Resubmissions

11-06-2024 09:54

240611-lxjb9atbjj 10

11-06-2024 09:50

240611-ltxqgaselb 7

General

  • Target

    5595c1dc3d2e51a9aa52283e601b92abfd878a6ca694d548f0bda140d60d48cc.jar

  • Size

    481KB

  • Sample

    240611-lxjb9atbjj

  • MD5

    11dec5e1d8b13456cd7e0ccb966fe12c

  • SHA1

    0c5ea4abbafa47010d529b2736a54b09da4cad29

  • SHA256

    5595c1dc3d2e51a9aa52283e601b92abfd878a6ca694d548f0bda140d60d48cc

  • SHA512

    a397c58ea60d12a45b295d8a7e85f3d5973ce836c9df97f7b5194020e6043a62d74cf2d521d1ff2d523dc0d60b0eb1f648a08ccfc7bc83b4fa1b769528da638a

  • SSDEEP

    12288:SVlCHKeQSPE4dP/I5FsRb5h3pCy1tEARGuJKcc:SHCHlrnIYxo0Gu4

Malware Config

Targets

    • Target

      5595c1dc3d2e51a9aa52283e601b92abfd878a6ca694d548f0bda140d60d48cc.jar

    • Size

      481KB

    • MD5

      11dec5e1d8b13456cd7e0ccb966fe12c

    • SHA1

      0c5ea4abbafa47010d529b2736a54b09da4cad29

    • SHA256

      5595c1dc3d2e51a9aa52283e601b92abfd878a6ca694d548f0bda140d60d48cc

    • SHA512

      a397c58ea60d12a45b295d8a7e85f3d5973ce836c9df97f7b5194020e6043a62d74cf2d521d1ff2d523dc0d60b0eb1f648a08ccfc7bc83b4fa1b769528da638a

    • SSDEEP

      12288:SVlCHKeQSPE4dP/I5FsRb5h3pCy1tEARGuJKcc:SHCHlrnIYxo0Gu4

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks