MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43ddd2b5298b9c14f9dd71ad0883e954fdc4515d947874ddf2c2f22b99764e55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 43ddd2b5298b9c14f9dd71ad0883e954fdc4515d947874ddf2c2f22b99764e55
SHA3-384 hash: 226a609798ca9a9489c8c69e8db53a5e9d9415f147d5691c882b99ed6076a119965a994d75d69d2e615b098ba10f895e
SHA1 hash: 3d30d87517a94358a5665c3628020f58d80fe628
MD5 hash: f8c0fd545dcf84b031440c51259e5494
humanhash: stairway-solar-kentucky-butter
File name:DUv1ZJm0.exe
Download: download sample
Signature njrat
File size:32'768 bytes
First seen:2020-09-22 19:17:21 UTC
Last seen:2020-09-23 08:17:19 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'600 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 384:fCbP3tSX6vBq7lazgE+0JQxZNgNK7+vjJOWTXtebrOFeqzK/E:ES6vBqMzI0aHNgN8gjJ8r1E
Threatray 29 similar samples on MalwareBazaar
TLSH 10E2184B37B58115C2ED16F89DB317204772E3838532EB6F9CDC84CA9BA36D50246EE9
Reporter pmelson
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
DNS request
Using the Windows Management Instrumentation requests
Sending a custom TCP request
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
80 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Contains functionality to log keystrokes (.Net Source)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Njrat
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-09-22 19:19:05 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of AdjustPrivilegeToken
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

Executable exe 43ddd2b5298b9c14f9dd71ad0883e954fdc4515d947874ddf2c2f22b99764e55

(this sample)

Comments