🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f7872fa785ac58389fc06102323b887d2cd2cf01a858c904d5849ea6350a574. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: 7f7872fa785ac58389fc06102323b887d2cd2cf01a858c904d5849ea6350a574
SHA3-384 hash: 843bdbad7a09d063699b8f1f8dcc2f9287e95fb3c1594d5cb436dd0383cb0632b387c77c903009d8f50d1fed2c9659cf
SHA1 hash: 94b5552cb5b9e4e83523b65cf0f1e966479cf3d3
MD5 hash: 7ffe6a6f3b5d49276f792f21ae1b73ae
humanhash: venus-helium-equal-glucose
File name:Amagnol PI 4507791110.jar
Download: download sample
Signature STRRAT
File size:188'481 bytes
First seen:2022-02-10 07:26:22 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:p5p5kbP0qRolnCurUbBVTJb+U5h8vKOi2vqE0dDAbJA3IFLnvCn9UzH:Z5kzolnUbDJbt8Cwvf0dueYFjK0H
TLSH T1D404F14D7EFAD0E5E20B81362905D17FE90CB1A1A00AA5BB6AFC1F491C71D8C5345EAF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
45.133.174.157:1331

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
45.133.174.157:1331 https://threatfox.abuse.ch/ioc/384859/

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 569922 Sample: Amagnol PI 4507791110.jar Startdate: 10/02/2022 Architecture: WINDOWS Score: 76 25 Found malware configuration 2->25 27 Malicious sample detected (through community Yara rule) 2->27 29 Multi AV Scanner detection for submitted file 2->29 31 2 other signatures 2->31 8 cmd.exe 2 2->8         started        11 cmd.exe 1 2->11         started        process3 file4 23 C:\cmdlinestart.log, ASCII 8->23 dropped 13 java.exe 5 8->13         started        15 conhost.exe 8->15         started        17 7za.exe 70 11->17         started        process5 process6 19 icacls.exe 1 13->19         started        process7 21 conhost.exe 19->21         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2022-02-10 07:27:10 UTC
File Type:
Binary (Archive)
Extracted files:
65
AV detection:
12 of 43 (27.91%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments