🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ec809c41cba7fc6dabf56ddac952366deb68aba8288bbfe14431ee305d6ba3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 6


Intelligence 6 IOCs YARA 10 File information Comments

SHA256 hash: 8ec809c41cba7fc6dabf56ddac952366deb68aba8288bbfe14431ee305d6ba3a
SHA3-384 hash: 35740a8681254080a6b41f6139da3beeaa6b55db9bb5d78b54dd1b5062b95d16c3556526c7879424a4b1072383d65048
SHA1 hash: 3e704995da8f3cd414b80cb509446006628094d2
MD5 hash: 2d3976e1c1cba9abd9b3a9feef0b96b4
humanhash: mountain-montana-blossom-wolfram
File name:ShellHelper.exe
Download: download sample
Signature njrat
File size:851'592 bytes
First seen:2026-02-14 23:48:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 24576:vjoC4DmmxhlqCVKtbW8FWwhYHCJZ6ztRVq:vUc2Ktq8TECJZC8
TLSH T1BE058D3527A8691FC29F577CF0E21E3A53B0A4553422EB8F698859DD2E43384B4C17AF
TrID 27.0% (.EXE) Win64 Executable (generic) (6522/11/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.4% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter SquiblydooBlog
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
236
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
AgentTesla Obfuscar
Details
Obfuscar
decrypted strings
Malware family:
n/a
ID:
1
File name:
ComprovantesPDF.exe
Verdict:
Malicious activity
Analysis date:
2026-02-14 23:51:06 UTC
Tags:
screenconnect tool rmm-tool remote

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.9%
Tags:
injection obfusc micro
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file
Sending a custom TCP request
Verdict:
Clean
File Type:
exe x64
First seen:
2026-02-11T22:43:00Z UTC
Last seen:
2026-02-12T18:08:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
7 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.23 SOS: 0.25 SOS: 0.28 SOS: 0.29 SOS: 0.35 SOS: 0.38 Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-13 00:25:56 UTC
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
8ec809c41cba7fc6dabf56ddac952366deb68aba8288bbfe14431ee305d6ba3a
MD5 hash:
2d3976e1c1cba9abd9b3a9feef0b96b4
SHA1 hash:
3e704995da8f3cd414b80cb509446006628094d2
SH256 hash:
8bf0f2e8dadf3967757191c2212c269333ccd9d7e59839eea968212c64787be9
MD5 hash:
c583aa3819b16ae53859f728f59ea9a0
SHA1 hash:
b699e8e2cfc52bc3cfba182fdabfc7f6ff8f82de
SH256 hash:
ca03780217139b37f7f5b6921d59defb8d24988315b16b167a77fa88caa7d00f
MD5 hash:
eb254b04d63a9f03b77563243805f68f
SHA1 hash:
b01c83ec51f7a6548d1babb5e5ff8d5b944965a1
SH256 hash:
fcf493fc47a2f478a65303886b975fbdbf714cbb1f2d79f7fce97e4bb16b01a8
MD5 hash:
48867f392b8e77dc06c062638c6fbd36
SHA1 hash:
ccc0931e2cf3d6d79e24c1f28d9c96b40c131af6
SH256 hash:
f246e29921797b173b54229685e997a11f9cc388fa1e589c212328abd7a94ebe
MD5 hash:
3f5c79100f4f7902114c3fcba275c606
SHA1 hash:
cb874b2a2561239b5b1c30a49574229716f5f62d
SH256 hash:
618ef0e49d64e7a66dfe64bbf6ae81705b9d9683d8a9f321e5c3024d666bdf82
MD5 hash:
278ebb79da14ecf8e0559530c2fda076
SHA1 hash:
8a45f0400f6bc46d254120345fd5e39b6c9b71a1
SH256 hash:
749a01ebbb5edd8b1a03c5263b04de6acadecf52e4cc84d7412bc6e93f180958
MD5 hash:
faf1ba532964984a34d60674fbc7a5a7
SHA1 hash:
0999178949de510a47d87de3b8a117a003c572ee
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:Obfuscar
Author:kevoreilly
Description:Obfuscar xor routime
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments