General

  • Target

    0285e2e492a0054ea00d3790884448a8bf2ba890de6496ecaa9fa22af97100eb.jar

  • Size

    452KB

  • Sample

    240608-jrfm3abc28

  • MD5

    b07c339834a5d170e4d53d5047450a8d

  • SHA1

    de8e5013ce628b4d1d14e3f4b665ffbda1faea82

  • SHA256

    0285e2e492a0054ea00d3790884448a8bf2ba890de6496ecaa9fa22af97100eb

  • SHA512

    c455b22807f9d592db3d36ffdf808242df7c87537bdcee8516cd22196bc688b728ec827a56a8c05d072c20482819257c0d749d09a7a2e1aa67ba168bc499c5f9

  • SSDEEP

    12288:iU9rum+uhMaH/Ml0nZQZGrotf0wXfMhmQd3jEdkR:num+uaaf0YKKotfxXfMhmQdzWI

Malware Config

Targets

    • Target

      0285e2e492a0054ea00d3790884448a8bf2ba890de6496ecaa9fa22af97100eb.jar

    • Size

      452KB

    • MD5

      b07c339834a5d170e4d53d5047450a8d

    • SHA1

      de8e5013ce628b4d1d14e3f4b665ffbda1faea82

    • SHA256

      0285e2e492a0054ea00d3790884448a8bf2ba890de6496ecaa9fa22af97100eb

    • SHA512

      c455b22807f9d592db3d36ffdf808242df7c87537bdcee8516cd22196bc688b728ec827a56a8c05d072c20482819257c0d749d09a7a2e1aa67ba168bc499c5f9

    • SSDEEP

      12288:iU9rum+uhMaH/Ml0nZQZGrotf0wXfMhmQd3jEdkR:num+uaaf0YKKotfxXfMhmQdzWI

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks