MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 968ed5f5fbf0b4666905b104eb77371942716fbfc2e240fc2c7eb4a99a9265c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 8


Intelligence 8 IOCs 1 YARA 4 File information Comments

SHA256 hash: 968ed5f5fbf0b4666905b104eb77371942716fbfc2e240fc2c7eb4a99a9265c2
SHA3-384 hash: 6753ba4eb7655e0cb4bd3c692f22cefdc7abba5c993c522d811c0bfb358466924f2a3acb93cff3302495aa93aefa22c7
SHA1 hash: ab408309380f26dac93fb1aa81e8da7035fff8be
MD5 hash: fccf9ac7d9db45ce6dae839ab0660a28
humanhash: triple-johnny-magazine-timing
File name:invoice order-9951487307#..xlsb
Download: download sample
Signature STRRAT
File size:71'416 bytes
First seen:2021-09-01 06:10:29 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 1536:29LKBLo0CLRyt7VrolmSb4wjE7zF0Rhdv1hQzMrTeLAD:2dw9Cd1Lb4GE0DrTekD
TLSH T133639C753E0BC084D86B7EB8B3C9B97435040E7765D2E53E08845DBE21A9FC2126DDAB
Reporter abuse_ch
Tags:STRRAT xlsb xlsx


Avatar
abuse_ch
STRRAT C2:
105.110.181.161:1990

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
105.110.181.161:1990 https://threatfox.abuse.ch/ioc/204144/

Intelligence


File Origin
# of uploads :
1
# of downloads :
216
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
invoice order-9951487307#..xlsb
Verdict:
Malicious activity
Analysis date:
2021-09-01 06:11:58 UTC
Tags:
macros40

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a process with a hidden window
Connection attempt
Sending an HTTP GET request
Creating a file
Sending a UDP request
Running batch commands by exploiting the app vulnerability
Launching a file downloaded from the Internet
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Excel4Macro
Payload URLs
URL
File name
18.222.206.129
workbook.bin
Document image
Document image
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Document exploit detected (process start blacklist hit)
Exploit detected, runtime environment dropped PE file
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Powershell drops PE file
Sigma detected: Drops script at startup location
Sigma detected: Encoded IEX
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Powershell Download and Execute IEX
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Suspicious powershell command line found
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 475557 Sample: invoice order-9951487307#..xlsb Startdate: 01/09/2021 Architecture: WINDOWS Score: 100 63 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->63 65 Antivirus detection for URL or domain 2->65 67 Multi AV Scanner detection for submitted file 2->67 69 8 other signatures 2->69 11 EXCEL.EXE 53 13 2->11         started        14 cmd.exe 2->14         started        process3 file4 51 C:\...\~$invoice order-9951487307#..xlsb, data 11->51 dropped 16 cmd.exe 11->16         started        20 cmd.exe 14->20         started        process5 dnsIp6 53 54.202.26.55, 49167, 80 AMAZON-02US United States 16->53 61 Suspicious powershell command line found 16->61 22 powershell.exe 15 345 16->22         started        26 java.exe 2 20->26         started        signatures7 process8 file9 41 C:\User\bin\zip.dll, PE32 22->41 dropped 43 C:\User\bin\wsdetect.dll, PE32 22->43 dropped 45 C:\User\bin\w2k_lsa_auth.dll, PE32 22->45 dropped 47 132 other files (85 malicious) 22->47 dropped 73 Powershell drops PE file 22->73 28 cmd.exe 22->28         started        30 java.exe 2 26->30         started        signatures10 process11 process12 32 cmd.exe 28->32         started        process13 34 java.exe 14 32->34         started        dnsIp14 55 8.8.8.8 GOOGLEUS United States 34->55 57 140.82.121.3 GITHUBUS United States 34->57 59 2 other IPs or domains 34->59 71 Exploit detected, runtime environment dropped PE file 34->71 38 java.exe 13 34->38         started        signatures15 process16 file17 49 C:\Users\user\...\jna6270138850708174859.dll, PE32 38->49 dropped
Threat name:
Document-Word.Trojan.IcedID
Status:
Malicious
First seen:
2021-09-01 06:11:05 UTC
AV detection:
4 of 42 (9.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
macro xlm
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Drops startup file
Loads dropped DLL
Blocklisted process makes network request
Executes dropped EXE
Process spawned unexpected child process
Malware Config
Dropper Extraction:
http://54.202.26.55/oo
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_Dridex_xls_20200528
Author:abuse.ch
Rule name:ach_Quakbot_xlsb_20201023
Author:abuse.ch
Description:Detects Quakbot XLS
Rule name:silentbuilder_halo_generated
Author:Halogen Generated Rule, Corsin Camichel
Rule name:zloader_halo_generated
Author:Halogen Generated Rule, Corsin Camichel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments