🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e7b5a9d400b328dc41b8e4adfce4ff12de3a11a744616049dfee06acfec09e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 2


Intelligence 2 IOCs YARA 5 File information Comments

SHA256 hash: 6e7b5a9d400b328dc41b8e4adfce4ff12de3a11a744616049dfee06acfec09e3
SHA3-384 hash: 60cfa499ed16268cd80a7af2af4b5a382df2bd51cb40c7f07f1a318d7fe449095ae04cd3bd1d60c054a1ff4708982ca2
SHA1 hash: 2cf7b59a1e72e9d663c022e0e2a59cd0c83c8865
MD5 hash: 62879881626ad392c087dad47439bdf1
humanhash: chicken-purple-golf-cardinal
File name:cx-programmer 9.1 free download full.7z
Download: download sample
Signature njrat
File size:17'499'827 bytes
First seen:2026-09-03 12:20:59 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 2167
ssdeep 393216:eiK1Gz5K3YbTnRtLSR/Op0XQNn5YZgAt5/4reI6q9s2LLU:eiv5DXLShO6Q18gAnqZ9sow
TLSH T1950733DE016E1349E8BCF3987FF01654C1615B5B86780E33794A9FA92D6ADEC90703AC
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:7z file-pumped nweenwew234-cc pw-2167 value-dome-club


Avatar
iamaachum
https://pulse.pulsecorevault4.lol/cx-programmer+9.1+free+download+Full.zip

C2: nweenwew234.cc

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:cx-programmer 9.1 free download full.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:973'625'587 bytes
SHA256 hash: 82d9efd228df23e24deda520fdc62bef485809e5d2d4f31995b4a402a8c042f6
MD5 hash: cc86c689034f7e6554663a9e23c7d873
De-pumped file size:546'816 bytes (Vs. original size of 973'625'587 bytes)
De-pumped SHA256 hash: 18d9697f3dd2563fed1053e0ef11731ee45af79c38ee48288576056b1aa6af8e
De-pumped MD5 hash: f6e66541ac36177402bded2052ed1704
MIME type:application/x-dosexec
Signature njrat
Vendor Threat Intelligence
No detections
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
SFX 7z
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery link pdf spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
System Time Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

7z 6e7b5a9d400b328dc41b8e4adfce4ff12de3a11a744616049dfee06acfec09e3

(this sample)

Comments