General

  • Target

    NiggaSploit v1.1.zip

  • Size

    3.6MB

  • MD5

    46b5336768498576875608a716ff6adb

  • SHA1

    b0e0f67b31cb90caa31385ca711ccf17dd51a7d3

  • SHA256

    93b7f43c2aba1ad9fb899a0cde6f22f582e4b2bea351430964af9c9363156c09

  • SHA512

    8fccd8cdaa387869a8c099239278bc3745956328ce55f68631895c05a05b22b9c7e916d696f61e1bff030dbc1a30303a0377d3ab7457ef951d5b2ac1484ce9f1

  • SSDEEP

    49152:TpEdoMyNLzWHgy+aoV55LoiOS9dxlZUJuTEMcr3yOBs3bWs8/SSOGhWKiqsYrFII:O+dzWHuhlDOmEMxksrW6nxKiUsqZdz

Score
10/10

Malware Config

Signatures

  • AgentTesla payload 1 IoCs
  • Agenttesla family
  • .NET Reactor proctector 1 IoCs

    Detects an executable protected by an unregistered version of Eziriz's .NET Reactor.

  • Unsigned PE 7 IoCs

    Checks for missing Authenticode signature.

Files

  • NiggaSploit v1.1.zip
    .zip
  • Release/CeleryAPIR.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Release/CeleryIn.bin
    .dll windows:6 windows x64 arch:x64

    fe78118d64d767d704fee2343d26ea59


    Headers

    Imports

    Exports

    Sections

  • Release/CeleryInject.exe
    .exe windows:6 windows x64 arch:x64

    d7247aa724e6b937c13a261291749f05


    Headers

    Imports

    Sections

  • Release/EvolveAPI.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Release/Flux.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Release/Flux.xml
    .xml
  • Release/Guna.UI2.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Release/Microsoft.Web.WebView2.Core.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Release/Microsoft.Web.WebView2.Core.xml
    .js .xml polyglot
  • Release/Microsoft.Web.WebView2.WinForms.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Release/Microsoft.Web.WebView2.WinForms.xml
    .xml
  • Release/Microsoft.Web.WebView2.Wpf.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Release/Microsoft.Web.WebView2.Wpf.xml
    .xml
  • Release/Monaco/Monaco.html
    .js
  • Release/Monaco/debug.log
  • Release/Monaco/vs/MonacoNet.dll
    .dll windows:6 windows x86 arch:x86

    785d680cbd472fae503fd72ce14d28cb


    Headers

    Imports

    Sections

  • Release/Monaco/vs/base/worker/workerMain.js
    .js
  • Release/Monaco/vs/basic-languages/lua/lua.js
  • Release/Monaco/vs/editor/contrib/suggest/media/String_16x.svg
  • Release/Monaco/vs/editor/contrib/suggest/media/String_inverse_16x.svg
  • Release/Monaco/vs/editor/editor.main.css
  • Release/Monaco/vs/editor/editor.main.js
    .js
  • Release/Monaco/vs/editor/editor.main.nls.de.js
  • Release/Monaco/vs/editor/editor.main.nls.es.js
  • Release/Monaco/vs/editor/editor.main.nls.fr.js
  • Release/Monaco/vs/editor/editor.main.nls.it.js
  • Release/Monaco/vs/editor/editor.main.nls.ja.js
  • Release/Monaco/vs/editor/editor.main.nls.js
  • Release/Monaco/vs/editor/editor.main.nls.ko.js
  • Release/Monaco/vs/editor/editor.main.nls.ru.js
  • Release/Monaco/vs/editor/editor.main.nls.zh-cn.js
  • Release/Monaco/vs/editor/editor.main.nls.zh-tw.js
  • Release/Monaco/vs/editor/standalone/browser/quickOpen/symbol-sprite.svg
  • Release/Monaco/vs/loader.js
    .js
  • Release/Siticone.UI.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Release/UIRemake.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • Release/UIRemake.exe.config
    .xml
  • Release/UIRemake.pdb
  • Release/autoexec (does not work)/yay.txt
  • Release/runtimes/win-arm64/native/WebView2Loader.dll
  • Release/runtimes/win-x64/native/WebView2Loader.dll
    .dll windows:10 windows x64 arch:x64

    f6946d311bccc86e2042a388e375de41


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Release/runtimes/win-x86/native/WebView2Loader.dll
    .dll windows:10 windows x86 arch:x86

    72229ff546c74d09d9030ca49ce61b31


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Release/version.txt