MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2706b773b93aef6fed4f0937f9b2d790c17575779df7dc5221322fb8979e2fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 14


Intelligence 14 IOCs 1 YARA 8 File information Comments

SHA256 hash: a2706b773b93aef6fed4f0937f9b2d790c17575779df7dc5221322fb8979e2fb
SHA3-384 hash: 46e503dc71a14fded990ecd35a0aa0749a7274a88e6e18f470342527d2f51f1c49f06b346d358818393ce8ab37accd95
SHA1 hash: 98e33dfaa9f6cb93168e665076491131717261d8
MD5 hash: a16940d8c3a85d6583aa5428b3210852
humanhash: emma-wolfram-angel-alabama
File name:a16940d8c3a85d6583aa5428b3210852.exe
Download: download sample
Signature njrat
File size:1'763'328 bytes
First seen:2025-07-04 07:40:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'070 x AgentTesla, 20'027 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 24576:K/zg2/k63qQZ5Egdzor1C3YNJ7r0QuVpdLEradgprtd4BgMb222r51lRhsFk8IYo:KMgk63Cg4xnTsAudgxH6b12a3IcSEmD
TLSH T1F685021D6F4B8E7ACBC92D7D85A36C2083A868453672D91FBF4523F236116E2EC13794
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10522/11/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon ccde4c4d6cc89898 (2 x njrat, 1 x AsyncRAT)
Reporter abuse_ch
Tags:exe NjRAT RAT


Avatar
abuse_ch
njrat C2:
104.207.138.98:1177

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
104.207.138.98:1177 https://threatfox.abuse.ch/ioc/1553100/

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
bladabindi crimsonrat autorun njrat
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Searching for synchronization primitives
Сreating synchronization primitives
Creating a window
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 crypt cryptor_detected net_reactor obfuscated obfuscated packed packed vbnet
Result
Threat name:
Njrat, PureLog Stealer
Detection:
malicious
Classification:
phis.troj.adwa.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to log keystrokes (.Net Source)
Creates autostart registry keys with suspicious names
Disables zone checking for all users
Drops PE files to the startup folder
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Protects its processes via BreakOnTermination flag
Suricata IDS alerts for network traffic
Uses netsh to modify the Windows network and firewall settings
Yara detected Njrat
Yara detected PureLog Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1728631 Sample: ZKbPKO9qEj.exe Startdate: 04/07/2025 Architecture: WINDOWS Score: 100 33 ronymahmoud.casacam.net 2->33 37 Suricata IDS alerts for network traffic 2->37 39 Found malware configuration 2->39 41 Malicious sample detected (through community Yara rule) 2->41 43 11 other signatures 2->43 9 ZKbPKO9qEj.exe 1 7 2->9         started        12 centrume.exe 5 2->12         started        14 centrume.exe 4 2->14         started        16 centrume.exe 4 2->16         started        signatures3 process4 file5 29 C:\Users\user\AppData\Roaming\centrume.exe, PE32 9->29 dropped 31 C:\Users\user\AppData\...\ZKbPKO9qEj.exe.log, ASCII 9->31 dropped 18 centrume.exe 4 5 9->18         started        process6 dnsIp7 35 ronymahmoud.casacam.net 104.207.138.98, 1177, 49721 AS-CHOOPAUS United States 18->35 27 C:\...\61388842c37176392ad84a15a2b5ffe4.exe, PE32 18->27 dropped 45 Antivirus detection for dropped file 18->45 47 Multi AV Scanner detection for dropped file 18->47 49 Protects its processes via BreakOnTermination flag 18->49 51 5 other signatures 18->51 23 netsh.exe 2 18->23         started        file8 signatures9 process10 process11 25 conhost.exe 23->25         started       
Verdict:
Malware
YARA:
8 match(es)
Tags:
.Net .Net Obfuscator .Net Reactor CAB:COMPRESSION:MSZIP CAB:COMPRESSION:NONE Executable PE (Portable Executable) Win 32 Exe x86
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-07-01 11:39:12 UTC
File Type:
PE (.Net Exe)
Extracted files:
18
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:njrat defense_evasion discovery persistence privilege_escalation trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
Adds Run key to start application
Checks computer location settings
Drops startup file
Executes dropped EXE
Modifies Windows Firewall
Njrat family
njRAT/Bladabindi
Verdict:
Malicious
Tags:
njrat Bladabindi
YARA:
n/a
Unpacked files
SH256 hash:
a2706b773b93aef6fed4f0937f9b2d790c17575779df7dc5221322fb8979e2fb
MD5 hash:
a16940d8c3a85d6583aa5428b3210852
SHA1 hash:
98e33dfaa9f6cb93168e665076491131717261d8
SH256 hash:
bcf3a521c6cb71c6ab3a1f3e8eda1473ad1e7645c249bacf6bc8d0ce97c950c8
MD5 hash:
af7f255442ae52a2d29aebf0fc20eb1a
SHA1 hash:
141292fdefe391b47d9c00fca85b43f09e503919
SH256 hash:
6339207987b676b89f85f7f384fc0aff208fb275abff89e691915f3f334e1028
MD5 hash:
2dfc0c196a3b77fced9278cd10ba9e5b
SHA1 hash:
cc59a73d309987319e470d924252e1fba92eff40
Detections:
CN_disclosed_20180208_c Njrat win_njrat_bytecodes_oct_2023 win_njrat_strings_oct_2023 MALWARE_Win_NjRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_EXE_Packed_DotNetReactor
Author:ditekSHen
Description:Detects executables packed with unregistered version of .NET Reactor
Rule name:Lumma_Stealer_Detection
Author:ashizZz
Description:Detects a specific Lumma Stealer malware sample using unique strings and behaviors
Reference:https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments