MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc50cd702c7bb3811aa49a445e4fe6057d2e71f2c19f27fe897386bbf6ec7c11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



STRRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: fc50cd702c7bb3811aa49a445e4fe6057d2e71f2c19f27fe897386bbf6ec7c11
SHA3-384 hash: 8a0abc1d2eecd1ca1be15333645b3107cf5b5396b91c5eb7531268709a0d3e72d3f5680d3c3cbf5d541fca651775dcba
SHA1 hash: a23a15e81070e313a5ac7cde682fe7c3eeb0c2f8
MD5 hash: 30bb7390115b12a186b7669772988121
humanhash: lactose-montana-grey-pizza
File name:NETBANCO TRANSFER 3307281 EUR .jar
Download: download sample
Signature STRRAT
File size:457'417 bytes
First seen:2023-08-09 00:55:45 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 12288:WvJ9RM4TS3hHJDyxieR5pjWaWWXsKwKuClvfRoQtK:WvJohpesecWcKw2lvftK
TLSH T1BDA413893855EAB5F0A7A5735C5256B6595D43ACC28FB01B22FE2A020E30DED5B03DCF
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:jar STRRAT


Avatar
abuse_ch
STRRAT C2:
80.85.153.166:6565

Intelligence


File Origin
# of uploads :
1
# of downloads :
168
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
NETBANCO TRANSFER 3307281 EUR .jar
Verdict:
Malicious activity
Analysis date:
2023-08-09 00:56:10 UTC
Tags:
rat strrat evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Threat name:
Detection:
malicious
Classification:
troj.expl
Score:
68 / 100
Signature
Exploit detected, runtime environment starts unknown processes
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected STRRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1288178 Sample: NETBANCO_TRANSFER_3307281_E... Startdate: 09/08/2023 Architecture: WINDOWS Score: 68 19 Found malware configuration 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Yara detected STRRAT 2->23 25 Exploit detected, runtime environment starts unknown processes 2->25 7 java.exe 5 2->7         started        9 7za.exe 77 2->9         started        process3 process4 11 icacls.exe 1 7->11         started        13 conhost.exe 7->13         started        15 conhost.exe 9->15         started        process5 17 conhost.exe 11->17         started       
Threat name:
ByteCode-JAVA.Downloader.BanLoad
Status:
Malicious
First seen:
2023-08-08 23:36:02 UTC
File Type:
Binary (Archive)
Extracted files:
70
AV detection:
6 of 38 (15.79%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments