MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc094a9cbf6b8e30b323d1b55d5b9a9a49c2d2ce34d48014540d00ea845fafe9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



njrat


Vendor detections: 22


Intelligence 22 IOCs 1 YARA 28 File information Comments

SHA256 hash: fc094a9cbf6b8e30b323d1b55d5b9a9a49c2d2ce34d48014540d00ea845fafe9
SHA3-384 hash: 03ccbc1b2012e26bb4eb478fa7e5c43f9aa850f69967ec95cb8b565099e6304f19ef5c89fafb377cd8adc0626bda69be
SHA1 hash: e095d3b85a18bd8dda63bfd1c12f60c02b812597
MD5 hash: 76d622a3a2f86e2a5e6217155a6ee1d4
humanhash: floor-west-twenty-cup
File name:tpmspoof.exe
Download: download sample
Signature njrat
File size:1'606'656 bytes
First seen:2026-04-24 02:35:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'131 x AgentTesla, 20'159 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:HyMPPZKL1YpDI8/WFCoanWgU6psHl2LPrA+YjIs2aTMpwoGcPAdjXbH:HyMPBKZ+skGd6pjLTA+w32asxg9r
TLSH T1F0751252F5A401F6D4AA81354D632F11B7B6F43A4720ABFB4B48584CBF63BA41D7AF80
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe NjRAT RAT


Avatar
abuse_ch
njrat C2:
8.148.70.23:13903

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
8.148.70.23:13903 https://threatfox.abuse.ch/ioc/1796954/

Intelligence


File Origin
# of uploads :
1
# of downloads :
252
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
tpmspoof.exe
Verdict:
Malicious activity
Analysis date:
2026-04-24 02:23:05 UTC
Tags:
auto-sch lofty loader phishing xworm rat njrat bladabindi

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
autorun emotet cobalt
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Launching a process
Forced system process termination
Сreating synchronization primitives
Enabling the 'hidden' option for files in the %temp% directory
Searching for synchronization primitives
DNS request
Running batch commands
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Creating a window
Creating a process with a hidden window
Launching the default Windows debugger (dwwin.exe)
Setting browser functions hooks
Unauthorized injection to a recently created process
Query of malicious DNS domain
Connection attempt to an infection source
Sending a TCP request to an infection source
Unauthorized injection to a system process
Unauthorized injection to a browser process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm asyncrat base64 lolbin msbuild obfuscated overlay packed packed reconnaissance soft-404 stealer unsafe windows xworm
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-04-23T23:32:00Z UTC
Last seen:
2026-04-24T11:02:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Spy.MSIL.KeyLogger.gen HEUR:Rootkit.Win64.Agent.gen BSS:Trojan.Win32.Generic Trojan.Win64.Kryplod.sb Trojan.MSIL.Disfa Trojan-Dropper.Win32.Agent.sb HEUR:Trojan.MSIL.Crypt.gen HEUR:Trojan-Spy.MSIL.Stealer.gen HEUR:Backdoor.MSIL.Bladabindi.gen Backdoor.MSIL.Crysan.d Trojan.Win64.Reflo.sb Trojan.MSIL.Crypt.sb HEUR:Trojan-Dropper.MSIL.Agent.gen VHO:Rootkit.Win64.r77.gen VHO:Rootkit.Win64.Convagent.gen HEUR:Trojan.Win32.Generic Backdoor.MSIL.Bladabindi.sb Backdoor.MSIL.Agent.sb Trojan.Win32.Agent.sb PDM:Trojan.Win32.Generic Trojan-PSW.Win32.Stealer.sb HEUR:Trojan.MSIL.Exnet.gen Trojan.Win64.Agent.smgbtd Trojan.Win32.Kryplod.sb Backdoor.Bladabindi.TCP.C&C Trojan-Dropper.Win32.Injector Backdoor.Agent.TCP.C&C
Result
Threat name:
Njrat, XWorm
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Contains functionality to compare user and computer (likely to detect sandboxes)
Contains functionality to inject code into remote processes
Contains functionality to log keystrokes (.Net Source)
Creates a thread in another existing process (thread injection)
Creates files in the system32 config directory
Disables zone checking for all users
Drops executables to the windows directory (C:\Windows) and starts them
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the prolog of user mode functions (user mode inline hooks)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential Privilege Escalation using Task Scheduler highest RunLevel
Sample uses string decryption to hide its real strings
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected Njrat
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1903772 Sample: tpmspoof.exe Startdate: 24/04/2026 Architecture: WINDOWS Score: 100 99 rentry.co 2->99 101 vcc-library.uk 2->101 103 7 other IPs or domains 2->103 133 Suricata IDS alerts for network traffic 2->133 135 Found malware configuration 2->135 137 Malicious sample detected (through community Yara rule) 2->137 141 19 other signatures 2->141 10 tpmspoof.exe 18 6 2->10         started        15 tpmspoof.exe 4 3 2->15         started        signatures3 139 Connects to a pastebin service (likely for C&C) 99->139 process4 dnsIp5 113 i.ibb.co 207.174.26.219, 443, 49715, 49723 RCN-ASUS United States 10->113 115 rentry.co 104.26.2.16, 443, 49716 CLOUDFLARENETUS United States 10->115 89 C:\Users\user\AppData\Local\...\tpm spoof.exe, PE32 10->89 dropped 91 C:\Users\user\AppData\...\gak4jr0j.k5m.exe, PE32+ 10->91 dropped 93 C:\Users\user\AppData\Local\...\Dominate.exe, PE32+ 10->93 dropped 161 Uses schtasks.exe or at.exe to add and modify task schedules 10->161 163 Potential Privilege Escalation using Task Scheduler highest RunLevel 10->163 165 Found direct / indirect Syscall (likely to bypass EDR) 10->165 17 gak4jr0j.k5m.exe 1 10->17         started        20 tpm spoof.exe 10->20         started        23 Dominate.exe 10->23         started        32 2 other processes 10->32 95 C:\Users\user\AppData\...\zqtlzw3b.gmc.exe, PE32+ 15->95 dropped 97 C:\Users\user\AppData\...\tpmspoof.exe.log, CSV 15->97 dropped 26 zqtlzw3b.gmc.exe 15->26         started        28 schtasks.exe 15->28         started        30 schtasks.exe 15->30         started        file6 signatures7 process8 dnsIp9 117 Antivirus detection for dropped file 17->117 119 Multi AV Scanner detection for dropped file 17->119 121 Contains functionality to inject code into remote processes 17->121 131 4 other signatures 17->131 34 lsass.exe 21 17->34 injected 38 winlogon.exe 17->38 injected 46 6 other processes 17->46 85 C:\Windows\WindowsServices.exe, PE32 20->85 dropped 87 C:\Tools.exe, PE32 20->87 dropped 123 Drops executables to the windows directory (C:\Windows) and starts them 20->123 40 WindowsServices.exe 20->40         started        109 keyauth.win 104.26.0.5, 443, 49719 CLOUDFLARENETUS United States 23->109 111 127.0.0.1 unknown unknown 23->111 42 cmd.exe 23->42         started        44 cmd.exe 23->44         started        48 4 other processes 23->48 125 Injects code into the Windows Explorer (explorer.exe) 26->125 127 Writes to foreign memory regions 26->127 129 Allocates memory in foreign processes 26->129 50 8 other processes 26->50 52 2 other processes 32->52 file10 signatures11 process12 dnsIp13 105 e7.c.lencr.org 104.18.20.213, 49722, 80 CLOUDFLARENETUS United States 34->105 143 Creates files in the system32 config directory 34->143 145 Writes to foreign memory regions 34->145 147 Unusual module load detection (module proxying) 34->147 107 6.tcp.cpolar.top 8.148.70.23, 13903, 49752 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd Singapore 40->107 149 Antivirus detection for dropped file 40->149 151 Disables zone checking for all users 40->151 153 Uses netsh to modify the Windows network and firewall settings 40->153 155 Modifies the windows firewall 40->155 54 netsh.exe 40->54         started        157 Suspicious powershell command line found 42->157 56 cmd.exe 42->56         started        59 cmd.exe 44->59         started        61 cmd.exe 48->61         started        63 certutil.exe 48->63         started        65 find.exe 48->65         started        67 find.exe 48->67         started        69 WerFault.exe 50->69         started        signatures14 process15 signatures16 71 conhost.exe 54->71         started        159 Suspicious powershell command line found 56->159 73 conhost.exe 56->73         started        75 powershell.exe 56->75         started        77 conhost.exe 59->77         started        79 powershell.exe 59->79         started        81 conhost.exe 61->81         started        83 timeout.exe 61->83         started        process17
Verdict:
XBinder
YARA:
12 match(es)
Tags:
.Net Crypter Executable Loader Malicious Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.21 SOS: 0.82 Win 32 Exe x86 XBinder XBinder Variant XRijMut Loader
Threat name:
Win32.Trojan.XWormRAT
Status:
Malicious
First seen:
2026-04-24 02:23:10 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
23 of 24 (95.83%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
r77rootkit nightcoreloader
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:njrat family:xworm bootkit defense_evasion discovery execution persistence privilege_escalation rat trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Enumerates connected drives
Writes to the Master Boot Record (MBR)
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Indicator Removal: Clear Windows Event Logs
Command and Scripting Interpreter: PowerShell
Modifies Windows Firewall
Sets service image path in registry
Detect Xworm Payload
Family: Xworm
Family: njRAT/Bladabindi
Suspicious use of NtCreateUserProcessOtherParentProcess
Unpacked files
SH256 hash:
fc094a9cbf6b8e30b323d1b55d5b9a9a49c2d2ce34d48014540d00ea845fafe9
MD5 hash:
76d622a3a2f86e2a5e6217155a6ee1d4
SHA1 hash:
e095d3b85a18bd8dda63bfd1c12f60c02b812597
SH256 hash:
2595ea3244b80ec866b5402a244b2389769935ea915d4363d00969bacad6e62b
MD5 hash:
8a16320af56bb97dffe5ccb340078906
SHA1 hash:
8d196ac26a218d8b7c945df76169f68e216f79bb
Detections:
win_njrat_g1 win_njrat_w1 NjRat Njrat MAL_Winnti_Sample_May18_1 CN_disclosed_20180208_c win_njrat_strings_oct_2023 MALWARE_Win_NjRAT
SH256 hash:
01aa278b07b58dc46c84bd0b1b5c8e9ee4e62ea0bf7a695862444af32e87f1fd
MD5 hash:
2d8e4f38b36c334d0a32a7324832501d
SHA1 hash:
f6f11ad2cd2b0cf95ed42324876bee1d83e01775
SH256 hash:
d8e59f05370be2015f2e0ec76d466602e2016afc4fff1e65a52a54623ab241fd
MD5 hash:
67a8c9c4775cb2ee0a61fb162daf0bb6
SHA1 hash:
269602952537b4a226e26f5ac19647763639bdca
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercês
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:MALWARE_Win_R77
Author:ditekSHen
Description:Detects r77 rootkit
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Runtime_Broker_Variant_1
Author:Sn0wFr0$t
Description:Detecting malicious Runtime Broker
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Suspicious_PssCaptureSnapshot_Usage
Author:Dana Behling - Just me not for personal curiosity, no company.
Description:Detects binaries abusing PssCaptureSnapshot in combination with typical combination that indicates malicious activity.
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Rootkit_R77_be403e3c
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit
Rule name:Windows_Rootkit_R77_d0367e28
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/elastic-security-labs-steps-through-the-r77-rootkit

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments