General

  • Target

    e8ee8e0e3be3c2819b17d2e2964c3b3427f1b9ca343de15188c029196df8e567.jar

  • Size

    448KB

  • Sample

    240613-cjt26a1ang

  • MD5

    633bdb02e821ed7d851d56782fd146b4

  • SHA1

    698ca6a9a04301a0ec8e2e5299a2a6f3a2a3db83

  • SHA256

    e8ee8e0e3be3c2819b17d2e2964c3b3427f1b9ca343de15188c029196df8e567

  • SHA512

    21e0faca206c59ae8e2f9ff6504846e677769a4190ab6a291a4b73499d50e83ce9c23cb24cd16ef918778d459116110c7722301f4b4a7b54cca64eb9dc85fd0b

  • SSDEEP

    12288:kO5jgT2yjEu28CabWuJq2rUlqXGvw+J4V:2Sy4u28CaZJDrMqXWJg

Malware Config

Targets

    • Target

      e8ee8e0e3be3c2819b17d2e2964c3b3427f1b9ca343de15188c029196df8e567.jar

    • Size

      448KB

    • MD5

      633bdb02e821ed7d851d56782fd146b4

    • SHA1

      698ca6a9a04301a0ec8e2e5299a2a6f3a2a3db83

    • SHA256

      e8ee8e0e3be3c2819b17d2e2964c3b3427f1b9ca343de15188c029196df8e567

    • SHA512

      21e0faca206c59ae8e2f9ff6504846e677769a4190ab6a291a4b73499d50e83ce9c23cb24cd16ef918778d459116110c7722301f4b4a7b54cca64eb9dc85fd0b

    • SSDEEP

      12288:kO5jgT2yjEu28CabWuJq2rUlqXGvw+J4V:2Sy4u28CaZJDrMqXWJg

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks