MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 967fa32f56316f9d82e8ef6d0bf89e9087181f4e3526f8942fdb856eaf850f73. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: 967fa32f56316f9d82e8ef6d0bf89e9087181f4e3526f8942fdb856eaf850f73
SHA3-384 hash: 9fe8cc71563723e354192d686440b1acb0e1e1df70e6275999a732f5ea1b62d4ed525f96175b0af1d48cc8dc7d8b5888
SHA1 hash: 914fa53b4c31afa1fa2916915858f8f0e17d45f9
MD5 hash: 702f50307e0b5991498ae7ff916ec324
humanhash: virginia-beryllium-pluto-floor
File name:Invoivce-Remit NO8936383.js
Download: download sample
Signature STRRAT
File size:6'033 bytes
First seen:2022-07-08 13:05:39 UTC
Last seen:2022-07-08 13:37:10 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 96:SOoAuf4zu0nuCTueWevzn/uTepsVuqAHENuyaegWM4Jxjy7sEo5MdXG:eHCTievDGo8seuyE4JxuPXG
TLSH T1BFC17C6EF3A88DD2E90740D5BB2F072AE2241EB03F1CA6D44CC4EC59434C718531EB90
Reporter abuse_ch
Tags:js STRRAT


Avatar
abuse_ch
STRRAT C2:
62.197.136.159:2022

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
62.197.136.159:2022 https://threatfox.abuse.ch/ioc/815453/

Intelligence


File Origin
# of uploads :
2
# of downloads :
307
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive greyware obfuscated packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Benign windows process drops PE files
Deletes itself after installation
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
System process connects to network (likely due to code injection or exploit)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 659750 Sample: Invoivce-Remit NO8936383.js Startdate: 08/07/2022 Architecture: WINDOWS Score: 100 62 Multi AV Scanner detection for domain / URL 2->62 64 Malicious sample detected (through community Yara rule) 2->64 66 Antivirus detection for URL or domain 2->66 68 2 other signatures 2->68 8 wscript.exe 3 17 2->8         started        13 msiexec.exe 97 25 2->13         started        process3 dnsIp4 54 173.244.209.108 SOFTLAYERUS United States 8->54 56 104.18.7.145 CLOUDFLARENETUS United States 8->56 58 8.8.8.8 GOOGLEUS United States 8->58 32 C:\Users\user\...\jre-8u333-windows-x64.exe, PE32+ 8->32 dropped 34 C:\Users\...\jre-8u333-windows-x64[1].exe, PE32+ 8->34 dropped 70 System process connects to network (likely due to code injection or exploit) 8->70 72 Benign windows process drops PE files 8->72 74 JScript performs obfuscated calls to suspicious functions 8->74 76 Deletes itself after installation 8->76 15 jre-8u333-windows-x64.exe 11 8->15         started        18 javaw.exe 23 8->18         started        36 C:\Windows\Installer\MSI7F6E.tmp, PE32+ 13->36 dropped 38 C:\Windows\Installer\MSI6F5F.tmp, PE32+ 13->38 dropped 40 C:\Windows\Installer\MSI2276.tmp, PE32+ 13->40 dropped 42 C:\Program Files\Java\...\installer.exe, PE32+ 13->42 dropped 21 installer.exe 13->21         started        23 msiexec.exe 13->23         started        file5 signatures6 process7 dnsIp8 44 C:\Users\...\jre-8u333-windows-x64.exe (copy), PE32+ 15->44 dropped 46 C:\Users\user\AppData\...\jds7322812.tmp, PE32+ 15->46 dropped 25 jre-8u333-windows-x64.exe 3 44 15->25         started        48 140.82.121.3 GITHUBUS United States 18->48 50 140.82.121.4 GITHUBUS United States 18->50 52 2 other IPs or domains 18->52 28 icacls.exe 1 18->28         started        file9 process10 dnsIp11 60 23.203.81.246 AKAMAI-ASUS United States 25->60 30 conhost.exe 28->30         started        process12
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2022-07-08 13:06:06 UTC
File Type:
Text (JavaScript)
AV detection:
2 of 40 (5.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Behaviour
Checks processor information in registry
Modifies registry class
Modifies system certificate store
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in Windows directory
Enumerates connected drives
Checks computer location settings
Deletes itself
Loads dropped DLL
Blocklisted process makes network request
Downloads MZ/PE file
Executes dropped EXE
UPX packed file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments