MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1cee6f4c2e07b1cde019619a7e6253dae02fbc84ec9513c5d62dc3e6f5edd6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: a1cee6f4c2e07b1cde019619a7e6253dae02fbc84ec9513c5d62dc3e6f5edd6c
SHA3-384 hash: f339ce67ad789952f4461c5a2074c227cc52a9ed021a1083a7f0c4a8597899b8a1a4349f70891420ff8b35cdfcab8691
SHA1 hash: e316a6ccf08b3e96e2addba1a30ccc353feb5fc2
MD5 hash: 5f90626a020c3e1aa91813f49469cded
humanhash: east-arkansas-lake-high
File name:SHIPPING DOCUMENTS OF MV STAR TRADER.jar
Download: download sample
Signature STRRAT
File size:530'424 bytes
First seen:2023-08-02 22:30:21 UTC
Last seen:2023-08-15 07:25:33 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 12288:uCBTkrp/aHmrXnuEopPqqwD74W65DKykNCr952ZymfV5OjefK:u1xGmDjopCTF6tyc3IymzK
TLSH T103B4220F37CFD428E447947B2684AA6BA65D45D8E28D410F28FC688BADF0E446F17DD8
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
84.54.50.148:4424

Intelligence


File Origin
# of uploads :
2
# of downloads :
140
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
SHIPPING DOCUMENTS OF MV STAR TRADER.jar
Verdict:
Malicious activity
Analysis date:
2023-08-02 22:32:49 UTC
Tags:
rat strrat evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
Detection:
malicious
Classification:
troj.evad.expl
Score:
72 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Malicious sample detected (through community Yara rule)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1284739 Sample: SHIPPING_DOCUMENTS_OF_MV_ST... Startdate: 03/08/2023 Architecture: WINDOWS Score: 72 22 Found malware configuration 2->22 24 Malicious sample detected (through community Yara rule) 2->24 26 Yara detected STRRAT 2->26 28 2 other signatures 2->28 7 java.exe 5 2->7         started        10 7za.exe 83 2->10         started        process3 dnsIp4 20 192.168.2.1 unknown unknown 7->20 12 icacls.exe 1 7->12         started        14 conhost.exe 7->14         started        16 conhost.exe 10->16         started        process5 process6 18 conhost.exe 12->18         started       
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2023-08-02 22:31:06 UTC
File Type:
Binary (Archive)
Extracted files:
76
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Drops file in Program Files directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments