MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 920d80efcbeee1a05139ffbea05ca56e59e71809d11afbe47d1e2e9aa95a0e5b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 920d80efcbeee1a05139ffbea05ca56e59e71809d11afbe47d1e2e9aa95a0e5b
SHA3-384 hash: 1cec0cd4782ec92e3d04ebf7084fb40426b35380b0e7706c51e5eaabba81d22ef0645759847914678d22e2ece517c660
SHA1 hash: b0f67fa71525e2f843e73e84661ee638b0463f30
MD5 hash: 79d2b79bad5f52b3bd2e82327f871c92
humanhash: mountain-california-lithium-kilo
File name:Quotation.jar
Download: download sample
Signature STRRAT
File size:109'158 bytes
First seen:2021-08-26 10:31:58 UTC
Last seen:2021-09-04 06:30:08 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 1536:yT5QD5oMXaPkkqyGhbeIZtVg2XEMV8UjiQB0YLt2tE6Ys0XVdZnG1HV0+gCtQ:yKaqyG0NY7BGYkos+VdFaa+gCtQ
TLSH T143B3D01EAEEAC1A5E18745B38009A333BB4D12D8E00A553F26FC58564D79DBD0B16BCF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
103.133.105.29:2664

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
103.133.105.29:2664 https://threatfox.abuse.ch/ioc/198282/

Intelligence


File Origin
# of uploads :
2
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Quotation.jar
Verdict:
No threats detected
Analysis date:
2021-08-26 10:35:00 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
92 / 100
Signature
Creates autostart registry keys to launch java
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
May check the online IP address of the machine
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 472081 Sample: Quotation.jar Startdate: 26/08/2021 Architecture: WINDOWS Score: 92 104 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->104 106 Multi AV Scanner detection for submitted file 2->106 108 Yara detected STRRAT 2->108 110 4 other signatures 2->110 11 cmd.exe 2 2->11         started        14 javaw.exe 2->14         started        16 javaw.exe 2->16         started        18 3 other processes 2->18 process3 signatures4 112 Uses schtasks.exe or at.exe to add and modify task schedules 11->112 20 java.exe 29 11->20         started        24 conhost.exe 11->24         started        process5 dnsIp6 92 github.com 140.82.121.4, 443, 49709 GITHUBUS United States 20->92 94 github-releases.githubusercontent.com 185.199.108.154, 443, 49710 FASTLYUS Netherlands 20->94 96 3 other IPs or domains 20->96 76 C:\cmdlinestart.log, ASCII 20->76 dropped 78 C:\Program Files (x86)\Java\...\Quotation.jar, Zip 20->78 dropped 26 java.exe 4 20->26         started        29 icacls.exe 1 20->29         started        file7 process8 file9 82 C:\Users\user\Quotation.jar, Zip 26->82 dropped 31 java.exe 2 22 26->31         started        35 conhost.exe 26->35         started        37 conhost.exe 29->37         started        process10 file11 84 C:\Users\user\AppData\Roaming\Quotation.jar, Zip 31->84 dropped 86 C:\Users\user\AppData\...\Quotation.jar, Zip 31->86 dropped 88 C:\ProgramData\Microsoft\...\Quotation.jar, Zip 31->88 dropped 90 C:\Users\user\...\jna1011898343460305633.dll, PE32 31->90 dropped 102 Creates autostart registry keys to launch java 31->102 39 java.exe 14 31->39         started        43 cmd.exe 1 31->43         started        45 conhost.exe 31->45         started        47 WMIC.exe 35->47         started        50 conhost.exe 35->50         started        signatures12 process13 dnsIp14 98 103.133.105.29, 2664, 49714 VNPT-AS-VNVIETNAMPOSTSANDTELECOMMUNICATIONSGROUPVN Viet Nam 39->98 100 ip-api.com 208.95.112.1, 49717, 80 TUT-ASUS United States 39->100 80 C:\Users\user\...\jna3919345830411522234.dll, PE32 39->80 dropped 52 cmd.exe 39->52         started        54 cmd.exe 39->54         started        56 cmd.exe 39->56         started        62 2 other processes 39->62 58 conhost.exe 43->58         started        60 schtasks.exe 43->60         started        114 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 47->114 file15 signatures16 process17 process18 64 conhost.exe 52->64         started        66 WMIC.exe 52->66         started        68 conhost.exe 54->68         started        70 WMIC.exe 54->70         started        72 conhost.exe 56->72         started        74 WMIC.exe 56->74         started       
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2021-08-26 10:23:21 UTC
AV detection:
6 of 26 (23.08%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments