MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca7072bba9d1b75b02b5d2887fdb7bcb1f86050b669ffd99a7e756e1a60095f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: ca7072bba9d1b75b02b5d2887fdb7bcb1f86050b669ffd99a7e756e1a60095f2
SHA3-384 hash: 34ab4fa4922d883ae862028a4e1e561665509e28a8a15484a5f80f2be7e8965aa074538208a1767006822fc1f71fb780
SHA1 hash: 5136271deac72742c6c95148db042f3e15d8101d
MD5 hash: db9cc0db01ec3ab20a2693d957f495b8
humanhash: uniform-wolfram-artist-early
File name:invoice.jar
Download: download sample
Signature STRRAT
File size:100'944 bytes
First seen:2021-09-18 11:55:45 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:Hg7Sy7P9iOugvON1QeEQBtyu85EMieGq8uaV:AOysh7fEQvycZe1VU
TLSH T141A3D02FAE9A95B8D10B44334A8AC333970C9A89D404912F7AFC5D455C75CEC176AACF
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
103.133.111.176:4292

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
103.133.111.176:4292 https://threatfox.abuse.ch/ioc/223322/

Intelligence


File Origin
# of uploads :
1
# of downloads :
202
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
invoice.jar
Verdict:
Malicious activity
Analysis date:
2021-09-18 11:56:41 UTC
Tags:
evasion trojan strrat rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 485615 Sample: invoice.jar Startdate: 18/09/2021 Architecture: WINDOWS Score: 60 23 sonatype.map.fastly.net 2->23 25 repo1.maven.org 2->25 27 github.com 2->27 35 Multi AV Scanner detection for submitted file 2->35 37 Yara detected STRRAT 2->37 39 Yara detected AllatoriJARObfuscator 2->39 9 cmd.exe 2 2->9         started        signatures3 process4 process5 11 java.exe 24 9->11         started        15 conhost.exe 9->15         started        dnsIp6 29 140.82.121.3, 443, 49770, 49774 GITHUBUS United States 11->29 31 github.com 140.82.121.4, 443, 49739, 49744 GITHUBUS United States 11->31 33 3 other IPs or domains 11->33 21 C:\cmdlinestart.log, ASCII 11->21 dropped 17 icacls.exe 1 11->17         started        file7 process8 process9 19 conhost.exe 17->19         started       
Threat name:
ByteCode-JAVA.Trojan.StrRat
Status:
Malicious
First seen:
2021-09-18 11:56:07 UTC
AV detection:
14 of 27 (51.85%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments