MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cbaa31d4f7ff28a87e5d22237e7c46ed5daf49f4d288349fdaf0275a99fd1fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0cbaa31d4f7ff28a87e5d22237e7c46ed5daf49f4d288349fdaf0275a99fd1fc
SHA3-384 hash: 340291321f58d4cb3f2ef3168cfd7ea82a4d82f996842cc90022e72c56681c3408182eda66a912af1f2ccf23ad594144
SHA1 hash: eb5d123be3ae5ecfbc00585eeeba362417057d45
MD5 hash: 173e9f2b16daac20c7bc3df7c5276c4a
humanhash: equal-uranus-snake-emma
File name:173e9f2b16daac20c7bc3df7c5276c4a
Download: download sample
Signature njrat
File size:103'936 bytes
First seen:2020-11-17 11:28:19 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'936 x AgentTesla, 19'831 x Formbook, 12'310 x SnakeKeylogger)
ssdeep 1536:ckuArVGlych1un/PMTDSvp5TnXiZZcFUBj91vijdXR6RG+9UBeRyGweBs:xeh0/k/Svp5rXibwB6wZfh
Threatray 434 similar samples on MalwareBazaar
TLSH 1DA39C291BBF0226F3797A38DD903162D619F5D75332A4CFA371DBC78E935928980278
Reporter seifreed
Tags:NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Creating a process with a hidden window
Connection attempt
Unauthorized injection to a recently created process
Launching the process to change the firewall settings
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-11-08 02:39:00 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:njrat evasion persistence trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Modifies service
Executes dropped EXE
Modifies Windows Firewall
njRAT/Bladabindi
Unpacked files
SH256 hash:
0cbaa31d4f7ff28a87e5d22237e7c46ed5daf49f4d288349fdaf0275a99fd1fc
MD5 hash:
173e9f2b16daac20c7bc3df7c5276c4a
SHA1 hash:
eb5d123be3ae5ecfbc00585eeeba362417057d45
SH256 hash:
3af8ad5290760229256dac9e9a220d5040555a0a52354c9ad260eda9f2f351b2
MD5 hash:
09931dd6aab91c679418326dca19bf14
SHA1 hash:
f2250462c776a8ffc48a0286883c97fcd8bffa11
Detections:
win_njrat_w1 win_njrat_g1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments