MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 538b56bb9dfd234b01c7d1d28fd4b79cc6ae7b14f2db5227f72379b772d072ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 538b56bb9dfd234b01c7d1d28fd4b79cc6ae7b14f2db5227f72379b772d072ee
SHA3-384 hash: 59a1c304ccb362828df1b490ecae011d92382e3015091721c1379ac27c5b4a15da25b8f70a5c029a90f57f35b3d87b75
SHA1 hash: 06c5b06d50feb5ceddcc28854bfa82837b832f0c
MD5 hash: 30f94569eb0972d14f9cb2567f0e3164
humanhash: eleven-quebec-hawaii-ceiling
File name:#MBT-PO-320.jar
Download: download sample
Signature STRRAT
File size:224'807 bytes
First seen:2023-05-09 01:50:26 UTC
Last seen:2023-05-10 06:11:22 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 6144:iL3FXwj7TdEJz+qkRrbuRjSR4SLYiK8jEcNj7:iyj7Tyw3PuRjNS8dvc5
TLSH T10624020FBDFACAEAD40B727A1585D55AEA0D0285D242532B51FC5C090DB1C7E1B8BACF
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
185.29.8.112:8778

Intelligence


File Origin
# of uploads :
2
# of downloads :
160
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
#MBT-PO-320.jar
Verdict:
Malicious activity
Analysis date:
2023-05-09 01:50:43 UTC
Tags:
rat strrat evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
banload spyagent
Result
Threat name:
Detection:
malicious
Classification:
troj.evad.expl
Score:
84 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Uses 7zip to decompress a password protected archive
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 861759 Sample: #MBT-PO-320.jar Startdate: 09/05/2023 Architecture: WINDOWS Score: 84 19 Found malware configuration 2->19 21 Malicious sample detected (through community Yara rule) 2->21 23 Multi AV Scanner detection for submitted file 2->23 25 4 other signatures 2->25 7 java.exe 5 2->7         started        9 7za.exe 81 2->9         started        process3 process4 11 icacls.exe 1 7->11         started        13 conhost.exe 7->13         started        15 conhost.exe 9->15         started        process5 17 conhost.exe 11->17         started       
Threat name:
ByteCode-JAVA.Trojan.Strrat
Status:
Malicious
First seen:
2023-05-09 01:51:07 UTC
File Type:
Binary (Archive)
Extracted files:
76
AV detection:
10 of 37 (27.03%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments