MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a3b480ce2b82d4b08f7e904e497e222753a731875d67fe5de99b2b144f7ccf48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: a3b480ce2b82d4b08f7e904e497e222753a731875d67fe5de99b2b144f7ccf48
SHA3-384 hash: 840d9304cb7bc9ebffcc4958dc7fa81c23b36d437f7d7203cb60e3504ceafaf4470a505d83ab7d129e15967c061eb09c
SHA1 hash: 6e28063ee78e517143ad5363ebd1e036514d6917
MD5 hash: 536d2bc29415f705f2e9a26ce0ee349f
humanhash: mountain-butter-tennessee-wolfram
File name:Quotation.jar
Download: download sample
Signature STRRAT
File size:122'479 bytes
First seen:2021-05-12 06:01:14 UTC
Last seen:2021-05-12 07:01:55 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 3072:9etLzTD/ZbFzeisahqGmvq4iLZ5PS480SjWBa79alk:gzZXxhR8qrL/vgCBa5alk
TLSH 97C312E9EC947AA3FEAD7470460FFE855D10676BEFABD046C1380F1250128A3146E75B
Reporter cocaman
Tags:jar STRRAT


Avatar
cocaman
Malicious email (T1566.001)
From: "pamteven@gmail.com" (likely spoofed)
Received: "from ip-221-107.dataclub.info (unknown [46.183.221.107]) "
Date: "12 May 2021 08:33:10 +0300"
Subject: "RE: Request for Quotation"
Attachment: "Quotation.jar"

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
194.5.98.38:2558 https://threatfox.abuse.ch/ioc/36045/

Intelligence


File Origin
# of uploads :
2
# of downloads :
134
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Quotation.jar
Verdict:
No threats detected
Analysis date:
2021-05-12 13:14:37 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
96 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Uses regedit.exe to modify the Windows registry
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 411884 Sample: Quotation.jar Startdate: 12/05/2021 Architecture: WINDOWS Score: 96 72 jfmamjjasond.awsmppl.com 2->72 80 Multi AV Scanner detection for domain / URL 2->80 82 Found malware configuration 2->82 84 Multi AV Scanner detection for submitted file 2->84 86 5 other signatures 2->86 12 cmd.exe 2 2->12         started        15 notepad.exe 2->15         started        17 notepad.exe 2->17         started        19 3 other processes 2->19 signatures3 process4 signatures5 90 Uses schtasks.exe or at.exe to add and modify task schedules 12->90 21 java.exe 6 12->21         started        24 conhost.exe 12->24         started        process6 file7 56 C:\Users\user\gukwmybxjx.js, Unknown 21->56 dropped 26 wscript.exe 3 3 21->26         started        30 icacls.exe 1 21->30         started        process8 file9 62 C:\Users\user\...\ebgeaegdbdecaedfebace.reg, ASCII 26->62 dropped 88 Uses regedit.exe to modify the Windows registry 26->88 32 javaw.exe 26 26->32         started        35 regedit.exe 26->35         started        37 conhost.exe 30->37         started        signatures10 process11 dnsIp12 66 github.com 140.82.121.4, 443, 49717 GITHUBUS United States 32->66 68 github-releases.githubusercontent.com 185.199.108.154, 443, 49721 FASTLYUS Netherlands 32->68 70 3 other IPs or domains 32->70 39 java.exe 2 21 32->39         started        process13 file14 58 C:\Users\user\AppData\...\zegkupnwda.txt, Zip 39->58 dropped 60 C:\Users\user\...\jna349952050647630169.dll, PE32 39->60 dropped 42 java.exe 39->42         started        46 cmd.exe 39->46         started        48 conhost.exe 39->48         started        process15 dnsIp16 74 jfmamjjasond.awsmppl.com 194.5.98.38, 2558, 49728, 49734 DANILENKODE Netherlands 42->74 76 10.9.0.6, 2558 unknown unknown 42->76 78 str-master.pw 42->78 64 C:\Users\user\...\jna117133358512948161.dll, PE32 42->64 dropped 50 conhost.exe 42->50         started        52 conhost.exe 46->52         started        54 schtasks.exe 46->54         started        file17 process18
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2021-05-12 04:41:28 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
8 of 47 (17.02%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Modifies registry class
Runs .reg file with regedit
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

STRRAT

Java file jar a3b480ce2b82d4b08f7e904e497e222753a731875d67fe5de99b2b144f7ccf48

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments