MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51a2b32805d812c7e6751db7f96ec55ecbcd8ba2f11255b7dc1e14c217ca4296. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: 51a2b32805d812c7e6751db7f96ec55ecbcd8ba2f11255b7dc1e14c217ca4296
SHA3-384 hash: 79ec7bcec2957eeed2241a7b98f874c66faecf7444be8422dc7c7f4e4209e818a9f71334def2c5961bdfb85c4b81863b
SHA1 hash: 1ae1890ecfc07b2e3439b175de489d500a787fa4
MD5 hash: d10be3b2f79d96289b9dd6b5c490958f
humanhash: hydrogen-double-cup-butter
File name:1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar
Download: download sample
Signature STRRAT
File size:84'169 bytes
First seen:2021-07-08 12:51:03 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 1536:1m2NehWzRUY3LaiMXrFz3pmdXqH1+riYwO4Y8C+k8pC1H:02BzRzLaiMr55GXqcADYnH
TLSH T11D83E01B716B50B2D10B91333410037BBB6D9A90D612966B35FD28372D36C2C3EEE66E
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
158.69.53.93:77

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
158.69.53.93:77 https://threatfox.abuse.ch/ioc/158646/

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar
Verdict:
No threats detected
Analysis date:
2021-07-08 12:54:33 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Creates autostart registry keys to launch java
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
May check the online IP address of the machine
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 445894 Sample: 1BhmQQkiR5BrTs5yBLUVwWjLMfQ... Startdate: 08/07/2021 Architecture: WINDOWS Score: 100 99 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->99 101 Found malware configuration 2->101 103 Multi AV Scanner detection for submitted file 2->103 105 5 other signatures 2->105 10 cmd.exe 2 2->10         started        13 javaw.exe 2 2->13         started        15 javaw.exe 2->15         started        17 3 other processes 2->17 process3 signatures4 109 Uses schtasks.exe or at.exe to add and modify task schedules 10->109 19 java.exe 29 10->19         started        23 conhost.exe 10->23         started        process5 dnsIp6 91 github.com 140.82.121.4, 443, 49742 GITHUBUS United States 19->91 93 github-releases.githubusercontent.com 185.199.111.154, 443, 49744 FASTLYUS Netherlands 19->93 95 2 other IPs or domains 19->95 73 C:\cmdlinestart.log, ASCII 19->73 dropped 75 C:\...\1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar, Zip 19->75 dropped 25 java.exe 2 22 19->25         started        30 icacls.exe 1 19->30         started        file7 process8 dnsIp9 97 192.168.2.1 unknown unknown 25->97 77 C:\...\1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar, Zip 25->77 dropped 79 C:\...\1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar, Zip 25->79 dropped 81 C:\...\1BhmQQkiR5BrTs5yBLUVwWjLMfQhv4xjUX.jar, Zip 25->81 dropped 83 C:\Users\user\...\jna3538814699313832565.dll, PE32 25->83 dropped 111 Creates autostart registry keys to launch java 25->111 32 java.exe 14 25->32         started        36 cmd.exe 1 25->36         started        38 conhost.exe 25->38         started        40 conhost.exe 30->40         started        file10 signatures11 process12 dnsIp13 85 158.69.53.93, 49759, 77 OVHFR Canada 32->85 87 ip-api.com 208.95.112.1, 49760, 80 TUT-ASUS United States 32->87 89 str-master.pw 32->89 71 C:\Users\user\...\jna4028154752665840397.dll, PE32 32->71 dropped 42 cmd.exe 32->42         started        44 cmd.exe 32->44         started        46 cmd.exe 32->46         started        52 2 other processes 32->52 48 conhost.exe 36->48         started        50 schtasks.exe 1 36->50         started        file14 process15 process16 54 WMIC.exe 42->54         started        57 conhost.exe 42->57         started        59 conhost.exe 44->59         started        61 WMIC.exe 44->61         started        63 conhost.exe 46->63         started        65 WMIC.exe 46->65         started        67 conhost.exe 52->67         started        69 WMIC.exe 52->69         started        signatures17 107 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 54->107
Threat name:
ByteCode-JAVA.Exploit.Jovab
Status:
Malicious
First seen:
2021-07-08 06:28:45 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments