MALICIOUS — 932_njRAT-v0.6.4.bin
MALICIOUS — 932_njRAT-v0.6.4.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the MSILHeracles family. 4 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
fde583027a692d210e8f1f73667fa0037705128ade8bbfbc9b780f019ead6672 - SHA-1:
d55533b20bda5c865f1e48561e497bf36c577097 - MD5:
f4a19d968ff6f5af1601b97f1756d6e3 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
6144:0nKBmP1NE/VdJXjTe8LKeIFQ1A2GCWqjo6fiM0lGJiIE0kyuuUJ:9Bi1+RjKreDAuxScJiIE0kfl - TLSH:
T186492BDC05FCBA79C4F09A236910DBEC5D9628CB647679DC1AC9B2325298F3B8835017 - Submitted as: 932_njRAT-v0.6.4.bin
- File type: pe · Size: 417280 bytes
- Verdict: malicious (84/100) · Family: MSILHeracles
Detections (4 of 52 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: Backdoor:MSIL/Bladabindi!rfn
- Emsisoft (Emergency Kit): Gen:Variant.MSILHeracles.1852
- Kaspersky (KVRT): Backdoor.MSIL.Bladabindi.avp
MITRE ATT&CK
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Backdoor:MSIL/Bladabindi!rfn (rule
Backdoor:MSIL/Bladabindi!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.MSILHeracles.1852 (rule
Gen:Variant.MSILHeracles.1852) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
47 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- inference.location.live.net
- desktop-hsgcbep
- ctldl.windowsupdate.com
- login.live.com
- v10.events.data.microsoft.com
- config.edge.skype.com
- www.bing.com
- windows.msn.com
- officeclient.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- dns.msftncsi.com
- watson.events.data.microsoft.com
- msedge.api.cdp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- tas02.sls.update.microsoft.com
- edge.microsoft.com
- assets.msn.com
- aefd.nelreports.net
Embedded domains
- this.name
- inference.location.live.net
- aefd.nelreports.net
Embedded IP addresses
- 162.159.36.2
More MSILHeracles samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report