MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5caf6e13b9ea3a95e4381f1f09028ccab2e587d691eec71801fadecc7f17f2f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 5caf6e13b9ea3a95e4381f1f09028ccab2e587d691eec71801fadecc7f17f2f4
SHA3-384 hash: a8593c7daf3e6360e41c55c0f095eedb68826cf0afd22a81d232b0d0fb3d185f867cff8d7af80764d0536fc84925f295
SHA1 hash: 16fe9a82bfc3426d3432a259805a545c841d9f00
MD5 hash: 11948f31e270d299e3d659cc06eb36c7
humanhash: king-monkey-oranges-may
File name:invoice IM-NE11043-22 and IU-NE10009-22.jar
Download: download sample
Signature STRRAT
File size:454'776 bytes
First seen:2023-08-20 23:40:19 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 6144:diF42NoOfhOmFaoPrm+2Vy8/OWggf3HE5QaG4M333Gu8lZEq8MhUgSLUTHdy0mo2:Mu29lPoyEcquMW7nEq8vLw9y0mohlS
TLSH T164A4121B389A6475E8579D322482A336575819F8D0C89CAF1EF9394E0C30D6CEA46FDB
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
212.193.30.230:4554

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
invoice IM-NE11043-22 and IU-NE10009-22.jar
Verdict:
Malicious activity
Analysis date:
2023-08-20 23:41:25 UTC
Tags:
rat strrat evasion remote

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Threat name:
Detection:
malicious
Classification:
troj.expl
Score:
68 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1294215 Sample: invoice_IM-NE11043-22_and_I... Startdate: 21/08/2023 Architecture: WINDOWS Score: 68 19 Found malware configuration 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Yara detected STRRAT 2->23 25 Exploit detected, runtime environment starts unknown processes 2->25 7 java.exe 5 2->7         started        9 7za.exe 77 2->9         started        process3 process4 11 icacls.exe 1 7->11         started        13 conhost.exe 7->13         started        15 conhost.exe 9->15         started        process5 17 conhost.exe 11->17         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2023-08-20 22:10:20 UTC
File Type:
Binary (Archive)
Extracted files:
70
AV detection:
10 of 38 (26.32%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Drops file in Program Files directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments