MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f2e4b45ad072f284a1944947956fb78a6459f8b8b8a77bfa82550ada91dc30b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 14


Intelligence 14 IOCs 1 YARA 4 File information Comments

SHA256 hash: 7f2e4b45ad072f284a1944947956fb78a6459f8b8b8a77bfa82550ada91dc30b
SHA3-384 hash: 569b3f17c212e6406c479904d66a9482f608c9147b368e0cb9e3c1377ec7592b7f4034701cabec2886d7e0e061759f0e
SHA1 hash: d3327dcf9ffe5442270c81371fb8be4adbeeaf2f
MD5 hash: 71b6b54c27925a65ffb84dee25ebad3e
humanhash: west-dakota-emma-aspen
File name:Shipping Bill9655247 dated 13022026.PDF.jar
Download: download sample
Signature STRRAT
File size:213'382 bytes
First seen:2026-03-04 19:50:05 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:8NY2SYqZPAslE+bADWD7dZU0C0dCVDJ11hNhbR/13DztY45Ibm52KNYdp7Q+1:8dSYADzACDZ+0bQ1LLvz+45Ib9px
TLSH T1CD24F12B3DDA99B4E42344B21181D5B7E64C4399E466840B29FD2C8F0D32DAE4B43EDF
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
185.38.142.158:5006

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.38.142.158:5006 https://threatfox.abuse.ch/ioc/1758474/

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
Shipping Bill9655247 dated 13022026.PDF.jar
Verdict:
Malicious activity
Analysis date:
2026-03-04 19:51:16 UTC
Tags:
arch-doc java rat strrat github auto-startup auto-reg auto-sch remote evasion arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
jar
Detections:
Trojan-Downloader.Java.Agent.sb Trojan.Java.Agent.sb HEUR:Trojan.Java.Generic Backdoor.Java.StrRat.sb
Result
Threat name:
Caesium Obfuscator, STRRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Creates autostart registry keys to launch java
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Suspicious Startup Folder Persistence
Suricata IDS alerts for network traffic
Uses an obfuscated file name to hide its real file extension (double extension)
Uses schtasks.exe or at.exe to add and modify task schedules
Uses WMIC command to query system information (often done to detect virtual machines)
Yara detected AllatoriJARObfuscator
Yara detected Caesium Obfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1878454 Sample: Shipping Bill9655247 dated ... Startdate: 04/03/2026 Architecture: WINDOWS Score: 100 85 pm2bitcoin.com 2->85 87 repo1.maven.org.cdn.cloudflare.net 2->87 89 4 other IPs or domains 2->89 103 Suricata IDS alerts for network traffic 2->103 105 Found malware configuration 2->105 107 Malicious sample detected (through community Yara rule) 2->107 109 9 other signatures 2->109 11 cmd.exe 2 2->11         started        15 javaw.exe 2->15         started        17 javaw.exe 2->17         started        19 2 other processes 2->19 signatures3 process4 file5 77 C:\cmdlinestart.log, ASCII 11->77 dropped 115 Uses schtasks.exe or at.exe to add and modify task schedules 11->115 117 Uses WMIC command to query system information (often done to detect virtual machines) 11->117 21 java.exe 23 11->21         started        25 conhost.exe 11->25         started        signatures6 process7 dnsIp8 91 github.com 140.82.114.4, 443, 49723 GITHUBUS United States 21->91 93 release-assets.githubusercontent.com 185.199.111.133, 443, 49724 FASTLYUS Netherlands 21->93 95 repo1.maven.org.cdn.cloudflare.net 104.18.18.12, 443, 49720, 49721 CLOUDFLARENETUS United States 21->95 73 Shipping Bill96552...ed 13022026.PDF.jar, Zip 21->73 dropped 27 java.exe 2 11 21->27         started        file9 process10 file11 79 Shipping Bill96552...ed 13022026.PDF.jar, Zip 27->79 dropped 81 Shipping Bill96552...ed 13022026.PDF.jar, Zip 27->81 dropped 83 Shipping Bill96552...ed 13022026.PDF.jar, Zip 27->83 dropped 119 Creates autostart registry keys to launch java 27->119 31 java.exe 11 27->31         started        36 cmd.exe 1 27->36         started        38 conhost.exe 27->38         started        signatures12 process13 dnsIp14 97 pm2bitcoin.com 185.38.142.158, 49725, 5006 NETSOLUTIONSNL Portugal 31->97 99 ip-api.com 208.95.112.1, 49729, 80 TUT-ASUS United States 31->99 71 C:\Users\user\...\jna6312231573502889132.dll, PE32 31->71 dropped 101 Uses WMIC command to query system information (often done to detect virtual machines) 31->101 40 cmd.exe 1 31->40         started        43 cmd.exe 31->43         started        45 cmd.exe 31->45         started        51 2 other processes 31->51 47 conhost.exe 36->47         started        49 schtasks.exe 1 36->49         started        file15 signatures16 process17 signatures18 113 Uses WMIC command to query system information (often done to detect virtual machines) 40->113 53 WMIC.exe 1 40->53         started        56 conhost.exe 40->56         started        58 WMIC.exe 43->58         started        61 conhost.exe 43->61         started        63 conhost.exe 45->63         started        65 WMIC.exe 45->65         started        67 conhost.exe 51->67         started        69 WMIC.exe 51->69         started        process19 file20 111 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 53->111 75 stdout, ASCII 58->75 dropped signatures21
Threat name:
ByteCode-JAVA.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-03-04 19:50:36 UTC
File Type:
Binary (Archive)
Extracted files:
81
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat discovery execution persistence stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
System Network Configuration Discovery: Internet Connection Discovery
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
STRRAT
Strrat family
Malware Config
C2 Extraction:
pm2bitcoin.com:5006
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:STRRAT
Author:NDA0E
Description:Detects STRRAT config filename
Rule name:strrat_jar_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments