MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1f9c3312a5a439c2b0b65c8df1944c7983d87be9be11aad64fdd64a763dc96b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 7


Intelligence 7 IOCs 1 YARA File information Comments

SHA256 hash: f1f9c3312a5a439c2b0b65c8df1944c7983d87be9be11aad64fdd64a763dc96b
SHA3-384 hash: ff65f3b36c5159f9a9f783eb013f455e1726c7870775285b967fba6c9c173e4a408f301669252d069717f2cba3104b32
SHA1 hash: cb4335dfbcc941a540beabbfe2d50de9d8d3e9a8
MD5 hash: 6e21bd2e962c389a02846fa9ed7896e4
humanhash: golf-six-fruit-vermont
File name:Product Inquiry LPO 20220928277352675.jar
Download: download sample
Signature STRRAT
File size:224'765 bytes
First seen:2022-09-29 20:30:23 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 6144:JGqgolOB3C/9jMmkRZHAhvHSXp44C5Q0ru4:glNC/RMtKHSX64C5Qz4
TLSH T17E24F10EBDEAB4F4C79F78BA20458276E61C11C8E505A55B1AFC498E1CB5C2E1786CCF
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
85.31.46.220:8080

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
85.31.46.220:8080 https://threatfox.abuse.ch/ioc/858519/

Intelligence


File Origin
# of uploads :
1
# of downloads :
219
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
f1f9c3312a5a439c2b0b65c8df1944c7983d87be9be11aad64fdd64a763dc96b.zip
Verdict:
Malicious activity
Analysis date:
2022-09-30 10:15:05 UTC
Tags:
evasion trojan strrat rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 713013 Sample: Product Inquiry LPO 2022092... Startdate: 29/09/2022 Architecture: WINDOWS Score: 68 25 Malicious sample detected (through community Yara rule) 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Yara detected STRRAT 2->29 31 Yara detected AllatoriJARObfuscator 2->31 8 cmd.exe 2 2->8         started        process3 process4 10 java.exe 24 8->10         started        13 conhost.exe 8->13         started        dnsIp5 19 github.com 140.82.121.4, 443, 49705, 49710 GITHUBUS United States 10->19 21 sonatype.map.fastly.net 199.232.192.209, 443, 49703, 49704 FASTLYUS United States 10->21 23 2 other IPs or domains 10->23 15 icacls.exe 1 10->15         started        process6 process7 17 conhost.exe 15->17         started       
Threat name:
ByteCode-JAVA.Trojan.StrRat
Status:
Malicious
First seen:
2022-09-29 03:27:47 UTC
File Type:
Binary (Archive)
Extracted files:
77
AV detection:
10 of 26 (38.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Drops file in Program Files directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments