MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 928b41b877a3c51a26431c21a478b8c4a9ce75cd02fb22fe2432847a13beaf1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
njrat
Vendor detections: 11
| SHA256 hash: | 928b41b877a3c51a26431c21a478b8c4a9ce75cd02fb22fe2432847a13beaf1f |
|---|---|
| SHA3-384 hash: | e39eecaff6266a55ef90d09fa4576eb279836e7385217dbff50f74c395cda9cce139972d89ece929e9179937a54b7673 |
| SHA1 hash: | 2613a316f5cb6dc70ff6fda27b1a6a27b6986c55 |
| MD5 hash: | 3839845e48928dc6b8cc660185c53ca6 |
| humanhash: | venus-wisconsin-wyoming-william |
| File name: | EDP-SX.exe |
| Download: | download sample |
| Signature | njrat |
| File size: | 10'150'280 bytes |
| First seen: | 2022-04-19 20:29:57 UTC |
| Last seen: | 2022-04-20 10:25:51 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat) |
| ssdeep | 196608:LywBReOKN9p4RJ/wdL5kE7dZTtYls2rvqrSp7aGNxhiXcJ/OAt:APW3/wdL17ztYCvrSp7H7h7mAt |
| Threatray | 1'510 similar samples on MalwareBazaar |
| TLSH | T146A63321FAC5EAB6E2B01C7912EDE70135797C2017204DFB67985F6EA3244C157A2AF3 |
| TrID | 32.2% (.EXE) Win64 Executable (generic) (10523/12/4) 20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 13.7% (.EXE) Win32 Executable (generic) (4505/5/1) 6.2% (.EXE) OS/2 Executable (generic) (2029/13) |
| File icon (PE): | |
| dhash icon | 9494b494d4aeaeac (832 x DCRat, 172 x RedLineStealer, 134 x CryptOne) |
| Reporter | |
| Tags: | exe hacktool lime NjRAT RAT SecurityXploded |
Intelligence
File Origin
# of uploads :
7
# of downloads :
471
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
SecurityXploded
ID:
1
File name:
(пароль 1234)njRAT L.rar
Verdict:
Malicious activity
Analysis date:
2022-01-21 23:32:44 UTC
Tags:
trojan SecurityXploded loader rat backdoor dcrat
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Unauthorized injection to a recently created process
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
greyware overlay packed setupapi.dll shdocvw.dll shell32.dll update.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
njRAT
Verdict:
Malicious
Result
Threat name:
Njrat
Detection:
malicious
Classification:
troj.evad
Score:
96 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Njrat
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2022-03-07 21:22:23 UTC
File Type:
PE (Exe)
Extracted files:
1030
AV detection:
28 of 42 (66.67%)
Threat level:
5/5
Verdict:
malicious
Similar samples:
+ 1'500 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
8/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Unpacked files
SH256 hash:
a9ca2fa0764be47755047550816c5f2d363f7868989e274582b62cd76c7d93d7
MD5 hash:
a946171cb13634851ed49c96309438e6
SHA1 hash:
f799b48243b7c62a6aeb4fedc17f7b6d9c9519e7
SH256 hash:
feb5893562b2e9805ba324fa5d5af290090dad21253078a08ae33ce0f31d99ee
MD5 hash:
97c0ab201a7a3fdda3804b64de107aef
SHA1 hash:
ec76b2341beb14db01310ec31e3613cb9c9db8e1
SH256 hash:
0328d00722a947499c460521478883eaef3a6a107682983f6ae98a114f59060e
MD5 hash:
77cf847aafd1c81fda58ec7ba10395b4
SHA1 hash:
a01c3fd4686c53be52583e6fc79ffbe9d96e1492
SH256 hash:
509c4faf431b3b0a6a499e1b39c539c3f142e697c4147406b1cf834c92a724c0
MD5 hash:
5da23188a14c6aa9447c1322ce9d465c
SHA1 hash:
982b27b1ea004560036972a71dcd93b5d441b78c
SH256 hash:
968f0e0135dd06753962f41baef33b6d23809b757410f21b2d19cddf06c001fd
MD5 hash:
34c04939d0f3420479f2044893daef6a
SHA1 hash:
91ec1f9e791a1c09ed8728e629e9c51f571cc9f2
SH256 hash:
34c7ccd850f70b08f943bdf4f3ae461052bdb980149e32706531402300b02d43
MD5 hash:
6ead43ef629405611e029c4989b07d52
SHA1 hash:
6255b3c93e4b5d9f6248e8f1bdc8c38970ffa772
SH256 hash:
ecb8c9e3c61665d9db1200611db8eaebf6d7e82c64deafafc23611c125d5eb74
MD5 hash:
bccdff1368ab2a6770f67f9fd90cc213
SHA1 hash:
5b93ebfc01b7eec663413c0f18da146c56de770d
SH256 hash:
928b41b877a3c51a26431c21a478b8c4a9ce75cd02fb22fe2432847a13beaf1f
MD5 hash:
3839845e48928dc6b8cc660185c53ca6
SHA1 hash:
2613a316f5cb6dc70ff6fda27b1a6a27b6986c55
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.