MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 56c4a7ab10b6387be81acdf783ecc80d441b7a6b890a6400df1ca86c754afa1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 56c4a7ab10b6387be81acdf783ecc80d441b7a6b890a6400df1ca86c754afa1e
SHA3-384 hash: e8528c723b56eb708df38a5e3c350afb65983bd2ccaa19478682c00f36f0534650121089bd97322d64cd5d335277fae5
SHA1 hash: 427a76ac3830d63373df08f4a2f423045e68e703
MD5 hash: 6da8c1d08d13b62de5cce8c2898c879e
humanhash: lithium-illinois-oven-tennis
File name:CV profiles Details.js
Download: download sample
Signature STRRAT
File size:190'343 bytes
First seen:2021-09-18 08:31:10 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:HEP0kKQSsUXZlbKbW4oHTNeaTg2HtARK698miYdTz8m+T3DPLa86kz:dkKcU3bl50kK98mit3i86kz
TLSH T16114AD210BB01A60DD66B20461FF0728A6FF675AD158350FFAFE6AC59F65001E31E73A
Reporter abuse_ch
Tags:js STRRAT


Avatar
abuse_ch
STRRAT C2:
23.105.131.243:1959

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
23.105.131.243:1959 https://threatfox.abuse.ch/ioc/223293/

Intelligence


File Origin
# of uploads :
1
# of downloads :
291
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2021-09-18 08:32:05 UTC
AV detection:
2 of 45 (4.44%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments