MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aae8fe497becc1d8bc355e12f207e2e65692cf34dd8df79e28be8550f5010874. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: aae8fe497becc1d8bc355e12f207e2e65692cf34dd8df79e28be8550f5010874
SHA3-384 hash: c6e4b5c92951cab618fd7de625d1bca180e828810b0547663c050d453e4597c10ef5a5cea61f787e09807bcf20625756
SHA1 hash: db9bf57b02888833de37165a36fa6127f27c74d3
MD5 hash: ad709327c57f43d9e3923e1178feda4f
humanhash: lithium-don-apart-snake
File name:PurchaseOrder.jar
Download: download sample
Signature STRRAT
File size:188'918 bytes
First seen:2023-04-11 09:00:21 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:nTf9sTFSNf3K9li1FWkhSbs6kCSnNvRQ+cjl/e8VB27AlpNCSn2hVjuY:nTf9spSdS8Wk+s6khNv3O1b27uEAQjR
TLSH T11C0413CF4FC040CA98B79D1D2639DB15EA3C82B112B4AC5AE7E3991D904EAB9450FF91
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
103.47.144.50:49606

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PurchaseOrder.jar
Verdict:
No threats detected
Analysis date:
2023-04-11 09:02:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
68 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Uses regedit.exe to modify the Windows registry
Yara detected AllatoriJARObfuscator
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 844479 Sample: PurchaseOrder.jar Startdate: 11/04/2023 Architecture: WINDOWS Score: 68 28 sonatype.map.fastly.net 2->28 30 repo1.maven.org 2->30 38 Malicious sample detected (through community Yara rule) 2->38 40 Multi AV Scanner detection for submitted file 2->40 42 Exploit detected, runtime environment starts unknown processes 2->42 44 Yara detected AllatoriJARObfuscator 2->44 8 java.exe 6 2->8         started        10 7za.exe 8 2->10         started        signatures3 process4 process5 12 wscript.exe 3 3 8->12         started        15 icacls.exe 1 8->15         started        17 conhost.exe 8->17         started        19 conhost.exe 10->19         started        signatures6 46 Uses regedit.exe to modify the Windows registry 12->46 21 javaw.exe 12 12->21         started        24 regedit.exe 12->24         started        26 conhost.exe 15->26         started        process7 dnsIp8 32 github.com 140.82.121.3, 443, 49701, 49705 GITHUBUS United States 21->32 34 140.82.121.4, 443, 49723, 49727 GITHUBUS United States 21->34 36 3 other IPs or domains 21->36
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2023-04-11 09:01:08 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Modifies registry class
Runs .reg file with regedit
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments