ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://str-master.pw/strigoi/server/ping.php?lid=khonsari.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-08-11 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 388263 |
|---|---|
| IOC: | http://str-master.pw/strigoi/server/ping.php?lid=khonsari |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | STRRAT |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS60781 LEASEWEB-NL-AMS-01 |
| Country: | NL |
| First seen: | 2022-02-16 19:16:10 UTC |
| Last seen: | never |
| UUID: | e6406165-8f5c-11ec-a022-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | STRRAT |
| Reference: | https://tria.ge/220216-wyr1wsdcdn |
AndreGironda
MITRE T1566.002Date: Wed, 16 Feb 2022 09:00-09:30 +0100
Received: from vm344867.pq.hosting (74.119.195.218)
Message-Id: <202202160817.21G8HPlA022596@vm344867.pq.hosting>
Mime-Version: 1.0
From: "voicesmail@<victimorg>" <ooamen@(victim org)>
ReplyTo:
Subject: You have a " <victim org> New voicemail <victim email>
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: base64
Return-Path: root@vm344867.pq.hosting
Message Body URL: hXXps://filebin[.]net/b7su770qo3eu5m6w/finanace_document.zip
Zipfile Plant Name: finanace_document.zip
Zipfile SHA256: b895d007385f7bb72cff329b6db972bc5bdcfc44e04228cb93a4cc986b13bda6
Unzipped JScript Dropper Name: finanace_document.js
JScript SHA256: ff09ee281033a47f148aab892fd3edefcf4b03f3f1e4b47b0d0e35df3e3ac7ce
JAR Name: invoice.jar
JAR SHA256: 73ef11d27180fe100ad22506de948238c359ebef0286b79e3be84ac00a4878b3
DLL Name: jna5567029690384875018.dll
DLL SHA256: a66959bec2ef5af730198db9f3b3f7cab0d4ae70ce01bec02bf1d738e6d1ee7a
NL