MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 077a1514c1e8452cea89624a0f990a369fa2e654ce743b264fc9e3c85d7025e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 077a1514c1e8452cea89624a0f990a369fa2e654ce743b264fc9e3c85d7025e4
SHA3-384 hash: 4567e43d7c365668b1730a1f75d733505c72d9af798b5cfe960987f1b11a8466bbbdf7ec1e30868555c0ec395de25ca3
SHA1 hash: 98d9f9d6c7aa62fe93b8daf4d3c56745c78e3e9c
MD5 hash: f081e5c3033b083ba7d3c61d006c4fc1
humanhash: eighteen-triple-cola-failed
File name:KAErwLBR.exe
Download: download sample
Signature njrat
File size:32'768 bytes
First seen:2020-09-12 20:02:21 UTC
Last seen:2020-09-12 20:02:39 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'599 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 384:kCbP3tSX6vBq7lazgEO0EQKA23y5Q1Q0YtQWTItebrOFeqzCnMl:RS6vBqMzA0ZD23369rpMl
Threatray 28 similar samples on MalwareBazaar
TLSH D2E2194777B58115C2FD16F88DB3132046B2E3838532EB6F9CEC44DA8BA37E54251AE5
Reporter pmelson
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
176
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
DNS request
Connection attempt
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
72 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Contains functionality to log keystrokes (.Net Source)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-09-11 20:46:20 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of AdjustPrivilegeToken
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

Executable exe 077a1514c1e8452cea89624a0f990a369fa2e654ce743b264fc9e3c85d7025e4

(this sample)

Comments