MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc10c4878f464167ae729dc5d788abc00f362ce91f64d12aa4e0981e109e7c48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 5


Intelligence 5 IOCs 1 YARA File information Comments

SHA256 hash: cc10c4878f464167ae729dc5d788abc00f362ce91f64d12aa4e0981e109e7c48
SHA3-384 hash: 63eaadc3c06f21213682e10f453036da93fa55c1d58afca313a153b45a6af0f9100c0bd14a4868995cfa965ec8f32ecd
SHA1 hash: 1f6716a8b5d203f81ecbbc9466dd29fee0ae055d
MD5 hash: ef41f3d4f25f9013839f6498089c43b0
humanhash: kentucky-pizza-london-leopard
File name:INQ7654323.jar
Download: download sample
Signature STRRAT
File size:188'623 bytes
First seen:2021-10-05 07:46:40 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:UfI+iyRXqhHVXzaNzCNWgzLhUfH5R3l+oyHYO6ArDzCXsNAQ9T7dlHvU:kI+HR6h1jNWgHIHjl+pXzd9/dlHs
TLSH T11B04015FBD8BC1E5F0AB4972C1679E33D61C619AC116556FA3FC68060CB9C6C4A03ACB
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
212.193.30.110:4292

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
212.193.30.110:4292 https://threatfox.abuse.ch/ioc/230451/

Intelligence


File Origin
# of uploads :
1
# of downloads :
233
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
INQ7654323.jar
Verdict:
No threats detected
Analysis date:
2021-10-05 07:49:23 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
evad.troj
Score:
68 / 100
Signature
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 496980 Sample: INQ7654323.jar Startdate: 05/10/2021 Architecture: WINDOWS Score: 68 28 Found malware configuration 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected STRRAT 2->32 34 Yara detected AllatoriJARObfuscator 2->34 8 cmd.exe 2 2->8         started        10 cmd.exe 1 2->10         started        process3 process4 12 java.exe 5 8->12         started        16 conhost.exe 8->16         started        18 7za.exe 70 10->18         started        dnsIp5 26 192.168.2.1 unknown unknown 12->26 24 C:\cmdlinestart.log, ASCII 12->24 dropped 20 icacls.exe 1 12->20         started        file6 process7 process8 22 conhost.exe 20->22         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2021-10-05 07:47:05 UTC
AV detection:
12 of 45 (26.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments