MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f76d4bd342ad31bed54e6e355dcc07272a7d13de4981ca50bce386963dfeea11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 11


Intelligence 11 IOCs 1 YARA 2 File information Comments

SHA256 hash: f76d4bd342ad31bed54e6e355dcc07272a7d13de4981ca50bce386963dfeea11
SHA3-384 hash: 433b1c33ca2543a3745b427cbdfd5aa91d5c605f4b444b4cbb2b530b452046e3c3c448a442560c961de3b6fdd80961ed
SHA1 hash: c4776cd4ae14929ee9221a658d667c2a0af21746
MD5 hash: de20192759fc85da6dd8b0bcb92469dc
humanhash: illinois-kilo-six-lemon
File name:PROFORMA.jar
Download: download sample
Signature STRRAT
File size:127'049 bytes
First seen:2025-07-24 07:35:05 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:+BRG0je/EJEiILIDXZYLMn1JF95+05T4MOE4Eb2b+6:2UF/ESi0SCLMnPXkzMOGb2
TLSH T1BEC312AF16C05A01CFAF30746937E03E95C1DACE4F672B9B03C54779B26E66612E7A04
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika unknown
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
107.158.145.206:5610

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
107.158.145.206:5610 https://threatfox.abuse.ch/ioc/1560260/

Intelligence


File Origin
# of uploads :
1
# of downloads :
276
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PROFORMA.jar
Verdict:
No threats detected
Analysis date:
2025-07-24 07:35:41 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
autorun emotet
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive obfuscated
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Suspicious Processes Spawned by Java.EXE
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected AllatoriJARObfuscator
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1743223 Sample: PROFORMA.jar Startdate: 24/07/2025 Architecture: WINDOWS Score: 100 82 jareyo.duckdns.org 2->82 84 str-master.pw 2->84 86 5 other IPs or domains 2->86 100 Suricata IDS alerts for network traffic 2->100 102 Found malware configuration 2->102 104 Malicious sample detected (through community Yara rule) 2->104 108 8 other signatures 2->108 13 cmd.exe 2 2->13         started        16 notepad.exe 2->16         started        18 notepad.exe 2->18         started        20 3 other processes 2->20 signatures3 106 Uses dynamic DNS services 82->106 process4 signatures5 114 Uses schtasks.exe or at.exe to add and modify task schedules 13->114 22 java.exe 4 13->22         started        25 conhost.exe 13->25         started        process6 file7 76 C:\Users\user\rtnqdlpqnz.js, ASCII 22->76 dropped 27 wscript.exe 1 2 22->27         started        process8 file9 80 C:\Users\user\AppData\Roaming\jgdzlajoi.txt, Zip 27->80 dropped 112 Windows Scripting host queries suspicious COM object (likely to drop second stage) 27->112 31 javaw.exe 22 27->31         started        signatures10 process11 dnsIp12 94 github.com 140.82.113.4, 443, 49719 GITHUBUS United States 31->94 96 release-assets.githubusercontent.com 185.199.108.133, 443, 49721 FASTLYUS Netherlands 31->96 98 dualstack.sonatype.map.fastly.net 199.232.192.209, 443, 49716, 49717 FASTLYUS United States 31->98 34 java.exe 1 17 31->34         started        process13 file14 74 C:\Users\user\...\jna1054581198620034106.dll, PE32 34->74 dropped 37 java.exe 10 34->37         started        41 cmd.exe 1 34->41         started        43 conhost.exe 34->43         started        process15 dnsIp16 88 jareyo.duckdns.org 107.158.145.206, 49727, 5610 EONIX-COMMUNICATIONS-ASBLOCK-62904US United States 37->88 90 ip-api.com 208.95.112.1, 49728, 80 TUT-ASUS United States 37->90 92 str-master.pw 5.79.71.205, 80 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 37->92 78 C:\Users\user\...\jna2498238599652084509.dll, PE32 37->78 dropped 45 cmd.exe 37->45         started        47 cmd.exe 37->47         started        49 cmd.exe 37->49         started        55 2 other processes 37->55 51 conhost.exe 41->51         started        53 schtasks.exe 41->53         started        file17 process18 process19 57 WMIC.exe 45->57         started        60 conhost.exe 45->60         started        62 conhost.exe 47->62         started        64 WMIC.exe 47->64         started        66 conhost.exe 49->66         started        68 WMIC.exe 49->68         started        70 conhost.exe 55->70         started        72 WMIC.exe 55->72         started        signatures20 110 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 57->110
Threat name:
Script-JS.Trojan.Acsogenixx
Status:
Malicious
First seen:
2025-07-24 07:35:24 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:adwind family:strrat execution persistence ransomware stealer trojan
Behaviour
Modifies registry class
Opens file in notepad (likely ransom note)
Scheduled Task/Job: Scheduled Task
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Drops startup file
Loads dropped DLL
STRRAT
Strrat family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_STRRAT_javascripts_Malware
Author:daniyyell
Description:Detects obfuscated JavaScript code indicative of STRRAT malware.
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments