General

  • Target

    97c277a6f9429d969d7948cf9fdf988007f4fe1a5e8743705b7fcafe8536ecdc.jar

  • Size

    559KB

  • Sample

    240616-bprzbatbnc

  • MD5

    b6f33efff9ad6941fb30ff5dce9fb17b

  • SHA1

    17c7c76eb4776fcb392ba10c58f9730bb0a54d55

  • SHA256

    97c277a6f9429d969d7948cf9fdf988007f4fe1a5e8743705b7fcafe8536ecdc

  • SHA512

    f1baa8035dfdc658ee8ddef584013e779bd2dcc62e646c2e8134bc7f2f65ff37cbb76251ff6ce88c4ea20218426c089e220d06bd86422a4c30c8b2d2133b86f2

  • SSDEEP

    6144:eLLL2vF5P41bafpEuFHMnpt5c/bIoOiYL3EEBLJX3XXqtNujcdu6Qmn4/lk4d/jP:qyvrSafyZnZc/UnBLJm8jcduAOl0m

Malware Config

Targets

    • Target

      97c277a6f9429d969d7948cf9fdf988007f4fe1a5e8743705b7fcafe8536ecdc.jar

    • Size

      559KB

    • MD5

      b6f33efff9ad6941fb30ff5dce9fb17b

    • SHA1

      17c7c76eb4776fcb392ba10c58f9730bb0a54d55

    • SHA256

      97c277a6f9429d969d7948cf9fdf988007f4fe1a5e8743705b7fcafe8536ecdc

    • SHA512

      f1baa8035dfdc658ee8ddef584013e779bd2dcc62e646c2e8134bc7f2f65ff37cbb76251ff6ce88c4ea20218426c089e220d06bd86422a4c30c8b2d2133b86f2

    • SSDEEP

      6144:eLLL2vF5P41bafpEuFHMnpt5c/bIoOiYL3EEBLJX3XXqtNujcdu6Qmn4/lk4d/jP:qyvrSafyZnZc/UnBLJm8jcduAOl0m

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks