency wallets, and information from additional applications, including email clients and messenger software. The data collection configuration can be customized to meet the needs.

The malware implements a customizable file grabber, to steal files matching their grabber rules. The stealer was also found to have loader capabilities that are typical for an information stealer sold as malware-as-a-service.

Currently, it’s being sold on a Malware-as-a-service and customers own a build of its administration panel to host the stealer command-and-control center, the build will likely leak to underground communities in the medium term. Eventually, a cracked version of a Stealc build may be released, which could be used for many years to come.

It’s expected that the Stealc info stealer will become widespread in the near term, as multiple threat actors add the malware to their arsenal while it is poorly monitored. Companies facing targeted stealer attacks are warned to be aware of this malware.

This research was documented by researchers from Sekoia

Advertisements
Sl.NoIndicators of Compromise
191.215.85[.]188
294.142.138[.]48
3185.242.87[.]149
4185.247.184[.]7
577.246.156[.]93
6185.143.223[.]136
765.109.131[.]183
8194.87.31[.]146
985.239.54[.]29
1045.136.51[.]61
1191.228.225[.]46
1245.136.49[.]247
1337.220.87[.]65
14195.74.86[.]37
15179.43.162[.]94
16185.130.46[.]214
1765.109.3[.]34
1894.142.138[.]11
1995.216.112[.]83
20146.70.161[.]51
2177.91.124[.]7
2245.136.50[.]69
23176.124.192[.]200
2445.144.29[.]176
25167.235.62[.]105
265.75.138[.]201
2795.217.143[.]99
28179.43.162[.]89
29162.0.238[.]10
3045.87.153[.]50
3123.88.116[.]117
3284.246.85[.]80
3394.131.99[.]185
34194.4.51[.]160
35179.43.162[.]2
3637.120.238[.]190
37185.5.248[.]95
38aa-cj[.]com
39fff-ttt[.]com
40start-not[.]com
41moneylandry[.]com
42666palm[.]com
43777palm[.]com
44hxxp://777palm.com/2ccaf544c0cf7de7/nss3.dll
45hxxp://23.88.116.117/libs/sqlite3.dll
46hxxp://94.142.138.48/54982f23330528c2/msvcp140.dll
47hxxp://666palm.com/54fbf4b9ffe8c98d/sqlite3.dll
48hxxp://666palm.com/54fbf4b9ffe8c98d/nss3.dll
49hxxp://777palm.com/2ccaf544c0cf7de7/vcruntime140.dll
50hxxp://start-not.com/libs/freebl3.dll
51hxxp://146.70.161.51/58d66e64beb49702/mozglue.dll
52hxxp://162.0.238.10/752e382b4dcf5e3f.php
53hxxp://162.0.238.10/dbe4ef521ee4cc21/mozglue.dll
54hxxp://fff-ttt.com/a02fc2187db8cd88/softokn3.dll
55hxxp://23.88.116.117/libs/softokn3.dll
56hxxp://fff-ttt.com/a02fc2187db8cd88/sqlite3.dll
57hxxps://streetlifegaming.com/wp-content/uploads/2023/02/Pass_55555_Setup.rar
58hxxp://23.88.116.117/libs/freebl3.dll
59hxxp://aa-cj.com/1b8df000d02ce631/freebl3.dll
60hxxp://146.70.161.51/273d9c8034a95cb4.php
61hxxp://94.142.138.48/54982f23330528c2/nss3.dll
62hxxp://95.216.112.83/5840871afdb84f06/sqlite3.dll
63hxxp://179.43.162.2/3461133978273cb9/vcruntime140.dll
64hxxp://aa-cj.com/1b8df000d02ce631/nss3.dll
65hxxp://666palm.com/54fbf4b9ffe8c98d/mozglue.dll
66hxxp://aa-cj.com/1b8df000d02ce631/mozglue.dll
67hxxp://moneylandry.com/2ccaf544c0cf7de7/vcruntime140.dll
68hxxp://666palm.com/54fbf4b9ffe8c98d/softokn3.dll
69hxxps://185.247.184.7/8c3498a763cc5e26.php
70hxxp://666palm.com/54fbf4b9ffe8c98d/vcruntime140.dll
71hxxp://146.70.161.51/58d66e64beb49702/sqlite3.dll
72hxxp://666palm.com/54fbf4b9ffe8c98d/msvcp140.dll
73hxxp://162.0.238.10/dbe4ef521ee4cc21/msvcp140.dll
74hxxp://start-not.com/libs/vcruntime140.dll
75hxxp://moneylandry.com/2ccaf544c0cf7de7/mozglue.dll
76hxxp://777palm.com/2ccaf544c0cf7de7/msvcp140.dll
77hxxp://94.142.138.48/54982f23330528c2/mozglue.dll
78hxxp://fff-ttt.com/a02fc2187db8cd88/nss3.dll
79hxxp://moneylandry.com/2ccaf544c0cf7de7/softokn3.dll
80hxxp://179.43.162.2/3461133978273cb9/msvcp140.dll
