MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26104fcd8de196afcbaf13b7a6aa150855ee64060ec9e9444db0448b3524cf80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 7


Intelligence 7 IOCs 1 YARA File information Comments

SHA256 hash: 26104fcd8de196afcbaf13b7a6aa150855ee64060ec9e9444db0448b3524cf80
SHA3-384 hash: 38aca8914cdc4684676335b5d2941bcef74b5fb33ec70f875cee3a0458454991016ad1ea31be17248acbb4b78063f830
SHA1 hash: d234e46d1ce7dd25b17a981596f61b33921a55e3
MD5 hash: 0c08cc90dfa99c3f52e79f281158883c
humanhash: triple-speaker-princess-juliet
File name:01.03.2208.20Anruf.0613259177.jar
Download: download sample
Signature STRRAT
File size:164'920 bytes
First seen:2022-03-01 09:16:29 UTC
Last seen:2022-04-20 09:51:46 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 3072:1/qT51UQOG5bMjsZOvln3xwpyG71D9heYmXjTUs5FKUB5lrQWDjbNRp:1/qrUQOeMjsZQ9BlIBIYSjTN6i5lBjx7
TLSH T1BAF3F16B3D6A88D4F04B4973601182733E5D81ACD619901F36FC89561E78C9B2B2FADF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
212.192.241.175:2310

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
212.192.241.175:2310 https://threatfox.abuse.ch/ioc/391556/

Intelligence


File Origin
# of uploads :
3
# of downloads :
254
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
01.03.22_08.20_Anruf.0613259177.jar
Verdict:
Malicious activity
Analysis date:
2022-03-01 10:31:26 UTC
Tags:
evasion trojan strrat rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
banload CVE_2021_44228
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
64 / 100
Signature
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 580464 Sample: 01.03.2208.20Anruf.0613259177.jar Startdate: 01/03/2022 Architecture: WINDOWS Score: 64 23 store-images.s-microsoft.com 2->23 25 Found malware configuration 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Yara detected STRRAT 2->29 9 cmd.exe 2 2->9         started        11 cmd.exe 1 2->11         started        signatures3 process4 process5 13 java.exe 5 9->13         started        15 conhost.exe 9->15         started        17 7za.exe 73 11->17         started        process6 19 icacls.exe 1 13->19         started        process7 21 conhost.exe 19->21         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2022-03-01 09:17:12 UTC
File Type:
Binary (Archive)
Extracted files:
68
AV detection:
11 of 42 (26.19%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Adds Run key to start application
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments