MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
STRRAT
Vendor detections: 12
| SHA256 hash: | 4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778 |
|---|---|
| SHA3-384 hash: | e8410e730fe22d89f538efebdd182344818d15d48a030cea1523b5a16e0191670b2fe0c6a81547177b05af55f2d789f4 |
| SHA1 hash: | df301332faa73c3d5f915fde61df2fc9de21a61a |
| MD5 hash: | 14052163e50c197697c64b1431b42271 |
| humanhash: | saturn-florida-one-vegan |
| File name: | 14052163e50c197697c64b1431b42271.exe |
| Download: | download sample |
| Signature | STRRAT |
| File size: | 18'462'845 bytes |
| First seen: | 2023-07-07 09:58:34 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | ab6770b0a8635b9d92a5838920cfe770 (84 x Formbook, 30 x AgentTesla, 15 x Loki) |
| ssdeep | 393216:LOh37DR+wwmOoDxRz016TCORfagi8boLH6fQmQa9T1AE0Grq:g/FRxRzlRfPeLajLlg |
| Threatray | 22 similar samples on MalwareBazaar |
| TLSH | T1C40733017DAD9965EC2945B5EC4CD778BA641C82360636B662EFFFAFF232360C41C609 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | f031d4f033688c96 (1 x STRRAT) |
| Reporter | |
| Tags: | exe STRRAT |
Intelligence
File Origin
# of uploads :
1
# of downloads :
291
Origin country :
NLVendor Threat Intelligence
Malware family:
wshrat
ID:
1
File name:
14052163e50c197697c64b1431b42271.exe
Verdict:
Malicious activity
Analysis date:
2023-07-07 09:59:47 UTC
Tags:
evasion trojan wshrat strrat rat miner
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection(s):
SecuriteInfo.com.Generic-EXE.UNOFFICIAL
SecuriteInfo.com.VBS.EmbeddedEXE-2.UNOFFICIAL
SecuriteInfo.com.Java.Siggen.498.18366.14673.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29230.27284.17824.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29244.9311.1371.UNOFFICIAL
Java.Malware.CVE_2021_44228-9915819-0
SecuriteInfo.com.Java.Trojan.GenericGB.29230.988.1324.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29229.17537.6855.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29268.27224.15916.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29154.2006.5323.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29270.6182.9849.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29230.16622.31214.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29296.28800.1088.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGBA.30627.12434.23722.UNOFFICIAL
SecuriteInfo.com.VBS.EmbeddedEXE-2.UNOFFICIAL
SecuriteInfo.com.Java.Siggen.498.18366.14673.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29230.27284.17824.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29244.9311.1371.UNOFFICIAL
Java.Malware.CVE_2021_44228-9915819-0
SecuriteInfo.com.Java.Trojan.GenericGB.29230.988.1324.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29229.17537.6855.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29268.27224.15916.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29154.2006.5323.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29270.6182.9849.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29230.16622.31214.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGB.29296.28800.1088.UNOFFICIAL
SecuriteInfo.com.Java.Trojan.GenericGBA.30627.12434.23722.UNOFFICIAL
Result
Verdict:
Malware
Maliciousness:
Behaviour
Searching for the window
Creating a file in the %temp% directory
Сreating synchronization primitives
Launching a process
Creating a window
Creating a process from a recently created file
Creating a file in the %AppData% directory
Creating a file
Creating a process with a hidden window
Enabling the 'hidden' option for recently created files
DNS request
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Moving a recently created file
Running batch commands
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Creating a file in the mass storage device
Launching the process to change the firewall settings
Enabling autorun by creating a file
Enabling threat expansion on mass storage devices
Result
Malware family:
n/a
Score:
5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
control lolbin overlay packed shell32
Verdict:
Malicious
Labled as:
Win/malicious_confidence_100%
Result
Threat name:
Njrat, WSHRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious names
Creates multiple autostart registry keys
Drops script or batch files to the startup folder
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
May check the online IP address of the machine
Modifies the context of a thread in another process (thread injection)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Drops script at startup location
Sigma detected: Register Wscript In Run Key
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect virtualization through RDTSC time measurements
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Wscript called in batch mode (surpress errors)
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected MSILLoadEncryptedAssembly
Yara detected Njrat
Yara detected WSHRAT
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Valyria
Status:
Malicious
First seen:
2023-05-22 12:42:09 UTC
File Type:
PE (Exe)
Extracted files:
78
AV detection:
26 of 38 (68.42%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
unknown
Similar samples:
+ 12 additional samples on MalwareBazaar
Result
Malware family:
wshrat
Score:
10/10
Tags:
family:njrat family:wshrat botnet:fr evasion trojan
Behaviour
Creates scheduled task(s)
Kills process with taskkill
Modifies registry class
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
AutoIT Executable
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Modifies Windows Firewall
WSHRAT
njRAT/Bladabindi
Malware Config
C2 Extraction:
francia.ydns.eu:5553
http://francia.ydns.eu:8000
http://francia.ydns.eu:8000
Dropper Extraction:
https://files.catbox.moe/fvl5hy.jpg
Unpacked files
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
41686ad9f581037f44b72b37f8bee562512854fc6807c5a13ea1646cdeab61c8
MD5 hash:
efcd72ad2d3430248a68e5f960ed5e2b
SHA1 hash:
58cc7d2732f401b99926211c0dab319dfc0bba1a
SH256 hash:
30c0c37f78ad6f76689398793bcd47e0a17154e2740407f740824a1c1ebd2b49
MD5 hash:
8da31b45e2109df6e45f7aa779758f22
SHA1 hash:
a079ba60c002900fb71e3905ed5f30a6bd826701
SH256 hash:
3863d2cab19dba2988e33810d9235e0f04aee019b696e4fdf4cf637b3072b19d
MD5 hash:
5d57e6b8aff1ec900f553789f6796648
SHA1 hash:
f9a953cfe6decb237ed98c30faabec8654d99171
SH256 hash:
126715e69bb46ac648a9063c15f08930b806f1214d9d0dd0395666cbc4e0d7da
MD5 hash:
85f48d0801863d9363f85f5037473823
SHA1 hash:
a679682bef7ad3fd9b2be52079011536aad96e50
SH256 hash:
4e0ddcd303f27c01dcc8a35a9bd821c53fb7dcca474ac7f0c84d3c6451e9f778
MD5 hash:
14052163e50c197697c64b1431b42271
SHA1 hash:
df301332faa73c3d5f915fde61df2fc9de21a61a
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
No further information available
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.