81hxxp://94.142.138.48/54982f23330528c2/sqlite3.dll
82hxxp://777palm.com/2ccaf544c0cf7de7/softokn3.dll
83hxxp://185.5.248.95/libs/nss3.dll
84hxxp://179.43.162.2/d8ab11e9f7bc9c13.php
85hxxp://146.70.161.51/58d66e64beb49702/vcruntime140.dll
86hxxp://176.124.192.200/bef7fb05c9ef6540.php
87hxxp://moneylandry.com/2ccaf544c0cf7de7/freebl3.dll
88hxxp://179.43.162.2/3461133978273cb9/mozglue.dll
89hxxp://moneylandry.com/2ccaf544c0cf7de7/nss3.dll
90hxxp://94.142.138.48/54982f23330528c2/freebl3.dll
91hxxp://162.0.238.10/dbe4ef521ee4cc21/nss3.dll
92hxxp://23.88.116.117/libs/nss3.dll
93hxxp://23.88.116.117/libs/vcruntime140.dll
94hxxp://start-not.com/libs/sqlite3.dll
95hxxp://aa-cj.com/6842f013779f3d08.php
96hxxp://fff-ttt.com/984dd96064cb23d7.php
97hxxp://185.5.248.95/libs/freebl3.dll
98hxxp://185.5.248.95/api.php
99hxxp://179.43.162.2/3461133978273cb9/freebl3.dll
100hxxp://185.247.184.7/b00dc1fe53045ca1/sqlite3.dll
101hxxp://185.5.248.95/libs/sqlite3.dll
102hxxp://94.142.138.48/f9f76ae4bb7811d9.php
103hxxp://aa-cj.com/1b8df000d02ce631/msvcp140.dll
104hxxp://23.88.116.117/libs/mozglue.dll
105hxxp://185.5.248.95/libs/softokn3.dll
106hxxp://179.43.162.2/3461133978273cb9/softokn3.dll
107hxxp://185.5.248.95/libs/mozglue.dll
108hxxp://moneylandry.com/bef7fb05c9ef6540.php
109hxxp://moneylandry.com/2ccaf544c0cf7de7/sqlite3.dll
110hxxp://fff-ttt.com/a02fc2187db8cd88/msvcp140.dll
111hxxp://185.247.184.7/8c3498a763cc5e26.php
112hxxp://95.216.112.83/413a030d85acf448.php
113hxxp://179.43.162.2/3461133978273cb9/nss3.dll
114hxxp://start-not.com/libs/nss3.dll
115hxxp://777palm.com/2ccaf544c0cf7de7/sqlite3.dll
116hxxp://23.88.116.117/api.php
117hxxp://146.70.161.51/58d66e64beb49702/nss3.dll
118hxxp://185.5.248.95/libs/msvcp140.dll
119hxxp://aa-cj.com/1b8df000d02ce631/softokn3.dll
120hxxp://95.216.112.83/5840871afdb84f06/mozglue.dll
121hxxp://fff-ttt.com/a02fc2187db8cd88/mozglue.dll
122hxxp://146.70.161.51/58d66e64beb49702/msvcp140.dll
123hxxp://777palm.com/2ccaf544c0cf7de7/mozglue.dll
124hxxp://777palm.com/bef7fb05c9ef6540.php
125hxxp://5.75.138.201/9026ac2a280e901d/softokn3.dll
126hxxp://aa-cj.com/1b8df000d02ce631/vcruntime140.dll
127hxxp://94.142.138.48/54982f23330528c2/softokn3.dll
128hxxp://162.0.238.10/dbe4ef521ee4cc21/softokn3.dll
129hxxp://162.0.238.10/dbe4ef521ee4cc21/sqlite3.dll
130hxxp://777palm.com/2ccaf544c0cf7de7/freebl3.dll
131hxxp://162.0.238.10/dbe4ef521ee4cc21/freebl3.dll
132hxxp://moneylandry.com/2ccaf544c0cf7de7/msvcp140.dll
133hxxp://start-not.com/libs/msvcp140.dll
134hxxp://162.0.238.10/dbe4ef521ee4cc21/vcruntime140.dll
135hxxp://aa-cj.com/1b8df000d02ce631/sqlite3.dll
136hxxp://666palm.com/54fbf4b9ffe8c98d/freebl3.dll
137hxxp://185.5.248.95/libs/vcruntime140.dll
138hxxp://185.5.248.95/c1377b94d43eacea.php
139hxxp://666palm.com/bca98681abf8e1ab.php
140hxxp://23.88.116.117/libs/msvcp140.dll
141hxxp://start-not.com/libs/mozglue.dll
142hxxp://146.70.161.51/58d66e64beb49702/softokn3.dll
143hxxp://fff-ttt.com/a02fc2187db8cd88/freebl3.dll
144hxxp://179.43.162.2/3461133978273cb9/sqlite3.dll
145hxxp://146.70.161.51/58d66e64beb49702/freebl3.dll
146hxxp://start-not.com/libs/softokn3.dll
147hxxp://fff-ttt.com/a02fc2187db8cd88/vcruntime140.dll
148hxxp://94.142.138.48/54982f23330528c2/vcruntime140.dll
1490d049f764a22e16933f8c3f1704d4e50;5faad57c7341f76c18ae813e9fa9fbfe434f7b41;77d6f1914af6caf909fa2a246fcec05f500f79dd56e5d0d466d55924695c702d
1509f1aae2b56ebe6681de5d6a376394e29;849703a883cf292b9e5a7e0c88c7c5388c37144f;87f18bd70353e44aa74d3c2fda27a2ae5dd6e7d238c3d875f6240283bc909ba6
1517b9cc53b66d07dfa782f75ffa5e503fe;3147ee316fd6f997099718fbd657e9349636de14;1e09d04c793205661d88d6993cb3e0ef5e5a37a8660f504c1d36b0d8562e63a2
152rcc-software[.]com

Leave a Reply

%d bloggers like this: