MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d83a3bf8e89fc47260517535e8437ec7dc3fa111dcf711442b2d806f4e07160e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 6


Intelligence 6 IOCs 1 YARA File information Comments

SHA256 hash: d83a3bf8e89fc47260517535e8437ec7dc3fa111dcf711442b2d806f4e07160e
SHA3-384 hash: 4a78beb6cebcaa561fc49cb8a8b6f7c64e9bb4c6640043bf0202e600a6c5cb59e21fd3cc507b691ac7c2306cb1de620d
SHA1 hash: 75dcd390977db02b7e1120637900e280b9d81777
MD5 hash: 13ecea48c3c151408025d49c74b9cb5e
humanhash: timing-india-crazy-red
File name:Over payment Invoice# 82792.js
Download: download sample
Signature STRRAT
File size:5'937 bytes
First seen:2022-07-08 00:05:31 UTC
Last seen:2022-07-08 07:55:58 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 96:1dfdx407v1VCuXsTeyEql9DZBnpHllmCk0ajOBrCN3qj9uGt0gf50J0DeWIYVVDq:Xfdv71vX4EofloCmOVCcpLxE0DeWIYLu
TLSH T199C17EC89DD8111EA6EB0D101F1F6BCE70141F98540E6384CAADB4E2E995B499F03FBD
Reporter abuse_ch
Tags:js STRRAT


Avatar
abuse_ch
STRRAT C2:
62.197.136.159:2022

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
62.197.136.159:2022 https://threatfox.abuse.ch/ioc/815453/

Intelligence


File Origin
# of uploads :
2
# of downloads :
366
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive greyware obfuscated packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
96 / 100
Signature
Benign windows process drops PE files
Deletes itself after installation
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
System process connects to network (likely due to code injection or exploit)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 659344 Sample: Over payment Invoice# 82792.js Startdate: 08/07/2022 Architecture: WINDOWS Score: 96 68 Multi AV Scanner detection for domain / URL 2->68 70 Malicious sample detected (through community Yara rule) 2->70 72 Yara detected STRRAT 2->72 74 Yara detected AllatoriJARObfuscator 2->74 8 wscript.exe 3 17 2->8         started        13 msiexec.exe 97 25 2->13         started        process3 dnsIp4 60 storageapi.fleek.co 104.18.6.145 CLOUDFLARENETUS United States 8->60 62 files01.tchspt.com 173.244.209.108, 443, 49743 SOFTLAYERUS United States 8->62 36 C:\Users\user\...\jre-8u333-windows-x64.exe, PE32+ 8->36 dropped 38 C:\Users\...\jre-8u333-windows-x64[1].exe, PE32+ 8->38 dropped 76 System process connects to network (likely due to code injection or exploit) 8->76 78 Benign windows process drops PE files 8->78 80 JScript performs obfuscated calls to suspicious functions 8->80 82 Deletes itself after installation 8->82 15 jre-8u333-windows-x64.exe 11 8->15         started        18 javaw.exe 23 8->18         started        40 C:\Windows\Installer\MSIA60A.tmp, PE32+ 13->40 dropped 42 C:\Windows\Installer\MSI9251.tmp, PE32+ 13->42 dropped 44 C:\Windows\Installer\MSI65C2.tmp, PE32+ 13->44 dropped 46 C:\Program Files\Java\...\installer.exe, PE32+ 13->46 dropped 21 installer.exe 22 13->21         started        23 msiexec.exe 13->23         started        file5 signatures6 process7 dnsIp8 48 C:\Users\...\jre-8u333-windows-x64.exe (copy), PE32+ 15->48 dropped 50 C:\Users\user\AppData\...\jds4224531.tmp, PE32+ 15->50 dropped 25 jre-8u333-windows-x64.exe 3 44 15->25         started        54 140.82.121.3 GITHUBUS United States 18->54 56 github.com 140.82.121.4 GITHUBUS United States 18->56 58 3 other IPs or domains 18->58 28 icacls.exe 1 18->28         started        52 C:\ProgramData\Oracle\Java\...\bspatch.exe, PE32 21->52 dropped 30 bspatch.exe 1 21->30         started        file9 process10 dnsIp11 64 rps-svcs.oracle.com 25->64 66 javadl-esd-secure.oracle.com 25->66 32 conhost.exe 28->32         started        34 conhost.exe 30->34         started        process12
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2022-07-08 00:12:32 UTC
AV detection:
2 of 41 (4.88%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Behaviour
Checks processor information in registry
Modifies registry class
Modifies system certificate store
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in Windows directory
Enumerates connected drives
Checks computer location settings
Deletes itself
Loads dropped DLL
Blocklisted process makes network request
Downloads MZ/PE file
Executes dropped EXE
UPX packed file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments