Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

STRRAT

90
Global rank
60 infographic chevron month
Month rank
39 infographic chevron week
Week rank
0
IOCs

STRRAT is a type of malicious software known as a remote access trojan (RAT). It gives attackers the ability to gain full control over a victim's computer system, enabling them to steal confidential information, spy on their activities, and drop other malware. STRRAT has been in operation since 2020 and is regularly updated to increase its complexity and make it more difficult to detect.

RAT
Type
Unknown
Origin
1 June, 2020
First seen
28 August, 2026
Last seen

How to analyze STRRAT with ANY.RUN

RAT
Type
Unknown
Origin
1 June, 2020
First seen
28 August, 2026
Last seen

IOCs

IP addresses
139.99.85.213
154.91.34.165
188.114.97.3
75.119.193.253
149.154.166.110
2.16.241.205
213.180.204.127
208.95.112.1
45.141.233.69
132.148.178.5
150.171.22.17
132.226.247.73
185.121.177.177
150.171.28.11
2.59.254.111
176.65.144.23
217.78.234.145
74.120.9.233
192.178.183.94
185.156.72.2
Hashes
82042ec4e11fffbf1b0b5e6721afce8ac960267b2061c1ca2b30ebc2e58f4d17
f91dbb7c64b4582f529c968c480d2dce1c8727390482f31e4355a27bb3d9b450
5e32f16d52a5577a937f2c8513ca35c9e6be351a7a0fbb74278407df504d86a5
0dda9a17d54e586598a6200db854be52654d3e9def07363cd1e837569af88974
0c5490ca2f6d61c2d410e7907be97b3bc36b3e4de614e1f5431278dbccad4c79
69cb93351b7b2b3c33fa6826be062c454924a34bae7dd812de27eb70767843f1
3935a289417a1f1584f163ae93bddac534a69f69af224dbd4a434300ced93382
a5c1700269d33046833d6165b026dbaf1305ad612a892dff4ba3fa6701744027
fb75d593076ef30f9ba4601a09bf5ea50bcf9c84f8dd0750d113429a71104a13
1091a5225a1cce78601515acec1f2d35976158852bb1a263d9b4ceb6506990f5
a7055562772c30feadf7fccf3f22da1acda82d995d536b7ff91cfef3551d9789
82eaf8e8bc7275aeaf5834f57b8cf4d53cbbe5d551a561bedd0de43ff3786708
d2ac55b4450b3d379ec28eddc138eeab49584c0c8a9328fb5158cd35bfa9e03f
96e670b631a8e0520dcbfd8067d75ef4b167df8dc3c4bb42d9e62023259adc51
dbcb1915cd4d696290d550b5c3169b9be00931df18c06b7dd157206220cab1f9
39e641a906d7f511496c49a711976117946bdfd05f8ddc6a8c495c32cb50c990
d4b23edc5e796b44c8f86e88445068bd5456ecd5d719f5b65138b682fe8a161f
fbb710d9e5dfd5037d2f5d382497c4cd36bd48d76889bc244457442e38da9d65
02546eb94be966d89abb363ff318fc1414a86a8de222654d9419d221687b8e11
ba1639606ec3b0f61526d08d8ec2efd83dc0d6327c385b80698e8898e9bf9550
Domains
reallyfreegeoip.org
www.dontlookhere.com
s3.timeweb.cloud
api.telegram.org
ip-api.com
dontlookhere.com
gstatic.com
www.bing.com
api.pcloud.com
config.edge.skype.com
mail.dhakahome.com
edge.microsoft.com
checkip.dyndns.org
google.com
cloud-api.yandex.net
login.live.com
iplogger.org
settings-win.data.microsoft.com
slscr.update.microsoft.com
grabify.link
URLs
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://ip-api.com/json/
http://checkip.dyndns.org/
http://ip-api.com/line/?fields=hosting
https://edge.microsoft.com/serviceexperimentation/v2/
https://config.edge.skype.com/config/v1/edge/109.0.1518.115?clientid=-626569875466424637&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=17&mngd=0&installdate=1604373552&edu=0&bphint=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-us&acceptformat=crx3&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d837%2526e%253d1
https://reallyfreegeoip.org/xml/85.203.47.38
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/28/2026%20/%205:37:26%20pm%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://dontlookhere.com/
http://www.dontlookhere.com/blog
http://dontlookhere.com/blog
https://dontlookhere.com/blog/
http://dontlookhere.com/blog/
https://api.telegram.org/bot7950066405:aae5kuvk04df6lzjfoe-yzt3f12hjhmziqg/senddocument?chat_id=-4703613545&caption=%20pc%20name:%20admin%20%7c%20/%20vip%20recovery%20%5c%0d%0a%0d%0apw%20%7c%20admin%20%7c%20vip%20recovery
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://gateway.discord.gg/?v=9&encording=json
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4136
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10033
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 12522
comments 0

What is STRRAT malware?

STRRAT is a Java-based malware that has been active since at least mid-2020. It is intended for a number of malicious purposes, including exfiltrating data from users’ browsers and email clients, keylogging, stealing files, as well as dropping additional malware. The creators of STRRAT are unknown, yet the continued evolution of the malware suggests that the developers behind it are constantly working to improve its capabilities.

The use of Java, a language that has largely lost its popularity over the past decade, does not prevent STRRAT from infecting numerous machines across the globe every year. Although the early versions of the malware required the presence of Java Runtime Environment (JRE) on the victim’s computer, the newer ones can do without it. Instead, they scan the system and install the JRE software downloaded from one of the remote servers.

While STRRAT continues to be distributed using simple .jar files, there are also instances of weaponized .pdfs and .xlsbs. Some attackers also use the polyglot technique to spread the malware (CVE-2020-1464). Specifically, they can combine two file formats (e.g., .msi and .jar) to circumvent security systems. Such files are usually sent as attachments to emails disguised as legitimate documents, including receipts and invoices, as part of spam or phishing campaigns.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the STRRAT malicious software

Similar to other remote access trojans, such as XWorm and AsyncRAT, STRRAT enables criminals to engage in:

  • Remote control: The malware lets its operators access the PC of their victim, view the screen of the device, and even reboot it.
  • Data theft: It can be used to gather sensitive data, including passwords, credit card information, and browser history.
  • File management: The program has the capacity to extract files from different directories. It can also upload, delete, and open files.
  • Malware installation: STRRAT can drop other malicious software.
  • Webcam and microphone recording: The spying capabilities of the malware make it possible for attackers to record users’ conversations and take photos.
  • Keylogging: It can transmit all the keystrokes detected on the infected machine to its C2C server. Alternatively, it can record the information in an offline mode and transfer it once the connection is established again.

Additionally, it can act as a reverse proxy server for attackers, listen for incoming RDP connections, as well as execute cmd and PowerShell commands. The malware can download and install new updates from a remote server, allowing it to receive the latest features and capabilities, and to evade detection by antivirus software.

Another notable feature of STRRAT is its “crimson” module, which makes an attempt at encrypting victims’ files by adding the .crimson extension to them. Yet, by manually removing this extension, users can once again access their files. Basically, STRRAT poorly imitates the behavior of full-scale ransomware, such as WannaCry.

In terms of obfuscation, the latest version of the malware, namely the 1.6 one, employs two commercial obfuscators, Zelix KlassMaster (ZKM) and Allatori. One of the ways that STRRAT achieves persistence is by creating a scheduled task, masked under the name of a legitimate process such as "Skype.exe." In addition to creating a scheduled task, STRRAT also changes the autorun value and writes itself into the startup menu. This ensures that the malware will launch again after the operating system is rebooted.

STRRAT is capable of easily gaining elevated privileges on the system, which gives more power to the attacker. You can learn more about the techniques used by STRRAT by reading the article STRRAT: Malware Analysis of a JAR archive.

Execution process of STRRAT

To get a better understanding of the techniques used by the malware and collect its IOCs, STRRAT can be uploaded to the ANY.RUN interactive sandbox.

Upon execution, STRRAT drops DLL files onto the disk and initiates a persistent task that runs every 30 minutes via the task scheduler. This task spawns a new process that generates WMI queries for system information. The malware then starts a benign Windows application that serves as a launchpad for an embedded malicious payload, in this case, Formbook.

Read a detailed analysis of STRRAT in our blog.

STRRAT process tree STRRAT's process tree

Distribution methods of the STRRAT malware

Phishing email campaigns remain the go-to method for threat actors to launch attacks using STRRAT against victims. Such emails typically mimic the branding and logos of trusted organizations, making them appear legitimate.

For instance, one of the documented cases related to STRRAT involved a fake email from the MAERSK shipping company. By unknowingly downloading and opening files attached to these emails, victims can kick off a chain reaction resulting in attackers gaining full control over their computers.

Conclusion

The STRRAT malware has proven to be a persistent challenge over the past 3 years. Individual users and SMEs are the groups primarily targeted by threat actors who use this malware. This puts an emphasis on the importance of having a reliable and fast tool like ANY.RUN for scanning suspicious links and files. The service generates comprehensive reports on the behavior of any sample in seconds and provides a conclusive verdict on whether a certain file or URL is malicious or not.

Try ANY.RUN for free – request a demo!.

HAVE A LOOK AT

Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More