🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c4289fd06fafc0a4ec36ce9ee5ba34861c5dea0587985ea591aef3bbfa5339b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 6c4289fd06fafc0a4ec36ce9ee5ba34861c5dea0587985ea591aef3bbfa5339b
SHA3-384 hash: 19b76cc4beb79124b4fa22bc8bff45f891a163f9e9c61cbce063b2d05af6ecac1f95dc639e4638690dacbff02bb420b3
SHA1 hash: e4c2c292ece5767d34aeb2b678a27041deed333a
MD5 hash: 74d0ace71e4e7894b3dcffdaeefd86f6
humanhash: friend-green-mountain-charlie
File name:Needed Aircraft PN#_Desc_&_Qty Details.js
Download: download sample
Signature njrat
File size:130'484 bytes
First seen:2025-06-13 13:16:51 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 1536:RvvHvd0s0s0s0s0s09FfA0s0s0s0s0s0s0J:9vd0s0s0s0s0s09FfA0s0s0s0s0s0s0J
TLSH T171D3822682BD4105F0F39B0DC1AB063543B7BD661E3E418D5676A1498EFAB04ADB83F7
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika mp3
Reporter Anonymous
Tags:js NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
493
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
dropper shell sage
Result
Threat name:
Detection:
malicious
Classification:
spre.phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Contains functionality to log keystrokes (.Net Source)
Contains functionality to spread to USB devices (.Net source)
Creates autostart registry keys with suspicious values (likely registry only malware)
Creates multiple autostart registry keys
Disables zone checking for all users
Encrypted powershell cmdline option found
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the windows firewall
Self deletion via cmd or bat file
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: PowerShell Base64 Encoded Invoke Keyword
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Uses netsh to modify the Windows network and firewall settings
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Njrat
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1714121 Sample: Needed Aircraft PN#_Desc_&_... Startdate: 13/06/2025 Architecture: WINDOWS Score: 100 142 myapps.sytes.net 2->142 144 myapps.chickenkiller.com 2->144 146 3 other IPs or domains 2->146 160 Suricata IDS alerts for network traffic 2->160 162 Found malware configuration 2->162 164 Malicious sample detected (through community Yara rule) 2->164 166 16 other signatures 2->166 13 wscript.exe 1 1 2->13         started        16 cmd.exe 2->16         started        18 cmd.exe 2->18         started        20 cmd.exe 2->20         started        signatures3 process4 signatures5 196 JScript performs obfuscated calls to suspicious functions 13->196 198 Suspicious powershell command line found 13->198 200 Wscript starts Powershell (via cmd or directly) 13->200 202 3 other signatures 13->202 22 powershell.exe 7 13->22         started        25 powershell.exe 16->25         started        27 conhost.exe 16->27         started        29 powershell.exe 18->29         started        31 conhost.exe 18->31         started        33 powershell.exe 20->33         started        35 conhost.exe 20->35         started        process6 signatures7 168 Suspicious powershell command line found 22->168 170 Encrypted powershell cmdline option found 22->170 172 Self deletion via cmd or bat file 22->172 178 2 other signatures 22->178 37 powershell.exe 14 18 22->37         started        41 conhost.exe 22->41         started        174 Writes to foreign memory regions 25->174 176 Injects a PE file into a foreign processes 25->176 43 powershell.exe 25->43         started        53 5 other processes 25->53 45 powershell.exe 29->45         started        47 conhost.exe 29->47         started        49 InstallUtil.exe 29->49         started        51 powershell.exe 33->51         started        55 3 other processes 33->55 process8 dnsIp9 148 desckvbrat.com.br 192.185.217.3, 443, 49690, 49691 UNIFIEDLAYER-AS-1US United States 37->148 134 C:\Users\user\AppData\Local\Temp\pxgqw.ps1, Unicode 37->134 dropped 57 powershell.exe 14 37->57         started        62 powershell.exe 43->62         started        72 4 other processes 43->72 64 powershell.exe 45->64         started        66 powershell.exe 45->66         started        68 powershell.exe 45->68         started        74 3 other processes 45->74 70 powershell.exe 51->70         started        76 3 other processes 51->76 file10 process11 dnsIp12 158 files.catbox.moe 108.181.20.35, 443, 49693 ASN852CA Canada 57->158 136 C:\Users\user\AppData\LocalLow\...\udwiq.ps1, ASCII 57->136 dropped 138 C:\Users\user\AppData\LocalLow\...\owawy.ps1, Unicode 57->138 dropped 140 C:\Users\user\AppData\LocalLow\...\fkjfa.ps1, ASCII 57->140 dropped 192 Self deletion via cmd or bat file 57->192 194 Adds a directory exclusion to Windows Defender 57->194 78 powershell.exe 57->78         started        81 cmd.exe 57->81         started        83 cmd.exe 57->83         started        85 7 other processes 57->85 file13 signatures14 process15 signatures16 204 Writes to foreign memory regions 78->204 206 Injects a PE file into a foreign processes 78->206 87 InstallUtil.exe 78->87         started        91 powershell.exe 78->91         started        208 Suspicious powershell command line found 81->208 210 Wscript starts Powershell (via cmd or directly) 81->210 93 powershell.exe 81->93         started        95 powershell.exe 83->95         started        212 Uses ping.exe to sleep 85->212 214 Uses ping.exe to check the status of other devices and networks 85->214 216 Loading BitLocker PowerShell Module 85->216 97 powershell.exe 85->97         started        99 PING.EXE 1 85->99         started        101 PING.EXE 1 85->101         started        103 2 other processes 85->103 process17 dnsIp18 150 crazydns.bumbleshrimp.com 196.251.72.146, 1597, 49701 Web4AfricaZA Seychelles 87->150 152 myapps.sytes.net 185.241.93.91, 56362 ASN-ITNETIT Italy 87->152 154 myapps.chickenkiller.com 127.0.0.2 unknown unknown 87->154 180 Disables zone checking for all users 87->180 182 Uses netsh to modify the Windows network and firewall settings 87->182 184 Modifies the windows firewall 87->184 105 netsh.exe 87->105         started        107 powershell.exe 91->107         started        109 powershell.exe 91->109         started        120 5 other processes 91->120 111 powershell.exe 93->111         started        186 Suspicious powershell command line found 95->186 114 powershell.exe 95->114         started        188 Writes to foreign memory regions 97->188 190 Injects a PE file into a foreign processes 97->190 116 powershell.exe 97->116         started        118 conhost.exe 97->118         started        122 3 other processes 97->122 156 127.0.0.1 unknown unknown 99->156 signatures19 process20 signatures21 124 conhost.exe 105->124         started        218 Creates autostart registry keys with suspicious values (likely registry only malware) 111->218 220 Creates multiple autostart registry keys 111->220 126 powershell.exe 116->126         started        128 powershell.exe 116->128         started        130 powershell.exe 116->130         started        132 2 other processes 116->132 process22
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-10 18:05:00 UTC
File Type:
Text (JavaScript)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution persistence privilege_escalation
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in System32 directory
Suspicious use of SetThreadContext
Adds Run key to start application
Hide Artifacts: Hidden Window
Indicator Removal: File Deletion
Checks computer location settings
Blocklisted process makes network request
Command and Scripting Interpreter: PowerShell
Modifies Windows Firewall
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via e-mail link

Comments