🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a4ae73d9deab5225bf225fec5f1a1bd92d1e7cded7384e17d4a38528e44389a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 10


Intelligence 10 IOCs YARA 26 File information Comments

SHA256 hash: 5a4ae73d9deab5225bf225fec5f1a1bd92d1e7cded7384e17d4a38528e44389a
SHA3-384 hash: a034af7c9142880ceadcbe5e2ef0c58088de177a7e4bb3ee22c0d8d44717460eaa9666eaf524d0b9a83a231182601b00
SHA1 hash: 5f53d8b8ed3adf810d20cfc32ecc400f93140c82
MD5 hash: 841cab2a3109ceb13f2bc33042ff4db7
humanhash: colorado-harry-montana-double
File name:2qfidlen.exe
Download: download sample
Signature njrat
File size:3'082'240 bytes
First seen:2026-02-14 23:47:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 49152:fDkefA44jNNwfDQQ1aYyUc2Ktq8TECJZCw:fP/0CRyUc++
TLSH T186E57C07BDE418A6E0AAA23189A25572BFF1BC452F2153CB2A80F7BC2F737C06575355
TrID 57.7% (.EXE) UPX compressed Win64 Executable (70117/5/12)
22.3% (.EXE) UPX compressed Win32 Executable (27066/9/6)
5.3% (.EXE) Win64 Executable (generic) (6522/11/2)
4.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
3.7% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon eaae8a9ea69ae8b0 (33 x Formbook, 4 x SnakeKeylogger, 2 x ConnectWise)
Reporter SquiblydooBlog
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
238
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2qfidlen.exe
Verdict:
No threats detected
Analysis date:
2026-02-14 23:48:07 UTC
Tags:
upx golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
81.4%
Tags:
micro
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
DNS request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
agenttesla base64 crypto golang obfuscated packed packed reconnaissance
Verdict:
Clean
File Type:
exe x64
First seen:
2026-02-12T20:16:00Z UTC
Last seen:
2026-02-13T08:51:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
8 match(es)
Tags:
.Net Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Malware.Heuristic
Status:
Malicious
First seen:
2026-02-13 02:42:52 UTC
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
upx
Unpacked files
SH256 hash:
5a4ae73d9deab5225bf225fec5f1a1bd92d1e7cded7384e17d4a38528e44389a
MD5 hash:
841cab2a3109ceb13f2bc33042ff4db7
SHA1 hash:
5f53d8b8ed3adf810d20cfc32ecc400f93140c82
SH256 hash:
0e3b16a70ab3338efc05b89054e069a490e2a39876488f2561e214cc37b013e5
MD5 hash:
b97dc60a8de6dc09329c2218a5d3a302
SHA1 hash:
6ecc69fd5ed316b50f71e63869f1d8bb4cc94025
SH256 hash:
8bf0f2e8dadf3967757191c2212c269333ccd9d7e59839eea968212c64787be9
MD5 hash:
c583aa3819b16ae53859f728f59ea9a0
SHA1 hash:
b699e8e2cfc52bc3cfba182fdabfc7f6ff8f82de
SH256 hash:
ca03780217139b37f7f5b6921d59defb8d24988315b16b167a77fa88caa7d00f
MD5 hash:
eb254b04d63a9f03b77563243805f68f
SHA1 hash:
b01c83ec51f7a6548d1babb5e5ff8d5b944965a1
SH256 hash:
fcf493fc47a2f478a65303886b975fbdbf714cbb1f2d79f7fce97e4bb16b01a8
MD5 hash:
48867f392b8e77dc06c062638c6fbd36
SHA1 hash:
ccc0931e2cf3d6d79e24c1f28d9c96b40c131af6
SH256 hash:
f246e29921797b173b54229685e997a11f9cc388fa1e589c212328abd7a94ebe
MD5 hash:
3f5c79100f4f7902114c3fcba275c606
SHA1 hash:
cb874b2a2561239b5b1c30a49574229716f5f62d
SH256 hash:
618ef0e49d64e7a66dfe64bbf6ae81705b9d9683d8a9f321e5c3024d666bdf82
MD5 hash:
278ebb79da14ecf8e0559530c2fda076
SHA1 hash:
8a45f0400f6bc46d254120345fd5e39b6c9b71a1
SH256 hash:
749a01ebbb5edd8b1a03c5263b04de6acadecf52e4cc84d7412bc6e93f180958
MD5 hash:
faf1ba532964984a34d60674fbc7a5a7
SHA1 hash:
0999178949de510a47d87de3b8a117a003c572ee
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:GoBinTest
Rule name:golang
Rule name:Golangmalware
Author:Dhanunjaya
Description:Malware in Golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:HiveRansomware
Author:Dhanunjaya
Description:Yara Rule To Detect Hive V4 Ransomware
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:Obfuscar
Author:kevoreilly
Description:Obfuscar xor routime
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments