🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf4b978e6be3f062ed2c294227d65fd25b54c970bd1db11838dfc44401edcae7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 9


Intelligence 9 IOCs YARA 19 File information Comments

SHA256 hash: cf4b978e6be3f062ed2c294227d65fd25b54c970bd1db11838dfc44401edcae7
SHA3-384 hash: 8fce74c8fc26997999d7a0e9904982dea8d6527c69445bafa9ca83519984dbbc11afe5c925e49f40c6299ad43a2472cc
SHA1 hash: 34ad953796c9e4ca0d9f0876132ad5996f666f5b
MD5 hash: fd0a8c06e481207ec7db7e3c17f1c425
humanhash: may-summer-salami-oranges
File name:Wbb52.76432.7.exe
Download: download sample
Signature njrat
File size:72'006'094 bytes
First seen:2025-04-25 05:16:56 UTC
Last seen:2025-04-25 05:17:52 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 49c6751b0096c4e59525d8a85cde6f39 (1 x njrat)
ssdeep 786432:qEuN80UTtldlE6lgT2wUytvD/WGiAAtRni2nPa6dLlHuVW7d1kMuLq4BR:qEuNgd/lgTtNvKGiAAtd3TdL/ABBR
TLSH T13EF7DF116EAC8725E415C1BCDAD506315630BC013B5007AB31BCF65AFF76BFA782AE89
TrID 56.8% (.EXE) InstallShield setup (43053/19/16)
13.8% (.EXE) Win64 Executable (generic) (10522/11/4)
8.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.9% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter zhuzhu0009
Tags:backdoor exe NjRAT SilverFox winos

Intelligence


File Origin
# of uploads :
2
# of downloads :
578
Origin country :
RU RU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Wbb52.76432.7.exe
Verdict:
No threats detected
Analysis date:
2025-04-25 05:18:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
shellcode cobalt small micro
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt to an infection source
Creating a file
Enabling the 'hidden' option for recently created files
Creating a file in the Windows subdirectories
Creating a process from a recently created file
Query of malicious DNS domain
Sending a TCP request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
action adaptive-context anti-vm anti-vm entropy evasive expand explorer fingerprint fingerprint keylogger lolbin microsoft_visual_cc njrat njrat overlay overlay packed packed packer_detected rat remote rundll32 squirrel update wuauclt
Result
Threat name:
GhostRat, Nitol
Detection:
malicious
Classification:
evad.troj
Score:
100 / 100
Signature
Adds extensions / path to Windows Defender exclusion list (Registry)
Antivirus detection for dropped file
Changes security center settings (notifications, updates, antivirus, firewall)
Creates an undocumented autostart registry key
Detected unpacking (creates a PE file in dynamic memory)
Disables security and backup related services
Drops PE files to the document folder of the user
Found direct / indirect Syscall (likely to bypass EDR)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
Sample is not signed and drops a device driver
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Costura Assembly Loader
Yara detected GhostRat
Yara detected Nitol
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1673795 Sample: Wbb52.76432.7.exe Startdate: 25/04/2025 Architecture: WINDOWS Score: 100 94 wu22wu.oss-cn-beijing.aliyuncs.com 2->94 96 upitem.oss-cn-hangzhou.aliyuncs.com 2->96 98 6 other IPs or domains 2->98 110 Suricata IDS alerts for network traffic 2->110 112 Malicious sample detected (through community Yara rule) 2->112 114 Antivirus detection for dropped file 2->114 116 12 other signatures 2->116 10 5havZX.exe 25 2->10         started        15 Wbb52.76432.7.exe 1 24 2->15         started        17 5havZX.exe 2->17         started        19 12 other processes 2->19 signatures3 process4 dnsIp5 106 sc-2pyl.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com 118.178.60.98, 443, 49703, 49704 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 10->106 82 C:\Program Files (x86)\95Kyif\XPSPLOG.dll, PE32 10->82 dropped 84 C:\Program Files (x86)\95Kyif\95Kyif.exe, PE32 10->84 dropped 86 C:\Users\Public\Music\destopbak.ini, MIPSEB 10->86 dropped 130 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 10->130 132 Found direct / indirect Syscall (likely to bypass EDR) 10->132 21 95Kyif.exe 10->21         started        26 cmd.exe 1 10->26         started        28 cmd.exe 1 10->28         started        36 3 other processes 10->36 108 wu22wu.oss-cn-beijing.aliyuncs.com 59.110.190.23, 443, 49694, 49695 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 15->108 88 C:\Windows\Temp\aceprocted.sys, PE32+ 15->88 dropped 90 C:\Users\user\Documents\eToken.dll, PE32+ 15->90 dropped 92 C:\Users\user\Documents\5havZX.exe, PE32+ 15->92 dropped 134 Drops PE files to the document folder of the user 15->134 136 Sample is not signed and drops a device driver 15->136 138 Tries to detect virtualization through RDTSC time measurements 15->138 140 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 17->140 142 Changes security center settings (notifications, updates, antivirus, firewall) 19->142 144 Uses cmd line tools excessively to alter registry or file data 19->144 30 reg.exe 1 1 19->30         started        32 reg.exe 1 1 19->32         started        34 reg.exe 1 1 19->34         started        38 9 other processes 19->38 file6 signatures7 process8 dnsIp9 100 47.239.134.206, 49711, 8379 CHARTER-20115US United States 21->100 102 sc-29h5.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com 118.178.60.103, 443, 49712 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 21->102 104 gqsqoq.net 3.33.130.190, 9011 AMAZONEXPANSIONGB United States 21->104 78 C:\Program Files (x86)\21CJ8992i\dg31tO.exe, PE32 21->78 dropped 80 C:\Program Files (x86)\...\XPSPLOG.dll, PE32 21->80 dropped 118 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 21->118 120 Creates an undocumented autostart registry key 21->120 122 Disables security and backup related services 21->122 40 cmd.exe 21->40         started        42 cmd.exe 21->42         started        44 cmd.exe 21->44         started        46 cmd.exe 21->46         started        124 Uses cmd line tools excessively to alter registry or file data 26->124 126 Uses schtasks.exe or at.exe to add and modify task schedules 26->126 48 conhost.exe 26->48         started        52 3 other processes 26->52 54 4 other processes 28->54 128 Adds extensions / path to Windows Defender exclusion list (Registry) 30->128 56 12 other processes 36->56 50 conhost.exe 38->50         started        file10 signatures11 process12 process13 58 net.exe 40->58         started        60 conhost.exe 40->60         started        62 sc.exe 40->62         started        64 conhost.exe 42->64         started        66 schtasks.exe 42->66         started        68 schtasks.exe 42->68         started        70 schtasks.exe 42->70         started        74 2 other processes 44->74 72 conhost.exe 46->72         started        process14 76 net1.exe 58->76         started       
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-04-25 05:18:25 UTC
File Type:
PE+ (Exe)
Extracted files:
101
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
link pdf
Behaviour
Suspicious behavior: EnumeratesProcesses
Verdict:
Malicious
Tags:
Win.Malware.Qukart-10016013-0 ta_abused_service
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:PECompactv2xx
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:ScanStringsInsocks5systemz
Author:Byambaa@pubcert.mn
Description:Scans presence of the found strings using the in-house brute force method
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::WriteConsoleA
KERNEL32.dll::SetConsoleCtrlHandler
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleOutputCP
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileMappingA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::RemoveDirectoryA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegDeleteKeyA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegQueryValueA
ADVAPI32.dll::RegSetValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageA
USER32.dll::CreateWindowExA

Comments