MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a949a372d364a5043427eb1577c008168da96d8aaf6384169324c6826d579e2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a949a372d364a5043427eb1577c008168da96d8aaf6384169324c6826d579e2f
SHA3-384 hash: 7f1e25890ce7a9ddb3a379c84f6bae9ae17f0919c519c9f19d49484cbff3e93c7e3efe2d21a2227dbccd2b85cca96a80
SHA1 hash: f904b56825cc8a598c25875ae57b8a95af6362a4
MD5 hash: 8a09cba600a996625723035c84c0a267
humanhash: coffee-fillet-nitrogen-leopard
File name:a949a372d364a5043427eb1577c008168da96d8aaf6384169324c6826d579e2f
Download: download sample
Signature njrat
File size:110'080 bytes
First seen:2020-06-10 11:51:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 1536:r4MOq8NQU5UGE2BeJJuF4iz6SYgvmcPUSomKf:runyGE2GuSizHKrp
Threatray 127 similar samples on MalwareBazaar
TLSH 10B3320125AE347BE0778EB26BFAFEF1CAFCD923550BA179108052164736E03AC4D5E6
Reporter JAMESWT_WT
Tags:NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Casdet
Status:
Malicious
First seen:
2020-06-09 02:01:55 UTC
File Type:
PE (.Net Exe)
Extracted files:
13
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Drops desktop.ini file(s)
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments