🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 86aae65ce3c1668cfc4d5914a86830fccc088484d32232e0e1203735fb74ffb7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 86aae65ce3c1668cfc4d5914a86830fccc088484d32232e0e1203735fb74ffb7
SHA3-384 hash: 4f8599b43ab5886a9a668f1a9f5a7e53f4786bbe8594304ea4dd80f2631980f77d34e97043a6ef9e5847b70787067a0b
SHA1 hash: 2784b067b138cf173385bec3233b4b9b5823c3d8
MD5 hash: f75fab1bf8ab16f9ece439e9b22325dd
humanhash: hot-virginia-uniform-alpha
File name:XWorm-5.6.zip
Download: download sample
Signature njrat
File size:26'222'839 bytes
First seen:2025-05-16 17:18:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 786432:MCygXHrCT0kw0OJAxTtJtAfoJ/9nH2a2UxfDfgSnVv:5XHrCTvbOiTt7AfoJ/9Wa2UxfDfgSd
TLSH T16147331BEE8303B5C14AED3438565FAEF31E71E2BAB2151CB344EF8848596506BE3356
Magika zip
Reporter skocherhan
Tags:AgentTesla AsyncRAT NjRAT opendir StormKitty zip


Avatar
skocherhan
http://107.189.20.81/XWorm-5.6.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
416
Origin country :
GB GB
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 bladabindi fingerprint obfuscated stealer telegram xworm xworm
Gathering data
Threat name:
Win32.Trojan.Jalapeno
Status:
Malicious
First seen:
2025-05-07 20:01:02 UTC
File Type:
Binary (Archive)
Extracted files:
1357
AV detection:
28 of 37 (75.68%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stormkitty family:xworm
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments