SYMBOLCOMMON_NAMEaka. SYNONYMS
js.starfish (Back to overview)

StarFish


According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.

References
2025-07-10IBM X-ForceChris Caridi, Golo Mühr
Hive0145 back in German inboxes with Strela Stealer and a backdoor
StarFish

There is no Yara-Signature yet.