MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc75bd30c623f080ee5dd003c2802a9c97a008f9fd6f4a1c4113a27b1242d290. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 8


Intelligence 8 IOCs 1 YARA 1 File information Comments

SHA256 hash: cc75bd30c623f080ee5dd003c2802a9c97a008f9fd6f4a1c4113a27b1242d290
SHA3-384 hash: 2630e2fb75752f2df5eaa11e74ff8ebc311ff771040765c9675897f4a59e406a93b7da4927546bb1ea94c375ef2ae708
SHA1 hash: 3724e7c56529257d9c6cf04b3bb4aae9d39e9421
MD5 hash: 3ed7d5a22f675b05f3c467a11b39a931
humanhash: october-mountain-alanine-network
File name:Scan_doc:ORDER #PO996574620775800000.pdf(104).jar
Download: download sample
Signature STRRAT
File size:106'324 bytes
First seen:2026-07-21 05:54:00 UTC
Last seen:Never
File type:Java file jar
MIME type:application/java-archive
ssdeep 3072:7nNSclyDWRe0ipfRLuYZdlHufRXAfuEC7lbpFI:7nNRyS00UR+JXGTC7lbpm
TLSH T1CAA30287ABFB1179E54E453AC1A2CFE46D63887AC8B857031B0616DD0C4EDED5220DBB
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter abuse_ch
Tags:jar RAT STRRAT

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
141.11.243.110:586 https://threatfox.abuse.ch/ioc/1854750/

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
jar
First seen:
2026-07-20T22:13:00Z UTC
Last seen:
2026-07-22T02:39:00Z UTC
Hits:
~1000
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
80 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Unusual module load detection (module proxying)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1945632 Sample: Scan_doc_ORDER #PO996574620... Startdate: 21/07/2026 Architecture: WINDOWS Score: 80 25 Found malware configuration 2->25 27 Malicious sample detected (through community Yara rule) 2->27 29 Yara detected STRRAT 2->29 31 4 other signatures 2->31 8 cmd.exe 1 2->8         started        process3 process4 10 java.exe 4 8->10         started        12 conhost.exe 8->12         started        process5 14 java.exe 3 10->14         started        17 tasklist.exe 1 10->17         started        file6 23 stdout, ASCII 14->23 dropped 19 conhost.exe 14->19         started        21 conhost.exe 17->21         started        process7
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-21 05:55:55 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
1 of 36 (2.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat discovery execution persistence stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Executes a command shell one-liner
Enumerates processes with tasklist
Adds Run key to start application
Looks up external IP address via web service
Drops startup file
Loads dropped DLL
Family: STRRAT
Malware Config
C2 Extraction:
wqo9.firewall-gateway.de:586
code1.ydns.eu:586
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments