MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b348733b6a9447b5ec3e5bfa35d8a2d64fcf9dcfa5da40ce9d0a245d6d1798a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 7


Intelligence 7 IOCs 1 YARA File information Comments

SHA256 hash: 2b348733b6a9447b5ec3e5bfa35d8a2d64fcf9dcfa5da40ce9d0a245d6d1798a
SHA3-384 hash: 550ea85077c89cd442fa38b43ec11948722db5b1246e1e10e248a3be2c304902a6e5c40a28eb24ce5ea04389c81024aa
SHA1 hash: b7362519e2ae8936ed33098c9b9af071d5a65600
MD5 hash: 3d13ac5136336d785ca6522a71abcc3e
humanhash: minnesota-north-potato-colorado
File name:GARMENT SAMPLE FOR QUOTATION PDF.jar
Download: download sample
Signature STRRAT
File size:178'533 bytes
First seen:2022-07-19 03:40:40 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:/ZxfLiDge0MJKnaXW5jzU7kd0NTzTD23vyNSEbTDxQp6aFFsQ5kliLHQ8P92cHcE:jfLiDEoMOW9gM09zX2q0EbTmp6aFiXip
TLSH T1570412AFCB4A9F84F8F613A5B3831E5573AA1FE1590592457B2B17784E04E0092F8DC7
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
185.222.57.218:1780

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.222.57.218:1780 https://threatfox.abuse.ch/ioc/838636/

Intelligence


File Origin
# of uploads :
1
# of downloads :
239
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2b348733b6a9447b5ec3e5bfa35d8a2d64fcf9dcfa5da40ce9d0a245d6d1798a.zip
Verdict:
Malicious activity
Analysis date:
2022-07-19 08:45:56 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
Detection:
malicious
Classification:
troj.expl
Score:
60 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Multi AV Scanner detection for submitted file
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 668729 Sample: GARMENT SAMPLE FOR QUOTATIO... Startdate: 19/07/2022 Architecture: WINDOWS Score: 60 31 sonatype.map.fastly.net 2->31 33 repo1.maven.org 2->33 35 github.com 2->35 43 Multi AV Scanner detection for submitted file 2->43 45 Yara detected STRRAT 2->45 47 Exploit detected, runtime environment starts unknown processes 2->47 9 cmd.exe 2 2->9         started        11 cmd.exe 1 2->11         started        signatures3 process4 process5 13 java.exe 6 9->13         started        15 conhost.exe 9->15         started        17 7za.exe 8 11->17         started        process6 19 wscript.exe 2 13->19         started        22 icacls.exe 1 13->22         started        file7 29 C:\Users\user\AppData\...\tnjkkwxizi.txt, Zip 19->29 dropped 24 javaw.exe 12 19->24         started        27 conhost.exe 22->27         started        process8 dnsIp9 37 github.com 140.82.121.3, 443, 49796, 49801 GITHUBUS United States 24->37 39 140.82.121.4, 443, 51296, 51301 GITHUBUS United States 24->39 41 3 other IPs or domains 24->41
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2022-07-19 03:41:07 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
9 of 25 (36.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence suricata
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Loads dropped DLL
suricata: ET MALWARE STRRAT CnC Checkin
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments