MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee060ddb962a0dd766cebce60df2f8e32eaa7e5f5d73a802834e39f3713b657d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: ee060ddb962a0dd766cebce60df2f8e32eaa7e5f5d73a802834e39f3713b657d
SHA3-384 hash: e682a244153648bca5e5a655114e9043336cd5a1e9020639535f207ff2277313c7358e20657584fa0ec92d822b0217fc
SHA1 hash: f6764ffe7e7f51bc54ccdd29b34b5c9dbe2c316f
MD5 hash: 0cfd92496ebae7f2ac809209f6eb6b25
humanhash: hamper-black-carolina-golf
File name:PURCHASEORDER002772-PDF.js
Download: download sample
Signature STRRAT
File size:1'387'377 bytes
First seen:2023-04-13 12:40:17 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:QQk4TcM1PbOhwJco13Wgxulc3oIvKatYN0V3/7KkkEpBa2g6DEyGBi5sLoAeWj5s:Tr
TLSH T1EB55F7C528E8590157A3F7A4D336E132AE79EA13189621D279C83F45EE77C503E7BA30
Reporter abuse_ch
Tags:js STRRAT


Avatar
abuse_ch
STRRAT C2:
45.9.168.40:7888

Intelligence


File Origin
# of uploads :
1
# of downloads :
308
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive obfuscated obfuscated
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
JScript performs obfuscated calls to suspicious functions
Uses regedit.exe to modify the Windows registry
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 846078 Sample: PURCHASEORDER002772-PDF.js Startdate: 13/04/2023 Architecture: WINDOWS Score: 52 27 sonatype.map.fastly.net 2->27 29 repo1.maven.org 2->29 8 wscript.exe 3 3 2->8         started        process3 file4 23 C:\Users\user\AppData\Roaming\aksplkqxy.txt, Zip 8->23 dropped 25 C:\Users\user\...\ebgeaegdbdecaedfebace.reg, ASCII 8->25 dropped 37 JScript performs obfuscated calls to suspicious functions 8->37 39 Uses regedit.exe to modify the Windows registry 8->39 12 javaw.exe 23 8->12         started        15 regedit.exe 8->15         started        17 regedit.exe 8->17         started        signatures5 process6 dnsIp7 31 140.82.121.3, 443, 50839, 50840 GITHUBUS United States 12->31 33 github.com 140.82.121.4, 443, 49683, 49687 GITHUBUS United States 12->33 35 3 other IPs or domains 12->35 19 icacls.exe 1 12->19         started        process8 process9 21 conhost.exe 19->21         started       
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2023-04-13 12:41:07 UTC
File Type:
Text (JavaScript)
AV detection:
1 of 37 (2.70%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:strrat persistence stealer trojan
Behaviour
Creates scheduled task(s)
Modifies registry class
Runs .reg file with regedit
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Loads dropped DLL
STRRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_Base64_Encoded_Hex_Encoded_Code
Author:Florian Roth (Nextron Systems)
Description:Detects hex encoded code that has been base64 encoded
Reference:https://www.nextron-systems.com/2019/04/29/spotlight-threat-hunting-yara-rule-example/
Rule name:SUSP_Base64_Encoded_Hex_Encoded_Code_RID3420
Author:Florian Roth
Description:Detects hex encoded code that has been base64 encoded
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments