MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89ddd76c8a55caef9f05473a49fefe22c0f5835abe63b95a51fd972bb7a959be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 89ddd76c8a55caef9f05473a49fefe22c0f5835abe63b95a51fd972bb7a959be
SHA3-384 hash: 660e830ebbf1135879e10db480225a2fc4ddb7e12d8b22b77e17531a5bae0281641fc2035a38045b6d6ab9822c155560
SHA1 hash: e071b26e4d69101ab044944c4053f3c55905cdc2
MD5 hash: fef7458a118a9f5291b1eec9956b7c37
humanhash: beryllium-mirror-spring-utah
File name:MoneyGramTopup Report up Sept 29.jar
Download: download sample
Signature STRRAT
File size:106'180 bytes
First seen:2021-09-29 12:27:04 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:5bdD/fWw/TRe6S0GbN5geAE7eI6GWaBzT:5RDWFI+XgnEyIoaBzT
TLSH T141A3D0AFBDA690B4D91B817356088231E60D61D9C14AE37BA0FC04863F79D6D0B4ADDF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
185.140.53.68:5055

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.140.53.68:5055 https://threatfox.abuse.ch/ioc/228008/

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
MoneyGramTopup Report up Sept 29.jar
Verdict:
No threats detected
Analysis date:
2021-09-29 19:47:50 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
evad.troj
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 493857 Sample: MoneyGramTopup Report up Se... Startdate: 30/09/2021 Architecture: WINDOWS Score: 60 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected STRRAT 2->30 32 Yara detected AllatoriJARObfuscator 2->32 8 cmd.exe 2 2->8         started        10 cmd.exe 1 2->10         started        process3 process4 12 java.exe 5 8->12         started        16 conhost.exe 8->16         started        18 7za.exe 73 10->18         started        dnsIp5 26 192.168.2.1 unknown unknown 12->26 24 C:\cmdlinestart.log, ASCII 12->24 dropped 20 icacls.exe 1 12->20         started        file6 process7 process8 22 conhost.exe 20->22         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2021-09-29 12:28:07 UTC
AV detection:
10 of 45 (22.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments