STARSYPOUND (d0220108-48d7-4056-babc-189048f37a59)
STARSYPOUND provides an interactive remote shell over an obfuscated communications channel. When it is first run, it loads a string (from the executable PE resource section) containing the beacon IP address and port. The malware sends the beacon string "(SY)#
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
STARSYPOUND (d0220108-48d7-4056-babc-189048f37a59) | Tool | StarsyPound (6df9bbd4-ab32-4d09-afdb-97eed274520a) | Malpedia | 1 |