MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c7182aa1b2923ada85698bfa7749fc2c1f072d7db0b06bf53f3024ae0a3b960. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 6c7182aa1b2923ada85698bfa7749fc2c1f072d7db0b06bf53f3024ae0a3b960
SHA3-384 hash: 4933910a1c393895cc0fc8876be6d336c7e20d4fea7f2285cdd9fda39c314815708bc8efeae97cdefa2e16a3660eb449
SHA1 hash: 223aa72dc8621ce90c3f993faa4f174a3a283c84
MD5 hash: 38f9be60125b5961a275dfbf110fa988
humanhash: michigan-grey-yellow-king
File name:scanorder01321.jar
Download: download sample
Signature STRRAT
File size:179'072 bytes
First seen:2021-07-26 13:45:30 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:75n41pRfW5/fqtJTSCEmxOTGMQp8iAgY39tId12NNj9YHjEqSst:7x47Rf0HySCEsOEpJAf9tC2NzYHQkt
TLSH T108042256355379DC9EFAB0937E327CE17E41C2E6181BD7E7A63064B6144C8A6C8F43A0
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
194.5.98.243:7123

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
194.5.98.243:7123 https://threatfox.abuse.ch/ioc/162933/

Intelligence


File Origin
# of uploads :
1
# of downloads :
179
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
scanorder01321.jar
Verdict:
No threats detected
Analysis date:
2021-07-26 14:06:58 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
92 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
May check the online IP address of the machine
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: WScript or CScript Dropper
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 454228 Sample: scanorder01321.jar Startdate: 26/07/2021 Architecture: WINDOWS Score: 92 95 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->95 97 Multi AV Scanner detection for submitted file 2->97 99 Yara detected STRRAT 2->99 101 5 other signatures 2->101 12 cmd.exe 2 2->12         started        15 notepad.exe 2->15         started        17 notepad.exe 2->17         started        19 notepad.exe 2->19         started        process3 signatures4 105 Uses schtasks.exe or at.exe to add and modify task schedules 12->105 21 java.exe 6 12->21         started        24 conhost.exe 12->24         started        process5 file6 79 C:\Users\user\istolftlpt.js, ASCII 21->79 dropped 26 wscript.exe 2 21->26         started        28 icacls.exe 1 21->28         started        process7 process8 30 javaw.exe 26 26->30         started        33 conhost.exe 28->33         started        dnsIp9 89 github.com 140.82.121.4, 443, 49718 GITHUBUS United States 30->89 91 github-releases.githubusercontent.com 185.199.111.154, 443, 49721 FASTLYUS Netherlands 30->91 93 3 other IPs or domains 30->93 35 java.exe 2 21 30->35         started        process10 file11 75 C:\Users\user\AppData\...\peebjrallv.txt, Zip 35->75 dropped 77 C:\Users\user\...\jna8918219296346250964.dll, PE32 35->77 dropped 38 java.exe 14 35->38         started        42 cmd.exe 1 35->42         started        44 conhost.exe 35->44         started        process12 dnsIp13 83 194.5.98.243, 49726, 7123 DANILENKODE Netherlands 38->83 85 ip-api.com 208.95.112.1, 49732, 80 TUT-ASUS United States 38->85 87 str-master.pw 38->87 81 C:\Users\user\...\jna4482604464530031810.dll, PE32 38->81 dropped 46 cmd.exe 38->46         started        48 cmd.exe 38->48         started        50 cmd.exe 38->50         started        56 2 other processes 38->56 52 conhost.exe 42->52         started        54 schtasks.exe 42->54         started        file14 process15 process16 58 WMIC.exe 46->58         started        61 conhost.exe 46->61         started        63 conhost.exe 48->63         started        65 WMIC.exe 48->65         started        67 conhost.exe 50->67         started        69 WMIC.exe 50->69         started        71 conhost.exe 56->71         started        73 WMIC.exe 56->73         started        signatures17 103 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 58->103
Gathering data
Threat name:
Archive-JAR.Trojan.AdWind
Status:
Malicious
First seen:
2021-07-26 00:30:40 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments