General

  • Target

    bc9a2a405326685130143b230720469ff9e1a294157748f7ccae56faf5d15887.jar

  • Size

    481KB

  • Sample

    240601-ymactadc5z

  • MD5

    95280ff1d28b3af85b570f55b0d113b8

  • SHA1

    6232e80612b3680de897ac40ba18f3e3ac03e3ff

  • SHA256

    bc9a2a405326685130143b230720469ff9e1a294157748f7ccae56faf5d15887

  • SHA512

    4b9ba1bdd7603aee780de4a98d698ab786177d2acc5c13667181a7846f09f1953544a8e6e6373685fdbf5c3a31d11149f579773cd31bddb0291484c63c61d6b0

  • SSDEEP

    12288:S1lenKeQSPEkhDboZFIRb5hLpCG5JMUFyWJKct:SnenlfHo81EEyWZ

Malware Config

Targets

    • Target

      bc9a2a405326685130143b230720469ff9e1a294157748f7ccae56faf5d15887.jar

    • Size

      481KB

    • MD5

      95280ff1d28b3af85b570f55b0d113b8

    • SHA1

      6232e80612b3680de897ac40ba18f3e3ac03e3ff

    • SHA256

      bc9a2a405326685130143b230720469ff9e1a294157748f7ccae56faf5d15887

    • SHA512

      4b9ba1bdd7603aee780de4a98d698ab786177d2acc5c13667181a7846f09f1953544a8e6e6373685fdbf5c3a31d11149f579773cd31bddb0291484c63c61d6b0

    • SSDEEP

      12288:S1lenKeQSPEkhDboZFIRb5hLpCG5JMUFyWJKct:SnenlfHo81EEyWZ

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks