MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778
SHA3-384 hash: e8410e730fe22d89f538efebdd182344818d15d48a030cea1523b5a16e0191670b2fe0c6a81547177b05af55f2d789f4
SHA1 hash: df301332faa73c3d5f915fde61df2fc9de21a61a
MD5 hash: 14052163e50c197697c64b1431b42271
humanhash: saturn-florida-one-vegan
File name:14052163e50c197697c64b1431b42271.exe
Download: download sample
Signature STRRAT
File size:18'462'845 bytes
First seen:2023-07-07 09:58:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ab6770b0a8635b9d92a5838920cfe770 (84 x Formbook, 30 x AgentTesla, 15 x Loki)
ssdeep 393216:LOh37DR+wwmOoDxRz016TCORfagi8boLH6fQmQa9T1AE0Grq:g/FRxRzlRfPeLajLlg
Threatray 22 similar samples on MalwareBazaar
TLSH T1C40733017DAD9965EC2945B5EC4CD778BA641C82360636B662EFFFAFF232360C41C609
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon f031d4f033688c96 (1 x STRRAT)
Reporter abuse_ch
Tags:exe STRRAT


Avatar
abuse_ch
STRRAT C2:
136.243.214.49:9999

Intelligence


File Origin
# of uploads :
1
# of downloads :
291
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
14052163e50c197697c64b1431b42271.exe
Verdict:
Malicious activity
Analysis date:
2023-07-07 09:59:47 UTC
Tags:
evasion trojan wshrat strrat rat miner

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% directory
Сreating synchronization primitives
Launching a process
Creating a window
Creating a process from a recently created file
Creating a file in the %AppData% directory
Creating a file
Creating a process with a hidden window
Enabling the 'hidden' option for recently created files
DNS request
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Moving a recently created file
Running batch commands
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Creating a file in the mass storage device
Launching the process to change the firewall settings
Enabling autorun by creating a file
Enabling threat expansion on mass storage devices
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control lolbin overlay packed shell32
Result
Threat name:
Njrat, WSHRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious names
Creates multiple autostart registry keys
Drops script or batch files to the startup folder
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
May check the online IP address of the machine
Modifies the context of a thread in another process (thread injection)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: Register Wscript In Run Key
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect virtualization through RDTSC time measurements
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Wscript called in batch mode (surpress errors)
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected MSILLoadEncryptedAssembly
Yara detected Njrat
Yara detected WSHRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1269073 Sample: k9AaBxZyKS.exe Startdate: 07/07/2023 Architecture: WINDOWS Score: 100 145 Sigma detected: Register Wscript In Run Key 2->145 147 Snort IDS alert for network traffic 2->147 149 Found malware configuration 2->149 151 14 other signatures 2->151 10 k9AaBxZyKS.exe 5 14 2->10         started        13 Helper.exe 2->13         started        16 wscript.exe 2->16         started        18 10 other processes 2->18 process3 file4 103 C:\Users\...mbraTor Mac Smash Bullet.exe, PE32 10->103 dropped 105 C:\Users\...\Windows Driver Foundation.vbs, ASCII 10->105 dropped 20 wscript.exe 3 3 10->20         started        24 wscript.exe 2 10->24         started        26 wscript.exe 2 10->26         started        37 2 other processes 10->37 187 Antivirus detection for dropped file 13->187 189 Multi AV Scanner detection for dropped file 13->189 29 Helper.exe 13->29         started        191 Wscript called in batch mode (surpress errors) 16->191 31 wscript.exe 16->31         started        33 conhost.exe 18->33         started        35 conhost.exe 18->35         started        39 3 other processes 18->39 signatures5 process6 dnsIp7 91 C:\...\Antimalware Service Executable.JS, ASCII 20->91 dropped 93 C:\...\Antimalware Service Executable.JS, ASCII 20->93 dropped 153 System process connects to network (likely due to code injection or exploit) 20->153 155 Wscript starts Powershell (via cmd or directly) 20->155 157 May check the online IP address of the machine 20->157 163 4 other signatures 20->163 41 wscript.exe 20->41         started        95 C:\Users\user\AppData\Local\Temp\x.exe, PE32 24->95 dropped 45 x.exe 24->45         started        137 192.168.2.1 unknown unknown 26->137 97 C:\ProgramData\rrrrrrrr.ps1, ASCII 26->97 dropped 48 powershell.exe 15 16 26->48         started        159 Modifies the context of a thread in another process (thread injection) 29->159 161 Injects a PE file into a foreign processes 29->161 50 Helper.exe 29->50         started        52 tor.exe 29->52         started        139 140.82.121.3, 443, 49878, 49883 GITHUBUS United States 37->139 141 github.com 140.82.121.4, 443, 49691, 49698 GITHUBUS United States 37->141 143 2 other IPs or domains 37->143 54 icacls.exe 37->54         started        file8 signatures9 process10 dnsIp11 125 ip-api.com 208.95.112.1, 49719, 80 TUT-ASUS United States 41->125 127 francia.ydns.eu 136.243.214.49, 5553, 8000 HETZNER-ASDE Germany 41->127 165 System process connects to network (likely due to code injection or exploit) 41->165 107 C:\Users\user\AppData\Roaming\...\Helper.exe, PE32+ 45->107 dropped 109 C:\Users\user\AppData\...\SystemCheck.xml, XML 45->109 dropped 111 C:\Users\user\AppData\...\CL_Debug_Log.txt, PE32 45->111 dropped 167 Antivirus detection for dropped file 45->167 169 Multi AV Scanner detection for dropped file 45->169 171 Tries to detect virtualization through RDTSC time measurements 45->171 173 Tries to detect sandboxes / dynamic malware analysis system (registry check) 45->173 56 CL_Debug_Log.txt 45->56         started        59 cmd.exe 45->59         started        62 cmd.exe 45->62         started        129 files.catbox.moe 108.181.20.35, 443, 49766 ASN852CA Canada 48->129 175 Found suspicious powershell code related to unpacking or dynamic code loading 48->175 64 RegAsm.exe 48->64         started        67 conhost.exe 48->67         started        113 C:\Users\user\AppData\Roaming\...\zlib1.dll, PE32+ 50->113 dropped 115 C:\Users\user\AppData\Roaming\...\tor.exe, PE32+ 50->115 dropped 117 C:\Users\user\AppData\...\libwinpthread-1.dll, PE32+ 50->117 dropped 119 7 other malicious files 50->119 dropped 69 conhost.exe 50->69         started        131 86.59.21.38, 443, 49916 UTA-ASAT Austria 52->131 133 149.56.45.200, 49915, 9001 OVHFR Canada 52->133 135 10 other IPs or domains 52->135 71 conhost.exe 54->71         started        file12 signatures13 process14 dnsIp15 99 C:\Users\user\AppData\Local\Temp\64.exe, PE32+ 56->99 dropped 101 C:\Users\user\AppData\Local\Temp\32.exe, PE32 56->101 dropped 73 conhost.exe 56->73         started        177 Uses schtasks.exe or at.exe to add and modify task schedules 59->177 75 conhost.exe 59->75         started        77 schtasks.exe 59->77         started        79 conhost.exe 62->79         started        81 timeout.exe 62->81         started        83 timeout.exe 62->83         started        87 2 other processes 62->87 121 185.241.208.234, 5553 GBTCLOUDUS Moldova Republic of 64->121 123 francia.ydns.eu 64->123 179 Creates autostart registry keys with suspicious names 64->179 181 Creates multiple autostart registry keys 64->181 183 Creates an autostart registry key pointing to binary in C:\Windows 64->183 185 2 other signatures 64->185 85 netsh.exe 64->85         started        file16 signatures17 process18 process19 89 conhost.exe 85->89         started       
Threat name:
Win32.Trojan.Valyria
Status:
Malicious
First seen:
2023-05-22 12:42:09 UTC
File Type:
PE (Exe)
Extracted files:
78
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:njrat family:wshrat botnet:fr evasion trojan
Behaviour
Creates scheduled task(s)
Kills process with taskkill
Modifies registry class
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
AutoIT Executable
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Modifies Windows Firewall
WSHRAT
njRAT/Bladabindi
Malware Config
C2 Extraction:
francia.ydns.eu:5553
http://francia.ydns.eu:8000
Dropper Extraction:
https://files.catbox.moe/fvl5hy.jpg
Unpacked files
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778
MD5 hash:
14052163e50c197697c64b1431b42271
SHA1 hash:
df301332faa73c3d5f915fde61df2fc9de21a61a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments