🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8769633506cd757af1860efd470b7e304a1adf13ee101f5d449c11a79f25eac6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 5


Intelligence 5 IOCs YARA 21 File information Comments

SHA256 hash: 8769633506cd757af1860efd470b7e304a1adf13ee101f5d449c11a79f25eac6
SHA3-384 hash: 1fa1fa7b76064c68a416fb4eba1766c4b4883d00864275741b0c363f608d768da7b046b8770157ecf4fbae39bc59e9f1
SHA1 hash: 2057aa20348bd631e8faca458a542347060624d4
MD5 hash: 3913c8d05138e8927156c8903fb96e84
humanhash: london-massachusetts-cardinal-wisconsin
File name:Program Rules NVIDEO.zip
Download: download sample
Signature njrat
File size:2'615'429 bytes
First seen:2025-06-10 12:17:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:PYm/k4UTEtxJzK5fNpbOaFUZegRyy1mkGIhm+I6XzeQs/jP2CYrVBBqL1y:PYmVxJzK5fNpbOam0gRyjkJhI2zfs72T
TLSH T1C9C533C053BF4B20B9FACC3306B3A7702B5BE1AA7F1555EA1C57B0350995CBA9D862D0
Magika zip
Reporter JAMESWT_WT
Tags:desckvbrat-com-br NjRAT zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
IT IT
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:xhubh.ps1
File size:263 bytes
SHA256 hash: 2bdefad686871d0633dc67a4694cbe529a2ad6bef1c392c46cf782edf21daff2
MD5 hash: 8f9966f2804a89832f8bb5e54228a592
MIME type:text/plain
Signature njrat
File name:cyzcv.ps1
File size:432 bytes
SHA256 hash: 9970fe5360b0fab28bdeedc756f7d9f20bc14b95ca2be5e5bf54585846c0e092
MD5 hash: 1007d83945d80499795a3e6a66cb5ce7
MIME type:text/plain
Signature njrat
File name:geude.ps1
File size:437 bytes
SHA256 hash: 95a04e68a1cccae586e3a36ccb4d22ce8cf56dea72665afa82d20c1c86d34737
MD5 hash: 244e84bbd0f72ee9c5f374ceb65832c7
MIME type:text/plain
Signature njrat
File name:ndsyx.ps1
File size:7'263'708 bytes
SHA256 hash: b8236cf293efe460838e50f61fa1c14c42acab344ff3e225de50c8738ab25e68
MD5 hash: 4d30711bb7a468edba8e30ad64aa35cc
MIME type:text/plain
Signature njrat
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
stration rapid shell spawn
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution persistence privilege_escalation
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Adds Run key to start application
Hide Artifacts: Hidden Window
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CN_disclosed_20180208_c
Author:Florian Roth (Nextron Systems)
Description:Detects malware from disclosed CN malware set
Reference:https://twitter.com/cyberintproject/status/961714165550342146
Rule name:CN_disclosed_20180208_c_RID2E71
Author:Florian Roth
Description:Detects malware from disclosed CN malware set
Reference:https://twitter.com/cyberintproject/status/961714165550342146
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:malware_Njrat_strings
Author:JPCERT/CC Incident Response Group
Description:detect njRAT in memory
Rule name:MAL_njrat
Author:SECUINFRA Falcon Team
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:pe_imphash
Rule name:Skystars_LightDefender_Njrat_Rule
Author:Skystars LightDefender
Description:Detects Njrat
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_netsh_firewall_command
Author:SECUINFRA Falcon Team
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:win32_njrat
Author:Reedus0
Description:Rule for detecting njrat malware
Rule name:Windows_Trojan_Njrat_30f3c220
Rule name:win_njrat_g1
Author:Daniel Plohmann <daniel.plohmann<at>fkie.fraunhofer.de>
Rule name:win_njrat_w1
Author:Brian Wallace @botnet_hunter <bwall@ballastsecurity.net>
Description:Identify njRat

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments