🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2204548563caa92eefcd36786cecab2277722318571f3578dfbbb85ee51a9eb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 16


Intelligence 16 IOCs YARA 51 File information Comments

SHA256 hash: 2204548563caa92eefcd36786cecab2277722318571f3578dfbbb85ee51a9eb2
SHA3-384 hash: 493bd7cadba85acd1844c8987456c2bc8a3d12076d5195024d8ea35f1e1a3ac4f5c2a0e79fdedd69f18ef962e4f29137
SHA1 hash: 2894218a8362dbaae050d593c34edb1237bcb8c7
MD5 hash: 608c3702a7e8e99055c783566bd33191
humanhash: tango-ink-eight-fruit
File name:Wrotocol.exe
Download: download sample
Signature njrat
File size:21'228'872 bytes
First seen:2025-06-26 19:55:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 064967a99ade726316dc79a4a929fe96 (5 x QuasarRAT, 2 x PythonStealer, 1 x njrat)
ssdeep 393216:RFXGMm6st5qvZ9DfLc8ogfOmbFDw2XefsY8NVlyYdQdF3MnG38BLrhJ:RFX/m9TyfDfDv/bNXDY8lyYdQ73MGs
Threatray 432 similar samples on MalwareBazaar
TLSH T1BE2733A4FBC51EF9EC569239C04198189371B9B3A7B6C7330B90665B1B1B2843F2F758
TrID 48.7% (.EXE) Win64 Executable (generic) (10522/11/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter burger
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
747
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exodus.zip
Verdict:
Malicious activity
Analysis date:
2025-06-26 19:44:44 UTC
Tags:
auto generic xred backdoor python blankgrabber stealer screenshot cobianrat remote evasion telegram delphi

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
vmdetect delphi cobalt njrat
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Using the Windows Management Instrumentation requests
Launching the process to change network settings
Launching the default Windows debugger (dwwin.exe)
Reading critical registry keys
Sending a custom TCP request
Creating a file in the %AppData% directory
Creating a process with a hidden window
Running batch commands
Launching a process
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Creating a window
Creating a file
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Setting browser functions hooks
Enabling the 'hidden' option for files in the %temp% directory
Enabling the 'hidden' option for recently created files
Moving a recently created file
Modifying an executable file
DNS request
Connection attempt
Sending an HTTP GET request
Stealing user critical data
Query of malicious DNS domain
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a recently created process
Enabling a "Do not show hidden files" option
Adding an exclusion to Microsoft Defender
Unauthorized injection to a browser process
Enabling autorun by creating a file
Unauthorized injection to a system process
Infecting executable files
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
entropy expand lolbin microsoft_visual_cc overlay overlay packed packed packer_detected
Result
Threat name:
Blank Grabber, Cobian RAT, R77 RootKit,
Detection:
malicious
Classification:
rans.troj.adwa.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains process injector
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Changes the view of files in windows explorer (hidden files and folders)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to log keystrokes (.Net Source)
Creates a thread in another existing process (thread injection)
Creates autostart registry keys with suspicious names
Creates files in the system32 config directory
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains an embedded VBA with functions possibly related to WSH operations (process, registry, environment, or keystrokes)
Drops PE files to the document folder of the user
Drops PE files to the startup folder
Drops PE files with benign system names
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found stalling execution ending in API Sleep call
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies existing user documents (likely ransomware behavior)
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Potentially Suspicious Malware Callback Communication
Sigma detected: Schedule system process
Sigma detected: System File Execution Location Anomaly
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
Yara detected Blank Grabber
Yara detected Cobian RAT
Yara detected R77 RootKit
Yara detected UAC Bypass using CMSTP
Yara detected XRed
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1723726 Sample: Wrotocol.exe Startdate: 26/06/2025 Architecture: WINDOWS Score: 100 153 freedns.afraid.org 2->153 155 api.telegram.org 2->155 157 11 other IPs or domains 2->157 193 Suricata IDS alerts for network traffic 2->193 195 Found malware configuration 2->195 197 Malicious sample detected (through community Yara rule) 2->197 203 31 other signatures 2->203 15 Wrotocol.exe 13 2->15         started        18 ._cache_Host Process for Windows.exe 2->18         started        22 EXCEL.EXE 186 51 2->22         started        signatures3 199 Uses dynamic DNS services 153->199 201 Uses the Telegram API (likely for C&C communication) 155->201 process4 dnsIp5 133 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 15->133 dropped 135 C:\Users\user\AppData\Local\...\select.pyd, PE32+ 15->135 dropped 137 C:\Users\user\AppData\Local\...\python311.dll, PE32+ 15->137 dropped 141 7 other malicious files 15->141 dropped 24 Wrotocol.exe 4 15->24         started        27 conhost.exe 15->27         started        159 147.185.221.28, 49180, 49735 SALSGIVERUS United States 18->159 139 {6Y7BDC40-879330-6E7IKJ-6E7IKJ40S1}.exe, PE32 18->139 dropped 205 Changes the view of files in windows explorer (hidden files and folders) 18->205 207 Creates autostart registry keys with suspicious names 18->207 209 Writes to foreign memory regions 18->209 211 4 other signatures 18->211 29 schtasks.exe 18->29         started        31 schtasks.exe 18->31         started        161 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49759, 49760 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 22->161 file6 signatures7 process8 file9 117 C:\Users\user\AppData\Local\Temp\...\tool.exe, PE32 24->117 dropped 33 tool.exe 1 5 24->33         started        36 conhost.exe 29->36         started        38 conhost.exe 31->38         started        process10 file11 107 C:\Users\user\AppData\...\._cache_tool.exe, PE32 33->107 dropped 109 C:\ProgramData\Synaptics\Synaptics.exe, PE32 33->109 dropped 111 C:\ProgramData\Synaptics\RCXDEDA.tmp, PE32 33->111 dropped 40 ._cache_tool.exe 4 33->40         started        43 Synaptics.exe 32 33->43         started        process12 dnsIp13 119 C:\Users\user\AppData\Local\...\WmiPrvSE.exe, PE32+ 40->119 dropped 121 C:\Users\...\Host Process for Windows.exe, PE32 40->121 dropped 47 WmiPrvSE.exe 40->47         started        50 Host Process for Windows.exe 40->50         started        167 drive.usercontent.google.com 142.250.176.193, 443, 49725, 49726 GOOGLEUS United States 43->167 169 docs.google.com 142.250.81.238, 443, 49723, 49724 GOOGLEUS United States 43->169 171 freedns.afraid.org 69.42.215.252, 49728, 80 AWKNET-LLCUS United States 43->171 123 C:\Users\user\Documents\JDDHMPCDUJ\~$cache1, PE32 43->123 dropped 231 Antivirus detection for dropped file 43->231 233 Drops PE files to the document folder of the user 43->233 52 WerFault.exe 43->52         started        file14 signatures15 process16 file17 143 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 47->143 dropped 145 C:\Users\user\AppData\Local\...\select.pyd, PE32+ 47->145 dropped 147 C:\Users\user\AppData\Local\...\python311.dll, PE32+ 47->147 dropped 151 7 other malicious files 47->151 dropped 54 WmiPrvSE.exe 47->54         started        57 conhost.exe 47->57         started        149 C:\...\._cache_Host Process for Windows.exe, PE32 50->149 dropped 59 ._cache_Host Process for Windows.exe 50->59         started        process18 file19 113 C:\Users\user\AppData\Local\Temp\...\tool.exe, PE32+ 54->113 dropped 62 tool.exe 54->62         started        115 C:\Users\user\AppData\Roaming\Svchost.exe, PE32 59->115 dropped 213 Writes to foreign memory regions 59->213 215 Allocates memory in foreign processes 59->215 217 Modifies the context of a thread in another process (thread injection) 59->217 219 2 other signatures 59->219 65 dllhost.exe 59->65         started        68 Svchost.exe 59->68         started        70 schtasks.exe 59->70         started        72 schtasks.exe 59->72         started        signatures20 process21 file22 125 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 62->125 dropped 127 C:\Users\user\AppData\Local\...\sqlite3.dll, PE32+ 62->127 dropped 129 C:\Users\user\AppData\Local\...