MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2c42c7641fcae4a61d7e6c183b06f9f828bd337f08ecba9f97033556540e52b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 19


Intelligence 19 IOCs YARA 5 File information Comments

SHA256 hash: f2c42c7641fcae4a61d7e6c183b06f9f828bd337f08ecba9f97033556540e52b
SHA3-384 hash: 77d3e50317aa75115bf4903a3a6448ab050e0209a7d89350e53ffe39fed514600d182025b18ddb6017957f7553938479
SHA1 hash: 5f4743958bfcd27ea81a1dbefb2910d3bcd45733
MD5 hash: 2cbd959c38fb466998473f8e5c2110f7
humanhash: double-gee-washington-alpha
File name:chromedriver.exe
Download: download sample
Signature njrat
File size:2'468'864 bytes
First seen:2026-04-08 17:53:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'074 x AgentTesla, 20'032 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 49152:k+DQS54uk9F8ktHgkcC7GSdHKC88Ro3m18m0Ar:k+DD4t9jTRo3q8Q
TLSH T154B533314A930924FC55A4B71BB3E2930E4DF426FD87424E6168E9AE7317E7279293F0
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter BlinkzSec
Tags:NjRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
CZ CZ
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
https://178.16.55.23/chromedriver.exe
Verdict:
Malicious activity
Analysis date:
2026-04-08 13:43:48 UTC
Tags:
rat evasion quasar remote stealer xworm

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
asyncrat autorun quasar bobik
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a process with a hidden window
DNS request
Creating a file in the %AppData% directory
Creating a process from a recently created file
Using the Windows Management Instrumentation requests
Creating a window
Launching a process
Unauthorized injection to a recently created process
Query of malicious DNS domain
Connection attempt to an infection source
Sending a TCP request to an infection source
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
infostealer packed reconnaissance stealer vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-03-30T07:19:00Z UTC
Last seen:
2026-04-10T04:08:00Z UTC
Hits:
~100
Detections:
VHO:Trojan.MSIL.Convagent.gen Trojan-PSW.Win32.Coins.sb HEUR:Trojan-Banker.MSIL.ClipBanker.gen Trojan-PSW.MSIL.Agent.sb Trojan.MSIL.Agent.sb HEUR:Trojan-PSW.Win32.Agent.gen HEUR:Trojan-Dropper.MSIL.FrauDrop.gen HEUR:Backdoor.MSIL.XClient.b Backdoor.MSIL.Crysan.fb Trojan.MSIL.Dnoper.sb Trojan-PSW.MSIL.Stealer.sb HEUR:Trojan-Spy.MSIL.Agent.sb Backdoor.MSIL.VenomRAT.a HEUR:Trojan-PSW.MSIL.Stealer.gen Backdoor.MSIL.XWorm.b VHO:Backdoor.Win32.Agent.gen Trojan.Win32.Vimditator.sb Trojan-GameThief.MSIL.Worgtop.b HEUR:Trojan.Win32.Generic Backdoor.MSIL.XWorm.a Trojan.Win32.Quasar.sb Trojan.MSIL.Quasar.a Backdoor.Agent.TCP.C&C Trojan.Win32.Agent.sb Trojan-PSW.Win32.Stealer.sb HEUR:Trojan-Spy.MSIL.Bobik.gen HEUR:Backdoor.MSIL.XWorm.gen BSS:Trojan.Win32.Generic Trojan-GameThief.Win32.Worgtop.f Trojan-Banker.Win32.Express.sb VHO:Trojan.MSIL.Tasker.gen HEUR:Trojan.MSIL.Agent.gen
Verdict:
inconclusive
YARA:
11 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.21 Win 32 Exe x86
Threat name:
Win32.Trojan.XWormRAT
Status:
Malicious
First seen:
2026-03-31 05:52:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
29 of 36 (80.56%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:quasar family:xorium_stealer family:xworm botnet:office04 discovery execution persistence rat spyware stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Adds Run key to start application
Checks computer location settings
Drops startup file
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Contains code to disable Windows Defender
Detect Xworm Payload
Detects XoriumStealer payload
Quasar RAT
Quasar family
Quasar payload
XoriumStealer
Xorium_stealer family
Xworm
Xworm family
Malware Config
C2 Extraction:
shroom010.duckdns.org:1602
178.16.55.23:1605
178.16.55.23:1602
Unpacked files
SH256 hash:
f2c42c7641fcae4a61d7e6c183b06f9f828bd337f08ecba9f97033556540e52b
MD5 hash:
2cbd959c38fb466998473f8e5c2110f7
SHA1 hash:
5f4743958bfcd27ea81a1dbefb2910d3bcd45733
SH256 hash:
c7cc6758dbc32c39df99b96cc99f7469c803219fede45a9f185fdfa9578342d1
MD5 hash:
8e023cb39ccf36e131172b61dba5adea
SHA1 hash:
375f9693c3fd6c9b33a8f3af8e14e127d3b849c4
Detections:
win_xworm_w0 win_xworm_a0 XWorm win_mal_XWorm INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA MALWARE_Win_AsyncRAT MALWARE_Win_XWorm
SH256 hash:
a39ba1cdde1b131c48711ffeb3691f4b8f58a44d49bad2b835bea2894b878a48
MD5 hash:
7f568f80a61705cc67429e1479773d3c
SHA1 hash:
9bc881820e4ea5e2f1baa4adf4d1eff70bdb67d4
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
561b1970908ac5b02af626ff8ea2bb4d74f3b14b2afcb1bc0be60bead48166c7
MD5 hash:
eea85ddc7733a08c4929ff079ec2ce07
SHA1 hash:
a0e3565889ce5c3243c75c83cd789955cf1320bd
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
d5eabf48d3ddcac258c3e9bdfbc843f1972cd5a9f1d8201e16ec11d90239266e
MD5 hash:
dbcff879a1c7d8941af585df09427efe
SHA1 hash:
9efddb88935abed81d6cdb84f4e6cd0c3d8773bb
Detections:
win_masslogger_w0 QuasarRAT cn_utf8_windows_terminal malware_windows_xrat_quasarrat MAL_QuasarRAT_May19_1 win_quasarrat_j2 win_quasar_rat_client INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients INDICATOR_SUSPICIOUS_GENInfoStealer INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA INDICATOR_SUSPICIOUS_Binary_Embedded_Crypto_Wallet_Browser_Extension_IDs MALWARE_Win_QuasarStealer
SH256 hash:
9aee3a3654eb745efc7bfa3aec1131461055861926524e3ebf7601f478235a99
MD5 hash:
5501ac18ce26079090a3f0aaec1d87ba
SHA1 hash:
93d842c4c9bad5300547b593e66dadadc74cc864
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
3c5bc84a1b1902c2ba28c122958c32fe8593333711f4e0c6c6d2e24e0e340d8c
MD5 hash:
0de921654d0f8aad582267a2687291f6
SHA1 hash:
bbd9427172e7683501a702c2c54feaa07dfde464
Detections:
win_xworm_a0 win_xworm_w0 XWorm win_mal_XWorm INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA MALWARE_Win_AsyncRAT MALWARE_Win_XWorm
SH256 hash:
c76d4c911574218273af1aea8e584f8ee3cc354b5c8bc2bf308c25084dbe75fa
MD5 hash:
7b0a528fb626e8eeb8f54ff1d74bd32d
SHA1 hash:
a39a5b034d92230b7f3c26ee08d5b34acbdd24bd
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

njrat

Executable exe f2c42c7641fcae4a61d7e6c183b06f9f828bd337f08ecba9f97033556540e52b

(this sample)

  
Delivery method
Distributed via web download

Comments