🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f60a7b2a8bc1a0c0477738c6c26fe8d5807cc1fbd065290034aa4303bbb29fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 7f60a7b2a8bc1a0c0477738c6c26fe8d5807cc1fbd065290034aa4303bbb29fd
SHA3-384 hash: aaba6fb885fdf5bbeab7335226c7b4050ee7445910602a83faaaca0c0a0ea54d6ebe9c9d1df3894be68ee4b65dd88b57
SHA1 hash: b61297b42d0d354e028a20c3ceec73053c4921a1
MD5 hash: 9e8d43c922112458612b184482c5848f
humanhash: arizona-quebec-william-michigan
File name:TRIAL_IMG_00O0125RDER.7z
Download: download sample
Signature njrat
File size:329'838 bytes
First seen:2026-05-21 14:28:14 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 6144:l+cSvaPm7Y2Mut83f89hM4h0tb95OV1J2pe8ejJy3borpj7krN44Is:l+cRmIJ3DNt55o1JPN4Urpj7krN5b
TLSH T14E6423DB75D44F58B4979EECAB8DCBC628278E986BD734403DD5ACCA18223D22D84F11
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter TomU
Tags:7z NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:TRIAL IMG_00O0125RDER.exe
File size:505'322 bytes
SHA256 hash: 076efef63c51577044a06216c84e1acb0f70f8297fdf514e914fd8c25e2069d2
MD5 hash: 007cf45726919923fac1d55ae6ab79db
MIME type:application/x-dosexec
Signature njrat
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
99.1%
Tags:
injection obfusc virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug evasive installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance smb
Verdict:
Malicious
File Type:
7z
First seen:
2026-05-21T11:41:00Z UTC
Last seen:
2026-05-21T11:52:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2026-05-21 15:37:42 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

njrat

7z 7f60a7b2a8bc1a0c0477738c6c26fe8d5807cc1fbd065290034aa4303bbb29fd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments