MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3eb094d80c7eddc34a5481f9f368b3f4495010e775125fa0ffe101162aef63d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: 3eb094d80c7eddc34a5481f9f368b3f4495010e775125fa0ffe101162aef63d7
SHA3-384 hash: 5137e016c866b6e60df5f083a2a9c15afc8df09cb4954349533ff7f2f542cbd2b64419b0192cd68aeedeceefeca1076b
SHA1 hash: b97d76c5bc15cb05c3884c5199e4c749d7b93028
MD5 hash: 3262808b4c1c76186e16f763cfcb1e1d
humanhash: pennsylvania-robert-lamp-leopard
File name:DHLMar 2021 at 1.M9B7290PDF.jar
Download: download sample
Signature STRRAT
File size:176'610 bytes
First seen:2021-03-24 07:02:32 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:PxXmwuCaDAwIGkMHtgLzMAGc4zup4DMzTjy4OY706TCF0SX/01urlej0kgNSz7Ag:PIQlFMNTw4DUy3iCF0SXUEIjmAf1VGTy
TLSH CB0423A851DA0C18B67C2EAC1B7CA7C4C69C115AE97E2636FECC3B61D069C3D47630C5
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
64.188.13.141:7888

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
64.188.13.141:7888 https://threatfox.abuse.ch/ioc/4417/

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
DHLMar 2021 at 1.M9B7290PDF.jar
Verdict:
No threats detected
Analysis date:
2021-03-24 07:11:16 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Get antivirus details via WMIC query
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 374917 Sample: DHLMar 2021 at 1.M9B7290PDF.jar Startdate: 24/03/2021 Architecture: WINDOWS Score: 100 92 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->92 94 Multi AV Scanner detection for domain / URL 2->94 96 Multi AV Scanner detection for submitted file 2->96 98 6 other signatures 2->98 12 cmd.exe 2 2->12         started        15 notepad.exe 2->15         started        17 notepad.exe 2->17         started        19 3 other processes 2->19 process3 signatures4 102 Uses schtasks.exe or at.exe to add and modify task schedules 12->102 21 java.exe 6 12->21         started        23 conhost.exe 12->23         started        process5 process6 25 wscript.exe 2 21->25         started        27 icacls.exe 1 21->27         started        process7 29 javaw.exe 26 25->29         started        32 conhost.exe 27->32         started        dnsIp8 86 github.com 140.82.121.3, 443, 49739 GITHUBUS United States 29->86 88 github-releases.githubusercontent.com 185.199.110.154, 443, 49740 FASTLYUS Netherlands 29->88 90 3 other IPs or domains 29->90 34 java.exe 2 21 29->34         started        process9 file10 74 C:\Users\user\AppData\Roaming\rsjplcego.txt, Zip 34->74 dropped 76 C:\Users\user\...\jna4486649118521597135.dll, PE32 34->76 dropped 37 java.exe 34->37         started        41 cmd.exe 34->41         started        43 conhost.exe 34->43         started        process11 dnsIp12 80 64.188.13.141, 49747, 7888 ASN-QUADRANET-GLOBALUS United States 37->80 82 str-master.pw 37->82 84 ip-api.com 208.95.112.1, 49763, 80 TUT-ASUS United States 37->84 78 C:\Users\user\...\jna6386265207341996023.dll, PE32 37->78 dropped 45 cmd.exe 37->45         started        47 cmd.exe 37->47         started        49 cmd.exe 37->49         started        55 2 other processes 37->55 51 conhost.exe 41->51         started        53 schtasks.exe 41->53         started        file13 process14 process15 57 WMIC.exe 45->57         started        60 conhost.exe 45->60         started        62 conhost.exe 47->62         started        64 WMIC.exe 47->64         started        66 conhost.exe 49->66         started        68 WMIC.exe 49->68         started        70 conhost.exe 55->70         started        72 WMIC.exe 55->72         started        signatures16 100 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 57->100
Threat name:
Archive-JAR.Trojan.AdWind
Status:
Malicious
First seen:
2021-03-23 23:28:18 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
persistence
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments