MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2799f78dd51fce411e566d428cd2f26bb752370f1be1fb2f4ffbc23ae1fd6504. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: 2799f78dd51fce411e566d428cd2f26bb752370f1be1fb2f4ffbc23ae1fd6504
SHA3-384 hash: 0c8eb62d4a48752cd0d3d22e8ef8dcac393b115e669ebba2d492dc254066deda8408cfbfbf4103f4d78cbda2b2e8a03f
SHA1 hash: 5199ab6257db0d690b7a08566bf8f032c74a22a8
MD5 hash: c4a38d07773d619f73abad13ed74286f
humanhash: maine-nuts-whiskey-delaware
File name:dataURI-1633317718912.jpg.jar
Download: download sample
Signature STRRAT
File size:106'128 bytes
First seen:2021-10-04 07:50:45 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:W1ugSIpJlEYiuzgd5wfe8/qoYwLJdRjatMFrzq:d2JlEYiZwW8/qqNdRjaitzq
TLSH T1EFA3CF6FBDE9C8B8D0079436504A8A22A78D059CE05E953FF6FC049A7CB4D2C4725B9F
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
194.5.98.239:5059

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
194.5.98.239:5059 https://threatfox.abuse.ch/ioc/230109/

Intelligence


File Origin
# of uploads :
1
# of downloads :
191
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dataURI-1633317718912.jpg.jar
Verdict:
No threats detected
Analysis date:
2021-10-04 07:52:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
evad.troj
Score:
64 / 100
Signature
Found malware configuration
Uses an obfuscated file name to hide its real file extension (double extension)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 496123 Sample: dataURI-1633317718912.jpg.jar Startdate: 04/10/2021 Architecture: WINDOWS Score: 64 28 Found malware configuration 2->28 30 Yara detected STRRAT 2->30 32 Uses an obfuscated file name to hide its real file extension (double extension) 2->32 34 Yara detected AllatoriJARObfuscator 2->34 8 cmd.exe 2 2->8         started        10 cmd.exe 1 2->10         started        process3 process4 12 java.exe 5 8->12         started        16 conhost.exe 8->16         started        18 7za.exe 73 10->18         started        dnsIp5 26 192.168.2.1 unknown unknown 12->26 24 C:\cmdlinestart.log, ASCII 12->24 dropped 20 icacls.exe 1 12->20         started        file6 process7 process8 22 conhost.exe 20->22         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2021-10-04 07:51:04 UTC
AV detection:
9 of 45 (20.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments