MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7467e03097fb1c6f8ae8b138335b3ea412e6837ee0803d44935b571671b1aa3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: a7467e03097fb1c6f8ae8b138335b3ea412e6837ee0803d44935b571671b1aa3
SHA3-384 hash: 6a6674e81b919532394a5b60a8061162b67d46beaa68290be1ebd493f35cfa468dcd1d49fd2f028fc6669895e0c58f60
SHA1 hash: af72d0671739b2167547bd95ac18df598cd58ae2
MD5 hash: ae4d8bf6b2cb97eeedc8370753a8d1fe
humanhash: nitrogen-carolina-alabama-louisiana
File name:e-transfer.jar
Download: download sample
Signature STRRAT
File size:182'007 bytes
First seen:2022-01-21 16:52:02 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:sQUOTOD2bSVyuNWR/J3tj+IERNKFwp13D1laPHFDDVc135vRJL:qOI2bY0RltC8sxMlH213h
TLSH T11A04F10B3CD651B8E60BC232C14543776E0C22D5D64662AF26FC18A61879D9D3B26FEF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
212.192.246.178:8555

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
212.192.246.178:8555 https://threatfox.abuse.ch/ioc/310414/

Intelligence


File Origin
# of uploads :
1
# of downloads :
504
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 557862 Sample: e-transfer.jar Startdate: 21/01/2022 Architecture: WINDOWS Score: 68 25 Found malware configuration 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Yara detected STRRAT 2->29 31 Yara detected AllatoriJARObfuscator 2->31 8 cmd.exe 2 2->8         started        11 cmd.exe 1 2->11         started        process3 file4 23 C:\cmdlinestart.log, ASCII 8->23 dropped 13 java.exe 5 8->13         started        15 conhost.exe 8->15         started        17 7za.exe 72 11->17         started        process5 process6 19 icacls.exe 1 13->19         started        process7 21 conhost.exe 19->21         started       
Threat name:
ByteCode-JAVA.Trojan.Tnega
Status:
Malicious
First seen:
2022-01-21 01:50:00 UTC
File Type:
Binary (Archive)
Extracted files:
65
AV detection:
16 of 27 (59.26%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Drops file in Program Files directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments