Enhancement idea
Description
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. The RAT has a focus on stealing credentials of browsers and email clients, and passwords via keylogging. It supports the following browsers and email clients: Firefox, Internet Explorer, Chrome, Foxmail, Outlook, Thunderbird.
Since Version 1.2 and above, STRRAT was infamous for its ransomware-like behavior of appending the file name extension .crimson to files. Version 1.5 is notably more obfuscated and modular than previous versions, but the backdoor functions mostly remain the same: collect browser passwords, run remote commands and PowerShell, log keystrokes, among others. Version 1.5 of STRRAT Malware includes a proper encryption routine, though currently pretty simple to revert.
Links
https://threatfox.abuse.ch/browse/malware/jar.strrat/
IOC
URL's
fileshaaringdocumseign.pages.dev
idgerowner.duckdns.org
streelifes.duckdns.org
Domains
ddns.net
dns.army
dynamic-dns.net
jetos.com
shivfurnishings.com
str-master.pw
ydns.eu
IP's
2.59.254.145
5.206.224.194
15.235.10.108
23.29.115.152
23.81.246.239
23.105.131.181
23.105.131.243
23.108.57.10
23.146.242.147
23.227.196.162
23.227.196.195
23.229.34.104
31.210.20.37
31.210.20.38
31.210.20.96
31.210.20.160
31.210.20.164
31.210.20.226
31.210.21.99
37.0.8.76
37.0.8.217
37.0.11.154
37.0.11.241
37.0.14.195
37.0.14.205
37.120.141.147
37.120.206.74
37.120.247.13
37.139.129.115
37.221.114.90
45.9.168.40
45.12.253.130
45.61.168.73
45.66.230.68
45.66.230.138
45.87.61.211
45.88.67.63
45.88.67.229
45.95.169.160
45.133.1.47
45.133.1.72
45.133.174.157
45.137.22.62
45.137.22.89
45.137.22.108
45.137.22.131
45.137.22.141
45.137.22.150
45.137.22.170
45.137.22.251
45.138.16.101
45.139.105.174
45.144.225.151
45.144.225.159
45.144.225.174
45.144.225.236
45.153.243.121
51.161.197.23
51.255.83.207
54.39.43.116
54.218.207.65
62.102.148.154
62.197.136.74
62.197.136.159
64.188.13.141
79.110.49.9
79.110.49.161
79.124.8.16
79.134.225.17
79.134.225.22
79.134.225.25
79.134.225.26
79.134.225.31
79.134.225.42
79.134.225.43
79.134.225.52
79.134.225.70
79.134.225.71
79.134.225.76
79.134.225.100
79.134.225.104
80.76.51.117
80.85.153.166
81.161.229.226
83.137.157.228
84.38.132.108
84.54.50.69
84.54.50.148
85.31.46.220
85.209.135.243
85.217.144.229
87.98.245.48
91.192.100.27
91.192.100.28
91.192.100.42
91.192.100.49
91.193.75.131
91.193.75.134
91.193.75.135
91.193.75.168
91.193.75.197
94.198.40.34
95.168.174.51
95.214.27.111
95.214.27.146
96.47.233.13
103.47.144.14
103.47.144.50
103.47.144.68
103.125.189.187
103.133.104.124
103.133.105.29
103.133.108.219
103.133.109.176
103.133.110.221
103.133.111.176
103.151.123.132
103.156.90.52
103.156.91.56
103.169.35.120
103.207.36.177
103.212.81.154
103.212.81.155
103.212.81.157
103.212.81.158
103.212.81.160
103.232.55.27
104.161.42.236
104.168.47.105
104.171.113.195
104.236.223.230
105.109.211.84
105.110.181.161
109.206.242.32
109.206.243.106
134.19.177.37
134.19.177.46
134.19.177.60
135.148.89.246
136.243.214.49
139.180.178.254
141.98.6.36
141.98.6.246
141.98.6.252
141.101.134.47
144.168.231.6
147.124.212.162
156.96.60.167
156.96.62.59
158.69.53.93
163.123.143.119
167.99.118.70
172.93.163.149
172.93.181.199
172.93.193.117
172.93.201.199
172.93.220.135
172.94.88.126
172.98.202.98
172.111.141.64
172.111.141.114
172.245.163.161
185.19.85.176
185.29.8.13
185.29.8.57
185.29.8.111
185.29.8.112
185.38.142.241
185.91.69.172
185.102.170.72
185.130.104.144
185.140.53.4
185.140.53.68
185.140.53.131
185.140.53.188
185.140.53.196
185.140.53.207
185.140.53.238
185.157.162.75
185.174.101.254
185.203.119.28
185.205.210.108
185.206.145.122
185.222.57.85
185.222.57.218
185.222.57.237
185.222.58.58
185.222.58.68
185.222.58.84
185.222.58.106
185.222.58.124
185.222.58.147
185.222.58.242
185.222.58.245
185.236.231.195
185.244.25.227
185.244.30.11
185.244.30.213
185.246.220.173
185.246.221.12
185.252.179.108
185.254.37.71
185.254.37.72
192.3.24.181
192.169.6.4
192.188.88.234
192.236.193.63
193.42.32.210
193.42.32.233
193.42.33.11
193.142.146.203
193.218.118.85
194.5.97.4
194.5.97.18
194.5.97.87
194.5.98.8
194.5.98.38
194.5.98.45
194.5.98.117
194.5.98.239
194.5.98.243
194.26.192.231
194.31.98.38
194.33.45.132
194.37.97.161
194.55.224.148
194.85.248.87
194.85.248.228
194.85.248.253
194.87.151.97
194.87.151.236
194.147.140.211
194.147.140.223
194.147.140.252
194.180.49.225
198.12.81.63
198.27.77.242
202.55.135.127
204.44.127.151
209.127.180.215
212.192.241.175
212.192.241.242
212.192.246.32
212.192.246.56
212.192.246.69
212.192.246.124
212.192.246.127
212.192.246.143
212.192.246.178
212.193.30.54
212.193.30.110
212.193.30.181
212.193.30.230
217.64.149.171