MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a586eb5233e14e5aaa61d1cbff1ec5a87c1323717fcbf79b55a88512744d5748. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a586eb5233e14e5aaa61d1cbff1ec5a87c1323717fcbf79b55a88512744d5748
SHA3-384 hash: bcf669144204787461164bf131adceb1f0396e1155f230ae6a845365195d9e311fbeeac26f00fa4f57b45e90a337c97b
SHA1 hash: 5be52f7fa76353533ad82addad501dbcc9e17021
MD5 hash: a349f206e36009a0807e803e802bd3a1
humanhash: helium-high-uncle-four
File name:uupnrgvX.exe
Download: download sample
Signature njrat
File size:32'768 bytes
First seen:2020-10-01 19:17:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 384:o0bUe5XB4e0XyOpySjgkM6WTstTUFQqz90Obbe:dT9BuxcSjeyqbe
Threatray 32 similar samples on MalwareBazaar
TLSH 1CE209467BA98215D6BC1AF88CB313110772E3478432EB6F5CDC88DA4B676D04295EFE
Reporter pmelson
Tags:exe NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Using the Windows Management Instrumentation requests
Sending a custom TCP request
Reading critical registry keys
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
80 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus / Scanner detection for submitted sample
Contains functionality to log keystrokes (.Net Source)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Njrat
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-10-01 19:19:05 UTC
AV detection:
28 of 29 (96.55%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Unpacked files
SH256 hash:
a586eb5233e14e5aaa61d1cbff1ec5a87c1323717fcbf79b55a88512744d5748
MD5 hash:
a349f206e36009a0807e803e802bd3a1
SHA1 hash:
5be52f7fa76353533ad82addad501dbcc9e17021
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

Executable exe a586eb5233e14e5aaa61d1cbff1ec5a87c1323717fcbf79b55a88512744d5748

(this sample)

Comments