MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ebef5d23ce0fe6c2940ba7a2f6bfc512b1ec5f01458284d2ce0e71ee8787b81. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 13


Intelligence 13 IOCs 1 YARA 3 File information Comments

SHA256 hash: 4ebef5d23ce0fe6c2940ba7a2f6bfc512b1ec5f01458284d2ce0e71ee8787b81
SHA3-384 hash: 888d069ef6b291ad1239b6cc20db116bf58e8a5be7fc65673d6df50daba300b0a485ad8575c763e8c76edae4bb5d989d
SHA1 hash: 2a49e1d00a6d3c7696d31066441d8e2e316fa259
MD5 hash: d23e5bf11f4f551477a4168152d9c412
humanhash: network-equal-cold-hotel
File name:PROOF OF PAYMENT1.vbs
Download: download sample
Signature STRRAT
File size:1'882'799 bytes
First seen:2025-09-18 07:15:06 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24576:BjppEazEuoayPghOIPj6Ois4R9LWsRC71Sx5aLaBHyriYb:tguIs4RPKx
TLSH T19195AE55EB844B8D7298092BE07C492EB7F25F0BE4E375CD2B537E0B295FE0C6209985
Magika vba
Reporter abuse_ch
Tags:STRRAT vbs


Avatar
abuse_ch
STRRAT C2:
51.79.62.89:3512

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
51.79.62.89:3512 https://threatfox.abuse.ch/ioc/1593822/

Intelligence


File Origin
# of uploads :
1
# of downloads :
293
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
vmdetect shell spawn sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm masquerade obfuscated obfuscated
Verdict:
Malicious
File Type:
text
First seen:
2025-09-18T04:08:00Z UTC
Last seen:
2025-09-18T04:08:00Z UTC
Hits:
~100
Result
Threat name:
Nanocore, DarkTortilla, STRRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for dropped file
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Changes security center settings (notifications, updates, antivirus, firewall)
Creates autostart registry keys to launch java
Creates multiple autostart registry keys
Detected Nanocore Rat
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Startup Folder Persistence
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suricata IDS alerts for network traffic
Uses dynamic DNS services
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses schtasks.exe or at.exe to add and modify task schedules
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected AllatoriJARObfuscator
Yara detected AntiVM3
Yara detected DarkTortilla Crypter
Yara detected Nanocore RAT
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1779840 Sample: PROOF OF PAYMENT1.vbs Startdate: 18/09/2025 Architecture: WINDOWS Score: 100 125 takersjavby.duckdns.org 2->125 127 str-master.pw 2->127 129 5 other IPs or domains 2->129 131 Suricata IDS alerts for network traffic 2->131 133 Found malware configuration 2->133 135 Malicious sample detected (through community Yara rule) 2->135 139 18 other signatures 2->139 12 wscript.exe 3 3 2->12         started        16 svchost.exe 2->16         started        18 javaw.exe 2->18         started        20 7 other processes 2->20 signatures3 137 Uses dynamic DNS services 125->137 process4 file5 107 C:\Users\user\AppData\Local\Temp\java.js, ASCII 12->107 dropped 109 C:\Users\user\AppData\Local\Temp\audiodg.js, ASCII 12->109 dropped 151 Benign windows process drops PE files 12->151 153 VBScript performs obfuscated calls to suspicious functions 12->153 155 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->155 22 wscript.exe 2 12->22         started        25 wscript.exe 3 2 12->25         started        157 Changes security center settings (notifications, updates, antivirus, firewall) 16->157 27 MpCmdRun.exe 16->27         started        signatures6 process7 file8 95 C:\Users\user\AppData\Local\Temp\QNaZg.exe, PE32 22->95 dropped 29 QNaZg.exe 4 22->29         started        32 javaw.exe 22 25->32         started        35 conhost.exe 27->35         started        process9 dnsIp10 159 Antivirus detection for dropped file 29->159 161 Detected Nanocore Rat 29->161 163 Hides that the sample has been downloaded from the Internet (zone.identifier) 29->163 37 cmd.exe 29->37         started        40 cmd.exe 29->40         started        111 github.com 140.82.116.4, 443, 49681 GITHUBUS United States 32->111 113 release-assets.githubusercontent.com 185.199.108.133, 443, 49685 FASTLYUS Netherlands 32->113 115 dualstack.sonatype.map.fastly.net 199.232.192.209, 443, 49682, 49683 FASTLYUS United States 32->115 43 java.exe 1 17 32->43         started        signatures11 process12 file13 141 Uses ping.exe to sleep 37->141 143 Uses schtasks.exe or at.exe to add and modify task schedules 37->143 145 Uses ping.exe to check the status of other devices and networks 37->145 45 reg.exe 37->45         started        48 PING.EXE 37->48         started        51 conhost.exe 37->51         started        97 C:\Users\user\AppData\Roaming\word\word.exe, PE32 40->97 dropped 53 word.exe 40->53         started        55 conhost.exe 40->55         started        64 2 other processes 40->64 99 C:\Users\user\...\jna1508268632086470621.dll, PE32 43->99 dropped 101 C:\Users\user\AppData\Roaming\PHat.jar, Composite 43->101 dropped 103 C:\Users\user\AppData\Roaming\...\PHat.jar, Composite 43->103 dropped 147 Creates autostart registry keys to launch java 43->147 149 Creates multiple autostart registry keys 43->149 57 java.exe 43->57         started        60 cmd.exe 43->60         started        62 conhost.exe 43->62         started        signatures14 process15 dnsIp16 165 Creates multiple autostart registry keys 45->165 117 127.0.0.1 unknown unknown 48->117 167 Antivirus detection for dropped file 53->167 169 Hides that the sample has been downloaded from the Internet (zone.identifier) 53->169 119 takersjavby.duckdns.org 51.79.62.89, 3512, 49696 OVHFR Canada 57->119 121 ip-api.com 208.95.112.1, 49697, 80 TUT-ASUS United States 57->121 123 str-master.pw 5.79.71.205, 80 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 57->123 105 C:\Users\user\...\jna1300002518853220240.dll, PE32 57->105 dropped 66 cmd.exe 57->66         started        68 cmd.exe 57->68         started        70 cmd.exe 57->70         started        76 2 other processes 57->76 72 conhost.exe 60->72         started        74 schtasks.exe 60->74         started        file17 signatures18 process19 process20 78 WMIC.exe 66->78         started        81 conhost.exe 66->81         started        83 conhost.exe 68->83         started        85 WMIC.exe 68->85         started        87 conhost.exe 70->87         started        89 WMIC.exe 70->89         started        91 conhost.exe 76->91         started        93 WMIC.exe 76->93         started        signatures21 171 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 78->171
Verdict:
Malware
YARA:
2 match(es)
Tags:
ADODB.Stream DeObfuscated Microsoft.XMLDOM Obfuscated Scripting.FileSystemObject T1059.005 VBScript WScript.Shell
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-18 07:23:40 UTC
File Type:
Text (VBS)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:darktortilla family:strrat crypter discovery execution loader persistence stealer trojan
Behaviour
Modifies registry class
Runs ping.exe
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Executes dropped EXE
Loads dropped DLL
Detect jar appended to MSI
Darktortilla
Darktortilla family
Detects Darktortilla crypter.
STRRAT
Strrat family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:SUSP_Double_Base64_Encoded_Executable_RID34CC
Author:Florian Roth
Description:Detects an executable that has been encoded with base64 twice
Reference:https://twitter.com/TweeterCyber/status/1189073238803877889
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments