s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.strrat

📛 Threat Title

Malware family: STRRAT

Category: STRRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.strrat`. Printable name: STRRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.strrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.strrat

IOC database

Type
domain
Value
jar.strrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.strrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.strrat

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    EXECUTIVE SUMMARY The Bloody Wolf threat actor group has been observed launching a phishing campaign targeting organizations in Kazakhstan. This campaign utilizes STRRAT , a commercial malware also known as Strigoi Master. The attackers send phishing emails impersonating the country's regulatory agencies, with malicious PDF attachments that contain links to download the malware and a Java ...

  • web:any.run

    STRRAT is a type of malicious software known as a remote access trojan (RAT). It gives attackers the ability to gain full control over a victim's computer system, enabling them to steal confidential information, spy on their activities, and drop other malware . STRRAT has been in operation since 2020 and is regularly updated to increase its complexity and make it more difficult to detect.

  • web:daniyyell.com

    A comprehensive analysis of the JavaScript obfuscation techniques utilised by STRRAT malware to evade detection. Both static and dynamic analysis methods are employed, along with the development of YARA rules to improve future detection and support broader threat-hunting activities.

  • web:malpedia.caad.fkie.fraunhofer.de

    STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. The RAT has a focus on stealing credentials of browsers and email clients, and passwords via keylogging.

  • web:rewterz.com

    STRRAT Malware - Active IOCs Severity High Analysis Summary STRRat is a Java-based Remote-Access Trojan (RAT) with a slew of malicious features, notably information theft and backdoor capabilities. This RAT was first identified at the German cybersecurity firm in June 2020. This malware uses plugins to grant the attacker remote access.

  • web:securityscorecard.com

    Executive summary STRRAT is a Java-based malware that executes multiple commands transmitted by the C2 server. The JAR file was obfuscated using the Allatori obfuscator. It establishes persistence on the host by copying to the Startup folder and creating a scheduled task and a Run registry entry. The functionalities of the implemented commands include: reboot the machine, uninstall the malware ...

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.hivepro.com

    #1 STRRAT , a sophisticated Remote Access Trojan with a history tracing back to at least mid-2020, exhibits a unique trait by being Java-based. Its delivery method involves the exploitation of spam emails, meticulously crafted to appear as originating from technology companies. Within these emails, an attached PDF file, cleverly masked as an invoice, plays a pivotal role.

  • web:www.microsoft.com

    StrRAT is a multi-functional Java-based remote access tool (RAT) that is known for its data stealing capabilities and fake ransomware-like behavior. Attackers distribute StrRAT malware through malicious email campaigns. This RAT can steal browser credentials, log keystrokes and take remote control of infected systems.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.