General

  • Target

    swift2.jar

  • Size

    203KB

  • Sample

    240614-gj57ms1dnl

  • MD5

    6466b8b6db77557217549b21d857ba28

  • SHA1

    850b21f745803ca28cc4e4607e433452d1fade1e

  • SHA256

    01ed21113dc9ef0fc8db1ab49021286f47c7e75eb377f24c8c57dc9b25cfcc59

  • SHA512

    72a62ec8b536bdb9f5075b25166b7c1cb59cd5cf2f736e3bc28c98b57a3d86c8b2c666669e1a5309291e5551a9f758e252ba9b1cd3b99bbe49f37441d42e9230

  • SSDEEP

    3072:mV2ECg5sT5LQlZ9IkZI/fd3qr9w5wYJJk4ubY+pqtvQzvL0BoWrTy/mS:Qz65LG9bZbBw5wYJqN0dozvQSWrTnS

Malware Config

Targets

    • Target

      swift2.jar

    • Size

      203KB

    • MD5

      6466b8b6db77557217549b21d857ba28

    • SHA1

      850b21f745803ca28cc4e4607e433452d1fade1e

    • SHA256

      01ed21113dc9ef0fc8db1ab49021286f47c7e75eb377f24c8c57dc9b25cfcc59

    • SHA512

      72a62ec8b536bdb9f5075b25166b7c1cb59cd5cf2f736e3bc28c98b57a3d86c8b2c666669e1a5309291e5551a9f758e252ba9b1cd3b99bbe49f37441d42e9230

    • SSDEEP

      3072:mV2ECg5sT5LQlZ9IkZI/fd3qr9w5wYJJk4ubY+pqtvQzvL0BoWrTy/mS:Qz65LG9bZbBw5wYJqN0dozvQSWrTnS

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Accesses Microsoft Outlook profiles

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Collection

Email Collection

1
T1114

Tasks