MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6293baf9939cfa1d421c46339bf0ff8ec167b0880de613c48101f5280e41f63. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: b6293baf9939cfa1d421c46339bf0ff8ec167b0880de613c48101f5280e41f63
SHA3-384 hash: 3a91a8a79747edcfc21394b039d00cd121277ba0f49eb741296e7fc3748cb6a7fc748745eeed7592a7e11a881e56145b
SHA1 hash: d94a8cbf45c5905d588b80c5dab61ac777a73cd1
MD5 hash: 5a08a4ccc4f1598cfa42d9cd856fa176
humanhash: sierra-cat-mike-august
File name:edb57976b9316f7685b3ef8dc26a2311.jar.exe
Download: download sample
Signature STRRAT
File size:373'845 bytes
First seen:2022-04-21 15:16:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 6144:qiF7NnLzHWSH3JkYUl+IUkqcofeIQNVjUGfpEAIi2Kd9nH:qsnLzHWy3JkJPofwV9Zes9H
TLSH T17284B799319326F6570E09304932B87E6A158DDD456FCA0A7AFEF801C7377F28F9250A
Reporter abuse_ch
Tags:exe STRRAT


Avatar
abuse_ch
STRRAT C2:
134.19.177.37:2022

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
134.19.177.37:2022 https://threatfox.abuse.ch/ioc/522156/

Intelligence


File Origin
# of uploads :
1
# of downloads :
296
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://skgroup.live/Statement_10619_from_eRev_Inc.zip
Verdict:
No threats detected
Analysis date:
2022-04-21 15:27:58 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
shell32.dll
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
Threat name:
ByteCode-JAVA.Trojan.StrRat
Status:
Malicious
First seen:
2022-04-21 15:17:47 UTC
File Type:
Binary (Archive)
Extracted files:
71
AV detection:
10 of 26 (38.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments