ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 45.133.1.72:3496.

Database Entry


IOC ID:226807
IOC: 45.133.1.72:3496
IOC Type :ip:port
Threat Type :botnet_cc
Malware: STRRAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS203320 TURIEN-AS
Country:- NL
First seen:2021-09-26 16:26:15 UTC
Last seen:never
UUID:78b2b613-1ee6-11ec-b078-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:STRRAT
Reference: https://bazaar.abuse.ch/sample/7bd8097de078f21e7f97dc04fac6ed6a4d7bc042934e2ec179706838303efe2f/

Avatar
AndreGironda
MITRE T1566.001
Date: 24 Sep 2021 12:32:51 +0200
Received: from canplast.com.tr (unknown [45.133.1.72])
From: "Eren Abasiyanik" <info@canplast.com.tr>
Subject: Quotation_Request
Message-ID: <20210924123251.FC57129170891FF0@canplast.com.tr>
Attachment Name: Quotation_Request.rar
Attachment Name: 7eb6ad23b9cc0bdbd29f186cf2515eca0ba76cb43f0241b63c1bcbc15801207f
Container zipfile Name: Quotation_Request.7z
Container zipfile SHA256: ebc60e5c4722122c5cb29dd49e2e58da60750d82a851bf6ffbd83392579178b1
JScript Dropper Name: Quotation_Request.js
JScript Dropper SHA256: c480fe7adba62a2d2f5b983c88358306ee204d94eedceae5f72e9c8c0c6e701a
Stage URL: hXXp://str-master[.]pw/strigoi/server/ping.php?lid=khonsari
JAR Stage Name: cejetjwve.txt
JAR Stage SHA256: 7bd8097de078f21e7f97dc04fac6ed6a4d7bc042934e2ec179706838303efe2f
STRRAT DLL SHA256: 04c9a8ab43d1eb616b84d0686c8ae1d881ef03fe4f3aa26511e5b19d35ef16af

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-09-30 03:11:35 d86762b56fd4a8a351a2f2be248000edf046f71dc721792c329e433991129e65