Is Your Data Safe? The Rising Threat of FredyStealer Malware
Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.

Malware Analysis Report
FredyStealer: The Silent Thief in Your System
Published March 26, 2026 · Threat Intelligence Team ·
A critical-severity script sample was processed by the malware analysis suite. The resulting write-up below is structured for publication and includes visuals, IOC tables, ATT&CK coverage, and operational guidance.
Verdict:SUSPICIOUS
Risk:72/100
Families:No confident family match
Risk Score
72/100
Risk Score derived from this analysis run.
ATT&CK Techniques
0
ATT&CK Techniques derived from this analysis run.
IOCs
5
IOCs derived from this analysis run.
Signature Matches
14
Signature Matches derived from this analysis run.
Analysis Snapshot
| Sample Name | 7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2.ps1 |
|---|---|
| File Type | SCRIPT |
| Verdict | SUSPICIOUS |
| Risk Score | 72/100 |
| Detected Families | No family confidently matched |
| Top ATT&CK Tactic | No ATT&CK mapping available |
| File Size | 1348 |
| MD5 | 7c420fcf3aab7e32a8dbc38481b0661a |
Threat Overview
This SCRIPT sample was classified as SUSPICIOUS with a risk score of 72/100. The narrative below is formatted for direct publication and is intended to help readers quickly understand what was found, why it matters, and what action should follow.
Technical Analysis
Behavioral Signals
Network behavior includes network:dga_detected. Behavioral tags: dga_activity, file_manipulation.
- Ransom Notes
Structured Evidence Highlights
These normalized findings summarize the strongest technical evidence discovered across the parser, IOC, and ATT&CK stages.
Total indicators: 8 · High-confidence findings: 1
| Indicator | Category | Severity | Confidence |
|---|---|---|---|
| Remote URL references embedded in script content | Network | High | Medium |
| 7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2 | Ioc | Medium | Medium |
| 7c420fcf3aab7e32a8dbc38481b0661a | Ioc | Medium | Medium |
| 55f916e466ff532214d8c71012cdf889c322513e | Ioc | Medium | Medium |
| kms8.msguides.com | Ioc | Medium | Medium |
| https://activat.my/ActSet.zip | Network | Medium | Medium |
| https://activat.my/ActSet.zip | Ioc | Medium | Medium |
| Script contains execution or staging primitives | Static | Medium | Medium |
Indicators of Compromise
The following tables are ready to paste into a WordPress or Elementor article. They include both the evidence itself and the recommended operational use for defenders.
| Type | Value | Operational Use |
|---|---|---|
| Domain | kms8.msguides.com | Add to DNS sinkhole and monitor resolver logs. |
| URL | https://activat.my/ActSet.zip | Block at secure web gateway and review access history. |
| SHA256 | 7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2 | Push to EDR blocklist and retrospective file search. |
| MD5 | 7c420fcf3aab7e32a8dbc38481b0661a | Use for legacy detections and historical pivoting. |
| SHA1 | 55f916e466ff532214d8c71012cdf889c322513e | Use for historical pivoting where SHA256 is unavailable. |
File Hashes
| Hash | Value |
|---|---|
| MD5 | 7c420fcf3aab7e32a8dbc38481b0661a |
| SHA1 | 55f916e466ff532214d8c71012cdf889c322513e |
| SHA256 | 7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2 |
| SHA512 | 5234769cd292ace0caa620d63c61f03d85a92484318c989cb127cbb90a874e91425cebba515bb090a69aa60bf7da584869ebd09ac0be2695ec899bf9797690d1 |
Signature Matches
The following detection content matched during analysis and can be cited as supporting evidence.
- Username/Computer Name Check – Checks username or computer name for sandbox indicators
- AV Exclusion Path Addition – Adds file paths to antivirus exclusions
- Tor/Onion Communication – Communicates through Tor network or onion addresses
- Email Collection – Collects emails from local clients or servers
- BITS Job Abuse – Abuses BITS service for privilege escalation or persistence
- Hidden File System – Creates hidden filesystem or storage area
- Alternate Data Stream Hiding – Hides data in NTFS alternate data streams for covert storage
- Registry-Based Payload Storage – Stores payload in registry keys for fileless execution
Recommended Actions
These actions are intentionally phrased so they can remain in the final published post as practical guidance.
- Share the IOC table and ATT&CK summary with defenders responsible for endpoint, network, and email controls.
- Search for the published indicators anywhere similar files may have been delivered or executed.
- Use the recommendations and visuals in this article to educate non-specialists on why the sample matters.
Impact Assessment
CRITICAL
Overall risk score of 72/100 places this sample in the critical severity tier.
- System compromise with potential for data theft or unauthorized access
Overall severity: Critical (72/100)
Detection & Mitigation
Detection
- Deploy file hash IOCs to EDR blocklists for immediate prevention
- Create behavioral detection rules from API call sequences identified
- Create SIEM correlation rules for network IOCs against firewall and DNS logs
- Conduct retrospective hunting across historical logs for IOC matches
Mitigation
- Isolate any systems where the sample or related IOCs have been identified
- Update antivirus and EDR signatures with extracted hashes and behavioral indicators
- Ingest all IOCs into threat intelligence platforms and SOAR playbooks
- Share IOCs and findings with industry ISACs and threat intelligence sharing communities
Future Monitoring
- Track recurrences of the IOC set across endpoint, proxy, DNS, and email telemetry.
- Re-run analysis if new variants, delivery files, or related infrastructure are discovered.
- Keep ATT&CK-aligned detection content synchronized with the mapped techniques in this article.
Conclusion
This critical-severity analysis generated 5 IOCs, and 14 signature references. The resulting article is designed to work as both a reader-friendly narrative and an operational handoff for defenders.



