MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 256873a8419bd5553511b23fad2bef56901669fc2c7891c89315f68fcedb1ff5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 256873a8419bd5553511b23fad2bef56901669fc2c7891c89315f68fcedb1ff5
SHA3-384 hash: 8c216a0a030356874bf24f02a5a8178a13a4883e2ba91550d661d4068f97d809ffe8c94828c664a7db430f189672aef0
SHA1 hash: 97cdeba091f7492688f88e55afe04022375db122
MD5 hash: 989a530a1dd233421e3e6ba3128b3980
humanhash: social-music-california-ack
File name:256873a8419bd5553511b23fad2bef56901669fc2c7891c89315f68fcedb1ff5
Download: download sample
Signature njrat
File size:90'624 bytes
First seen:2020-06-29 07:47:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 768:3W95c/j/kR3tLoMWzTIl879gZ7wQYydguJcF4Qhc4VjsS8jdMUIDLTtgy0DeyD7x:3IKzkRdLDWHIl87OZ7wQ/2hBjsVL5J
TLSH 6293CD2229EF249DF3B29AB12FE9F5FFC96EE973150A70BA208107068735D41AC41775
Reporter JAMESWT_WT
Tags:NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-06-22 02:42:26 UTC
File Type:
PE (.Net Exe)
Extracted files:
14
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
Score:
  10/10
Tags:
trojan family:njrat evasion persistence
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Modifies service
Adds Run entry to start application
Loads dropped DLL
Executes dropped EXE
Modifies Windows Firewall
njRAT/Bladabindi
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments