MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a4a333147eb03fa0bfb7d0f03b37585669e4d056d63d31beecbb56eafc80c91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: 4a4a333147eb03fa0bfb7d0f03b37585669e4d056d63d31beecbb56eafc80c91
SHA3-384 hash: 91631da3d905b22bdeba0411bc463c6291ae9c218e44e01a11740f153dea65acea782b8f94d3b7f6f3c1763e963ab10b
SHA1 hash: f5b5e634b40d0a043c77f48a259dab9b5eea1f5b
MD5 hash: 3b098ed6aa7c3b342772a135129afebd
humanhash: grey-seven-lamp-alpha
File name:BANK DETAILS.jar
Download: download sample
Signature STRRAT
File size:90'596 bytes
First seen:2021-05-07 19:20:42 UTC
Last seen:2021-05-07 20:01:51 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 1536:EQLmoKjSXJwjINhkq76Uju1WVFXURsZUt8mXIsruuSuO8cNFgD:Ek/wMPX8sZUKhRuO8cNq
TLSH DB93CF1B3DDA95D6C007593319448327EA0D4AC8DD1AA80F6AFC47A51EB8C6C5F06EDF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
194.5.97.87:2558

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
194.5.97.87:2558 https://threatfox.abuse.ch/ioc/32652/

Intelligence


File Origin
# of uploads :
2
# of downloads :
145
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
84 / 100
Signature
Creates autostart registry keys to launch java
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Multi AV Scanner detection for submitted file
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 407617 Sample: BANK DETAILS.jar Startdate: 08/05/2021 Architecture: WINDOWS Score: 84 75 Found malware configuration 2->75 77 Multi AV Scanner detection for submitted file 2->77 79 Yara detected STRRAT 2->79 81 3 other signatures 2->81 9 cmd.exe 2 2->9         started        12 javaw.exe 2 2->12         started        14 javaw.exe 2 2->14         started        16 2 other processes 2->16 process3 signatures4 83 Uses schtasks.exe or at.exe to add and modify task schedules 9->83 18 java.exe 29 9->18         started        22 conhost.exe 9->22         started        process5 dnsIp6 61 github.com 140.82.121.3, 443, 49731 GITHUBUS United States 18->61 63 github-releases.githubusercontent.com 185.199.109.154, 443, 49735 FASTLYUS Netherlands 18->63 65 2 other IPs or domains 18->65 49 C:\cmdlinestart.log, ASCII 18->49 dropped 51 C:\Users\user\BANK DETAILS.jar, Zip 18->51 dropped 24 java.exe 2 22 18->24         started        29 icacls.exe 1 18->29         started        file7 process8 dnsIp9 67 192.168.2.1 unknown unknown 24->67 53 C:\Users\user\AppData\...\BANK DETAILS.jar, Zip 24->53 dropped 55 C:\Users\user\AppData\...\BANK DETAILS.jar, Zip 24->55 dropped 57 C:\ProgramData\Microsoft\...\BANK DETAILS.jar, Zip 24->57 dropped 59 C:\Users\user\...\jna9217547626958192374.dll, PE32 24->59 dropped 85 Creates autostart registry keys to launch java 24->85 31 java.exe 14 24->31         started        35 cmd.exe 1 24->35         started        37 conhost.exe 24->37         started        39 conhost.exe 29->39         started        file10 signatures11 process12 dnsIp13 69 jfmamjjasond.awsmppl.com 194.5.97.87, 2558, 49750, 49754 DANILENKODE Netherlands 31->69 71 10.9.0.6, 2558 unknown unknown 31->71 73 str-master.pw 31->73 47 C:\Users\user\...\jna8311453871885635334.dll, PE32 31->47 dropped 41 conhost.exe 31->41         started        43 conhost.exe 35->43         started        45 schtasks.exe 1 35->45         started        file14 process15
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2021-05-07 19:21:11 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments