MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca0c5787943929cb6e8efb4403d58a9524b3afcb1bc0da075f8da333beab58bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: ca0c5787943929cb6e8efb4403d58a9524b3afcb1bc0da075f8da333beab58bc
SHA3-384 hash: b2f9554a9296750266f3b5735c831a090775d591d7027467608d10d5514e6b5f49022678d69fa9a93fd79511dee97374
SHA1 hash: 586fbbe556125735dfa8cb1fac794f71763a8c01
MD5 hash: 86e3c52136afea5be1ccd503f0aac5a5
humanhash: happy-music-william-princess
File name:Annexure A-61322.jar
Download: download sample
Signature STRRAT
File size:129'263 bytes
First seen:2021-05-03 02:35:57 UTC
Last seen:2021-05-03 03:00:46 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 3072:WsEHr6qhNIkJxM3U5li7xNaYoWc9Rz/TyIFeA1et7vRCU3V+:IdvM3ymN07xFJet7vHF+
TLSH EAC31234AC009779BCC489722BC065D0E48A7F6B9F7B17F2129D913E369292DC67E063
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
31.210.21.99:2090

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
31.210.21.99:2090 https://threatfox.abuse.ch/ioc/28091/

Intelligence


File Origin
# of uploads :
2
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
May check the online IP address of the machine
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Get antivirus details via WMIC query
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 402377 Sample: Annexure A-61322.jar Startdate: 03/05/2021 Architecture: WINDOWS Score: 100 92 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->92 94 Found malware configuration 2->94 96 Multi AV Scanner detection for submitted file 2->96 98 6 other signatures 2->98 12 cmd.exe 2 2->12         started        15 notepad.exe 2->15         started        17 notepad.exe 2->17         started        19 2 other processes 2->19 process3 signatures4 102 Uses schtasks.exe or at.exe to add and modify task schedules 12->102 21 java.exe 6 12->21         started        23 conhost.exe 12->23         started        process5 process6 25 wscript.exe 2 21->25         started        27 icacls.exe 1 21->27         started        process7 29 javaw.exe 26 25->29         started        32 conhost.exe 27->32         started        dnsIp8 86 github.com 140.82.121.4, 443, 49744 GITHUBUS United States 29->86 88 github-releases.githubusercontent.com 185.199.108.154, 443, 49748 FASTLYUS Netherlands 29->88 90 3 other IPs or domains 29->90 34 java.exe 2 21 29->34         started        process9 file10 74 C:\Users\user\AppData\...\ycwkqyvyoy.txt, Zip 34->74 dropped 76 C:\Users\user\...\jna3576377763461986213.dll, PE32 34->76 dropped 37 java.exe 14 34->37         started        41 cmd.exe 1 34->41         started        43 conhost.exe 34->43         started        process11 dnsIp12 80 rolex.sytes.net 31.210.21.99, 2090, 49757 PLUSSERVER-ASN1DE Netherlands 37->80 82 ip-api.com 208.95.112.1, 49759, 80 TUT-ASUS United States 37->82 84 str-master.pw 37->84 78 C:\Users\user\...\jna5817856063126231974.dll, PE32 37->78 dropped 45 cmd.exe 37->45         started        47 cmd.exe 37->47         started        49 cmd.exe 37->49         started        55 2 other processes 37->55 51 conhost.exe 41->51         started        53 schtasks.exe 41->53         started        file13 process14 process15 57 WMIC.exe 45->57         started        60 conhost.exe 45->60         started        62 conhost.exe 47->62         started        64 WMIC.exe 47->64         started        66 conhost.exe 49->66         started        68 WMIC.exe 49->68         started        70 conhost.exe 55->70         started        72 WMIC.exe 55->72         started        signatures16 100 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 57->100
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2021-05-03 02:29:02 UTC
AV detection:
5 of 47 (10.64%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments