MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f82ffeb8a0fbf1f0bddb154a0bf85b730564c3f067c62d382802ccc5662efff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8f82ffeb8a0fbf1f0bddb154a0bf85b730564c3f067c62d382802ccc5662efff
SHA3-384 hash: ceae63e9e2fec859555c143bed373ea381c8c1e6b2c30987c025438d4a0113ec52dea6f5414e59e0f32a51f78cc48eab
SHA1 hash: 3e89ae98a225a287458fa3f3c861f26bf8637740
MD5 hash: 28c02f29fdf307393b4b71669c55a81d
humanhash: eighteen-california-thirteen-single
File name:Purchase_Order_Aumita_2026-07-23.jar
Download: download sample
Signature STRRAT
File size:32'911 bytes
First seen:2026-07-23 13:06:17 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 768:8cRfAtuQxaPDujwK00z4do3Txn+8a3jVIxxWBtIjFxNyuyvIXfSoS5dKd7Qv4:8chAtuGWMwK00zPTxRkWnWHSEtvIv9Sy
TLSH T108E2E1425F9AD4BCD18284BC8234912248324FDA8D49757B7F563BDF9194CBC382CDA9
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter smica83
Tags:jar STRRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
8f82ffeb8a0fbf1f0bddb154a0bf85b730564c3f067c62d382802ccc5662efff.zip
Verdict:
No threats detected
Analysis date:
2026-07-24 08:28:58 UTC
Tags:
arch-doc arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
jar
First seen:
2026-07-23T01:38:00Z UTC
Last seen:
2026-07-24T06:55:00Z UTC
Hits:
~100
Result
Threat name:
Caesium Obfuscator
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Yara detected Caesium Obfuscator
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1947087 Sample: Purchase_Order_Aumita_2026-... Startdate: 23/07/2026 Architecture: WINDOWS Score: 48 12 Yara detected Caesium Obfuscator 2->12 6 cmd.exe 1 2->6         started        process3 process4 8 java.exe 3 6->8         started        10 conhost.exe 6->10         started       
Result
Malware family:
Score:
  10/10
Tags:
family:strrat discovery execution persistence stealer trojan
Behaviour
Modifies registry key
Runs ping.exe
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
System Network Configuration Discovery: Internet Connection Discovery
Drops file in System32 directory
Adds Run key to start application
Looks up external IP address via web service
Loads dropped DLL
Family: STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments