MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abda456f2f4994e4e619ecfe2ef5dd2e1a4fd6d4e3be8d27074052703362eb15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: abda456f2f4994e4e619ecfe2ef5dd2e1a4fd6d4e3be8d27074052703362eb15
SHA3-384 hash: f9ecbe7490b42e7a82eda48a14685566a7f29e3986c777b81b96387ca8cf81910bc2b7e57d37f4656f885938fdebd78e
SHA1 hash: 40e266ee6285586405bb3a9d75193672bbac72a7
MD5 hash: 0820fe7a5db15cc5cac299cd26e4c95d
humanhash: fourteen-sierra-nuts-skylark
File name:DHL Paket.jar
Download: download sample
Signature STRRAT
File size:192'506 bytes
First seen:2021-04-07 18:59:52 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:ZlRpFPn2CMV+3qMf2H8Np/coC9Ivr3YFVOgKeJaNovDE2wqWBAmm2CmvkmemptMq:Bn2hV+6cRcxwmceWgDUAmN7/Mru
TLSH BC141206B8B6D565EBD602371F8BBBBBD51E42ED00328F2F08D21B947433546959E28F
Reporter neoxmorpheus1
Tags:STRRAT

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
185.203.119.28:7888 https://threatfox.abuse.ch/ioc/7204/

Intelligence


File Origin
# of uploads :
1
# of downloads :
154
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
DHL Paket.jar
Verdict:
No threats detected
Analysis date:
2021-04-07 19:01:59 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
96 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Get antivirus details via WMIC query
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 383486 Sample: DHL Paket.jar Startdate: 07/04/2021 Architecture: WINDOWS Score: 96 92 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->92 94 Multi AV Scanner detection for domain / URL 2->94 96 Yara detected STRRAT 2->96 98 5 other signatures 2->98 12 cmd.exe 2 2->12         started        15 notepad.exe 2->15         started        17 notepad.exe 2->17         started        19 3 other processes 2->19 process3 signatures4 102 Uses schtasks.exe or at.exe to add and modify task schedules 12->102 21 java.exe 6 12->21         started        23 conhost.exe 12->23         started        process5 process6 25 wscript.exe 2 21->25         started        27 icacls.exe 1 21->27         started        process7 29 javaw.exe 26 25->29         started        32 conhost.exe 27->32         started        dnsIp8 86 github.com 140.82.121.4, 443, 49727 GITHUBUS United States 29->86 88 github-releases.githubusercontent.com 185.199.108.154, 443, 49729 FASTLYUS Netherlands 29->88 90 3 other IPs or domains 29->90 34 java.exe 2 21 29->34         started        process9 file10 74 C:\Users\user\AppData\...\gntlnuldjx.txt, Zip 34->74 dropped 76 C:\Users\user\...\jna1083201027451631490.dll, PE32 34->76 dropped 37 java.exe 34->37         started        41 cmd.exe 34->41         started        43 conhost.exe 34->43         started        process11 dnsIp12 80 185.203.119.28, 49734, 7888 BELCLOUDBG Cyprus 37->80 82 str-master.pw 37->82 84 ip-api.com 208.95.112.1, 49735, 80 TUT-ASUS United States 37->84 78 C:\Users\user\...\jna3054188060683580399.dll, PE32 37->78 dropped 45 cmd.exe 37->45         started        47 cmd.exe 37->47         started        49 cmd.exe 37->49         started        55 2 other processes 37->55 51 conhost.exe 41->51         started        53 schtasks.exe 41->53         started        file13 process14 process15 57 WMIC.exe 45->57         started        60 conhost.exe 45->60         started        62 conhost.exe 47->62         started        64 WMIC.exe 47->64         started        66 conhost.exe 49->66         started        68 WMIC.exe 49->68         started        70 conhost.exe 55->70         started        72 WMIC.exe 55->72         started        signatures16 100 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 57->100
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments