MALICIOUS — 939_njRAT-v0.6.4.bin
MALICIOUS — 939_njRAT-v0.6.4.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Bladabindi family. 3 of 36 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
fd624aa205517580e83fad7a4ce4d64863e95f62b34ac72647b1974a52822199 - SHA-1:
e9ff4da7e3f2199cbc16d37d8935cb1b0567ac2a - MD5:
0431311b5f024d6e66b90d59491f2563 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:+O9vE3J7JO+xEPuc//9wivAmv6SAbnzmip2hGnadlFM4ZHOT2:+eXuczPCSGnzVjad1 - TLSH:
T1A7526EA94F35E212C4E258B23DF9498E204A15B5D719989C82FCD62F62DCF3BA133171 - Submitted as: 939_njRAT-v0.6.4.bin
- File type: pe · Size: 982016 bytes
- Verdict: malicious (99/100) · Family: Bladabindi
Detections (3 of 36 engines)
- capa (capabilities): execute via PowerShell
- ClamAV (daily): Win.Packed.Bladabindi-7086597-0
- Cyble Vision: Cyble Vision: njRAT
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Packed.Bladabindi-7086597-0 (rule
Win.Packed.Bladabindi-7086597-0) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: njRAT (rule
Cyble Vision: njRAT) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://twitter.com/njq8 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://twitter.com/njq8
- http://www.w3.org/2001/XMLSchema-instance
Embedded domains
- twitter.com
- system.io
- system.net
- myapplication.app
- www.w3.org
- zaaptoo.zapto.org
Embedded IP addresses
- 4.0.0.0
- 2.0.0.0
- 8.0.0.0
- 9.0.0.0
- 0.6.4.0
- 1.0.0.0
- 10.0.0.0
- 6.0.0.0
File paths
- C:\Users\algha_000\AppData\Local\Temporary
More Bladabindi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report