\select.pyd, PE32+ 62->129 dropped 131 16 other malicious files 62->131 dropped 74 tool.exe 62->74         started        181 Found stalling execution ending in API Sleep call 65->181 183 Writes to foreign memory regions 65->183 185 Creates a thread in another existing process (thread injection) 65->185 78 winlogon.exe 65->78 injected 80 lsass.exe 65->80 injected 82 svchost.exe 65->82 injected 187 Allocates memory in foreign processes 68->187 189 Modifies the context of a thread in another process (thread injection) 68->189 191 Injects a PE file into a foreign processes 68->191 84 schtasks.exe 68->84         started        86 schtasks.exe 68->86         started        88 conhost.exe 70->88         started        90 conhost.exe 72->90         started        signatures23 process24 dnsIp25 163 ip-api.com 208.95.112.1, 49755, 80 TUT-ASUS United States 74->163 165 api.telegram.org 149.154.167.220, 443, 49756 TELEGRAMRU United Kingdom 74->165 221 Tries to harvest and steal browser information (history, passwords, etc) 74->221 223 Tries to steal Crypto Currency Wallets 74->223 225 Modifies existing user documents (likely ransomware behavior) 74->225 92 Synaptics.exe 74->92         started        94 Conhost.exe 74->94         started        96 dllhost.exe 78->96         started        99 dllhost.exe 78->99         started        227 Creates files in the system32 config directory 80->227 229 Writes to foreign memory regions 80->229 101 conhost.exe 84->101         started        103 conhost.exe 86->103         started        signatures26 process27 signatures28 173 Injects code into the Windows Explorer (explorer.exe) 96->173 175 Writes to foreign memory regions 96->175 177 Creates a thread in another existing process (thread injection) 96->177 179 Injects a PE file into a foreign processes 99->179 105 dwm.exe 99->105 injected process29
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) Win 64 Exe x64
Gathering data
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-06-26 19:41:06 UTC
File Type:
PE+ (Exe)
Extracted files:
437
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xred backdoor collection credential_access defense_evasion discovery execution persistence privilege_escalation spyware stealer upx
Behaviour
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of SetWindowsHookEx
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: AddClipboardFormatListener
Scheduled Task/Job: Scheduled Task
Modifies registry class
Gathers system information
Enumerates system info in registry
Detects videocard installed
Checks processor information in registry
System Network Configuration Discovery: Wi-Fi Discovery
System Location Discovery: System Language Discovery
Event Triggered Execution: Netsh Helper DLL
Enumerates physical storage devices
Browser Information Discovery
Suspicious use of SetThreadContext
UPX packed file
Enumerates processes with tasklist
Drops file in System32 directory
Obfuscated Files or Information: Command Obfuscation
Looks up external IP address via web service
Adds Run key to start application
Accesses cryptocurrency files/wallets, possible credential harvesting
Unsecured Credentials: Credentials In Files
Reads user/profile data of web browsers
Loads dropped DLL
Executes dropped EXE
Drops startup file
Clipboard Data
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Xred family
Xred
Suspicious use of NtCreateUserProcessOtherParentProcess
Malware Config
C2 Extraction:
xred.mooo.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercês
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MALWARE_Win_CobianRAT
Author:ditekSHen
Description:Detects CobianRAT, a fork of Njrat
Rule name:MALWARE_Win_R77
Author:ditekSHen
Description:Detects r77 rootkit
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PyInstaller
Author:@bartblaze
Description:Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:upx_largefile
Author:k3nr9
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Windows_Rootkit_R77_5bab748b
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit
Rule name:Windows_Rootkit_R77_99050e7d
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit
Rule name:Windows_Rootkit_R77_d0367e28
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (FORCE_INTEGRITY)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::ConvertSidToStringSidW
ADVAPI32.dll::ConvertStringSecurityDescriptorToSecurityDescriptorW
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessW
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetDriveTypeW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetConsoleCtrlHandler
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleWindow
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::FindFirstFileW
KERNEL32.dll::RemoveDirectoryW
KERNEL32.dll::SetDllDirectoryW
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageW
USER32.dll::CreateWindowExW

Comments