StreamEx
Description
(Cylance) Cylance dubbed this family of malware StreamEx, based upon a common exported function used across all samples ‘stream’, combined with the dropper functionality to append ‘ex’ to the DLL file name.
The StreamEx family has the ability to access and modify the user’s file system, modify the registry, create system services, enumerate process and system information, enumerate network resources and drive types, scan for security tools such as firewall products and antivirus products, change browser security settings, and remotely execute commands. The malware documented in this post was predominantly 64-bit, however, there are 32-bit versions of the malware in the wild.
Names
Name |
---|
StreamEx |
Category
Malware
Type
- Reconnaissance
- Backdoor
Information
Mitre Attack
Alienvault Otx
Other Information
Uuid
fa1c38a2-c132-470d-8a83-b5b6df3e2a00
Last Card Change
2020-04-22