Academic report · Malware analysis
STX RAT Malware Analysis
An evidence-led analysis of an installer-themed STX RAT sample that distinguishes direct local evidence, public sandbox observations, reputation data, and family-level research.

Investigation workflow
Evidence before attribution
The report moves from reproducible local facts to externally observed behavior, then bounds the final assessment.
Question and evidence standard
The goal was not to repeat family-level claims, but to determine what this specific installer-themed sample could support. Every conclusion is labeled by evidence source, and behavior is described as locally observed only when local artifacts prove it.
Analysis workflow
The investigation combined safe local inspection with external execution and reputation evidence.
- Verify identity, hash, file type, and chain of custody
- Inspect PE metadata, imports, strings, entropy, sections, and overlay data
- Correlate peframe indicators for packing, anti-debugging, crypto, registry, token, and file operations
- Review ANY.RUN, Hatching Triage, CAPE, and FileScan execution evidence
- Cross-check MalwareBazaar, VirusTotal, and Hybrid Analysis
Key finding
The strongest supported assessment is an installer-themed STXRAT delivery or loader artifact. Evidence supports packing, setup-wrapper behavior, a decoy hardware-monitor presentation, and PowerShell-staged execution.
Analytical restraint
Live C2 contact, durable persistence, credential theft, and recovery of a final payload were not confirmed for this sample. Recording those limits is part of the result, not a gap to hide.