MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e8cbc4d7dae216004bb82560381d822fbb1dba3f1dabda8ff2db7d6353f95fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 8e8cbc4d7dae216004bb82560381d822fbb1dba3f1dabda8ff2db7d6353f95fd
SHA3-384 hash: c295388c50af9b6549dd5e07da7fa7d95beef315896e7a96d235ed131d7ff23857f7f3f7c917ef73aaf722a5687b5fa5
SHA1 hash: aff00d6977e76e94a159d8ec34b5644460cfab9e
MD5 hash: 09cff2db6d624a22fa08e634e3205e88
humanhash: idaho-beer-aspen-speaker
File name:Quotation Sheet.js
Download: download sample
Signature STRRAT
File size:191'213 bytes
First seen:2021-09-24 11:20:44 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:rAtVKO2HadaqGaXNZVOdlsfb5l9ccY6nP2hV8wAcAiAPtXydlZjbTku:ctIO24aqGiVOdlszfecYQ+4mANCFTku
TLSH T16E14AE304F80FAD09759361D412A1368F2E00EFA832FAC55BAEDD9BA4B77111651A4FF
Reporter abuse_ch
Tags:js STRRAT


Avatar
abuse_ch
STRRAT C2:
45.133.1.47:3284

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
45.133.1.47:3284 https://threatfox.abuse.ch/ioc/226200/

Intelligence


File Origin
# of uploads :
1
# of downloads :
263
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2021-09-24 11:21:06 UTC
AV detection:
5 of 45 (11.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments