🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb6ed91616f9c3fd1132e86f44c61a2661d229bebebefa2470d3f655726e80ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: bb6ed91616f9c3fd1132e86f44c61a2661d229bebebefa2470d3f655726e80ce
SHA3-384 hash: a70f9a596b6e27d683793173a230784ddbf86f352ec8def56b1992d64decb6d1a126ba5dbcf869b70af76e1d69e5ea13
SHA1 hash: 77cac33b01214cf0e9a09bfd18dcf73741fba986
MD5 hash: 2c0150f1a78ba9448687dc98f92fbe2a
humanhash: snake-bravo-wyoming-gee
File name:WORKXREPORTXFORXYOURXFILLINGXANDXSUBMITTINGXSCAN0012XPDF.rar
Download: download sample
Signature njrat
File size:662'411 bytes
First seen:2026-05-21 14:40:18 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:P0pTLEPkwIo584q9kEvKoUOXPjtCDVu2Ly39Q8aXBjqdPmYwF5DTT5+C15F:PgnEPQoax9FvKVOX5CVlZFDV915F
TLSH T1A9E4233C59C348711D54E01E4A6FE4A2C88F5ABAB18D8FDE2968F536B3C6127428EDD4
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:NjRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
CH CH
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:Rockendes.Pot
File size:55'351 bytes
SHA256 hash: 5a14f9c07c8a4e4bd81a2dfef920c89710c485e586a61aa5bfac114cb59ab61d
MD5 hash: 6c421a79202dba8fc10120783680cb3a
MIME type:text/plain
Signature njrat
File name:uddelegeringer.twe
File size:449'546 bytes
SHA256 hash: 375447a7ee0c0a3e866d5cb556b3041cb092cfa57060bb4e88b06cbee144c46d
MD5 hash: 893fcc5be4db26ad2fc207ac1fd8ed3d
MIME type:application/octet-stream
Signature njrat
File name:lenene.cul
File size:386'186 bytes
SHA256 hash: 70bbb413de07322ae218c25428fd41fc322a17c5275d8bd1543f9fece93944ab
MD5 hash: b72e06cc44c5298b5eced7fa0e22e0e3
MIME type:application/octet-stream
Signature njrat
File name:WORK REPORT FOR YOUR FILLING AND SUBMITTING SCAN0012 PDF.com
File size:924'706 bytes
SHA256 hash: 3c63a3c0670132e07fb90ca3c29ba35d898f6293bd40619a5611cb705e8b8212
MD5 hash: cccaef3434bb48fa765a2025ab21770a
MIME type:application/x-dosexec
Signature njrat
File name:Rooing.txt
File size:325 bytes
SHA256 hash: a23f4a95953c1e56d3b79c347e3df446515c67605d305ba60aaa818ae0003553
MD5 hash: 0e5c24aa1659c57af66b4bb57a95ffe8
MIME type:text/plain
Signature njrat
File name:Nordamerikaneren.hyl
File size:339'413 bytes
SHA256 hash: 767eee9d2c6333be28a8bbe5668bcba1f5cf3735e32788d5653025ae9ffb9b6d
MD5 hash: 31d13fb9ec191a2eb8ac575fa8799d31
MIME type:application/octet-stream
Signature njrat
File name:Flashbulb.Ind
File size:342'728 bytes
SHA256 hash: 5e3c0e890e251408517162cb8097c192b8f64067f6efe56cec6a3bb91d6b7ee4
MD5 hash: 2b62d69e9f7f67883f6e0b932c837144
MIME type:application/octet-stream
Signature njrat
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.1%
Tags:
injection obfusc virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm encrypted evasive evasive fingerprint installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance smb
Verdict:
Malicious
File Type:
rar
First seen:
2025-09-19T07:53:00Z UTC
Last seen:
2026-05-21T12:57:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-05-21 16:04:37 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 23 (73.91%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:guloader discovery downloader execution persistence
Behaviour
Modifies registry key
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Family: Guloader,Cloudeye
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

njrat

rar bb6ed91616f9c3fd1132e86f44c61a2661d229bebebefa2470d3f655726e80ce

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments