MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f274a80cbba4d7bfbe30aca84dc7d8b3ec251cf4e44b6638c0746050ac4a762c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: f274a80cbba4d7bfbe30aca84dc7d8b3ec251cf4e44b6638c0746050ac4a762c
SHA3-384 hash: 79f51f2627251dfadde2b1bcfe9b2381231c27397538c8b221b325e018ae7f2f0b475326c5cd9c59e431e2a23cd66502
SHA1 hash: c8b565e4e31b635a7bb021334b577d21a77aee10
MD5 hash: ec090167e167d4a68b90c680a2d39a48
humanhash: golf-johnny-spaghetti-east
File name:Rechnung 0028.jar
Download: download sample
Signature STRRAT
File size:179'976 bytes
First seen:2021-09-28 19:52:59 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:V/TTBB69ofY4s3Q7RMuZinDGaxCEeUMuw0qCF7zP2GsTPpCf4:VL9APERMuZinrQEeUMuwGF7zPXsFCf4
TLSH T1230412E8E7E90D33AD564C4A38FB24BD2ABC4D1C0255969F19007C93AC3FFE8A711A45
Reporter neoxmorpheus1
Tags:jar jar. STRRAT

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
194.147.140.223:2525 https://threatfox.abuse.ch/ioc/227658/

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Rechnung 0028.jar
Verdict:
No threats detected
Analysis date:
2021-09-28 19:57:14 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
76 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 492196 Sample: Rechnung 0028.jar Startdate: 28/09/2021 Architecture: WINDOWS Score: 76 31 sonatype.map.fastly.net 2->31 33 repo1.maven.org 2->33 35 github.com 2->35 43 Multi AV Scanner detection for domain / URL 2->43 45 Multi AV Scanner detection for submitted file 2->45 47 Yara detected STRRAT 2->47 49 3 other signatures 2->49 9 cmd.exe 2 2->9         started        11 cmd.exe 1 2->11         started        signatures3 process4 process5 13 java.exe 6 9->13         started        16 conhost.exe 9->16         started        18 7za.exe 8 11->18         started        file6 29 C:\Users\user\kwnscafekc.js, ASCII 13->29 dropped 20 wscript.exe 2 13->20         started        22 icacls.exe 1 13->22         started        process7 process8 24 javaw.exe 21 20->24         started        27 conhost.exe 22->27         started        dnsIp9 37 140.82.121.3, 443, 49796, 49820 GITHUBUS United States 24->37 39 github.com 140.82.121.4, 443, 49765, 49768 GITHUBUS United States 24->39 41 3 other IPs or domains 24->41
Threat name:
ByteCode-JAVA.Trojan.AdWind
Status:
Malicious
First seen:
2021-09-28 19:53:11 UTC
AV detection:
13 of 45 (28.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments