MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30f8fdb26e5ef75f382fd927a35e00ea8accd504e677058b7fd28e6a73553d40. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: 30f8fdb26e5ef75f382fd927a35e00ea8accd504e677058b7fd28e6a73553d40
SHA3-384 hash: 3a8bd6ccb26747db649cf559d6577d6a7834134064b356ac18d666dd8f3e26a571f86106e499387b3d2fbf5405b9b43a
SHA1 hash: 1dc70364adbe70b7f1396fb1ae54bd56769b1f4b
MD5 hash: 7311320686afe0a309586adb63442d46
humanhash: carbon-zebra-mexico-batman
File name:30f8fdb26e5ef75f382fd927a35e00ea8accd504e677058b7fd28e6a73553d40
Download: download sample
Signature njrat
File size:822'272 bytes
First seen:2026-08-10 15:01:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'192 x AgentTesla, 20'341 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:ueA9sc3qymb6fWdVLO1pGsy+Jp238NtpY3:PUs+5w6MVLO1wIp23a+
TLSH T1D80502582A16EA06D99243B80BB1E3B417BC5DDDE820E3179FE9BDEB7629F444D04343
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Launching a process
Creating a file
Adding an exclusion to Microsoft Defender
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
entropy packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-30T06:07:00Z UTC
Last seen:
2026-08-12T13:20:00Z UTC
Hits:
~1000
Gathering data
Gathering data
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-30 23:18:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm collection defense_evasion discovery execution persistence privilege_escalation rat spyware stealer trojan
Behaviour
Kills process with taskkill
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Checks computer location settings
Creates a file in the Startup directory
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Detect Xworm Payload
Family: Xworm
Malware Config
C2 Extraction:
31.59.118.77:7004
Unpacked files
SH256 hash:
30f8fdb26e5ef75f382fd927a35e00ea8accd504e677058b7fd28e6a73553d40
MD5 hash:
7311320686afe0a309586adb63442d46
SHA1 hash:
1dc70364adbe70b7f1396fb1ae54bd56769b1f4b
SH256 hash:
968145d2f0d00b3f8262f4b1bd8421d7caf04b2d55b905e13d8e2bb604f58d12
MD5 hash:
8f8752ccab2774a39d675563af36f57c
SHA1 hash:
0dea4bbbb87a1c34a3ef77ad5347635d603cf173
SH256 hash:
35fcc556369997816cf8cc3afa5ab5e41cfe626dac0c60de1ed523241b4f2521
MD5 hash:
689153acaf552748d37bb1673e9ebb54
SHA1 hash:
280409155461d3f5df4e576f1b57249d0d014b67
Detections:
win_xworm_w0 win_xworm_a0 XWorm
SH256 hash:
6d4c5bc731b2e23fa90f0d8e916c17f57c4bf3d38278b1d02bb560cb19b85091
MD5 hash:
cd2fd8822f142d3a5f9d51f58967a218
SHA1 hash:
7d83a73965e5cdba3ecf738e3794804d3c98f8c0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments