MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc6e92d0ce0c483e3f31547c8c9c85e74c3da4d50476b894b3f116903ebe18c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bc6e92d0ce0c483e3f31547c8c9c85e74c3da4d50476b894b3f116903ebe18c4
SHA3-384 hash: c1d2c4dda89faa3e821734e898bd4353f67607cde5814b5d140d994d5541640b635f860c6166be2fc12ebc3abee34bb4
SHA1 hash: 039e86fdcd1a831bc2e1f559fbd1fdc59a852e89
MD5 hash: b07ec93cae7883be9766c0d273333dcf
humanhash: ceiling-glucose-hot-neptune
File name:PDF455667442.img
Download: download sample
Signature njrat
File size:520'192 bytes
First seen:2020-10-23 17:35:59 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:zRwrpjMiMhXazWhonJztTqzx8dRCAJ7bWORThyYNnTXg9k7Z5+viO53PB/Il7HSp:OTMBYRnG18B79TNXgOZ4viOBPNIl7GF
TLSH E3B4E01031D42BA1D6BE4BF6143C920A83B7784F1A75D65C2DAD36EE1B91F018B64FA3
Reporter abuse_ch
Tags:img NjRAT RAT


Avatar
abuse_ch
Malspam distributing njrat:

HELO: countrywoods.co.za
Sending IP: 45.138.172.120
From: Gerard Bouman <sales@countrywoods.co.za>
Reply-To: Gerard Bouman <sales@countrywoods.co.za>
Subject: RE:
Attachment: PDF455667442.img (contains "k6aRShSGVN5Y56m.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
145
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-23 17:04:28 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

njrat

img bc6e92d0ce0c483e3f31547c8c9c85e74c3da4d50476b894b3f116903ebe18c4

(this sample)

  
Dropping
njrat
  
Delivery method
Distributed via e-mail attachment

Comments