MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4f
SHA3-384 hash: d581bff7aa30a8f9b759e0833c7715bfa9ddb80e42ee6a06dfeafe8fd7325dadbe635ec7f6df571bb22a4971611e7660
SHA1 hash: d1531f8fe3cc29cb6be790fbceb713c16fcb7070
MD5 hash: b941df6a19c37ff4f77b1ef1cc2ae16d
humanhash: charlie-nebraska-east-beer
File name:done.exe
Download: download sample
Signature njrat
File size:136'192 bytes
First seen:2021-07-21 08:20:47 UTC
Last seen:2021-07-21 09:20:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:SNbunwxGaGIf5qq+lTyqTSPtDN8ecfQ00gv8E6SfzsMAIY22TJ2:ScAGzIf5qq+lSxqxfQLW8E6SfzsMAIYn
TLSH T1B9D3939D766072DFC85BC8769EA81C68EA60747B931F9203A45316ED9E0D89BCF140F2
Reporter JAMESWT_WT
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
192
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
done.exe
Verdict:
No threats detected
Analysis date:
2021-07-21 08:25:02 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
92 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Njrat
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2021-07-21 06:27:07 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
1
AV detection:
13 of 46 (28.26%)
Threat level:
  1/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Core1 .NET packer
Unpacked files
SH256 hash:
3582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4f
MD5 hash:
b941df6a19c37ff4f77b1ef1cc2ae16d
SHA1 hash:
d1531f8fe3cc29cb6be790fbceb713c16fcb7070
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

Executable exe 3582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4f

(this sample)

Comments