General

  • Target

    939255a91c0a2198e56d3f87286439bd.bin

  • Size

    55KB

  • MD5

    939255a91c0a2198e56d3f87286439bd

  • SHA1

    e4462da0c2f65765f210ce95931df0523b18a603

  • SHA256

    b4bab00a1266c3b688cfc811015c19b2cf06d14be7fd577cd2a2c7fee29a3a10

  • SHA512

    aab13ea30415a7f3a960f1bd1b9ec0d55a0633b2d09f88d6d26c266636705b9343d17f3f5ebc7a8caf66bc0f693237558e7dbc64287ec8b616bff8222021242b

  • SSDEEP

    768:jSDyFut1MankI2N9hi8QR3Q0kSNAmwFvfu0YMDHPsGL7XJSxI3pmam:jSy8Dn2N9hi8KdDVwsNMDFXExI3pmam

Score
10/10

Malware Config

Extracted

Family

njrat

Version

<- NjRAT 0.7d Horror Edition ->

Botnet

h2cKeD

C2

away-displays.gl.at.ply.gg:1144

Mutex

91725726f9142359c260345d5c3ac9ec

Attributes
  • reg_key

    91725726f9142359c260345d5c3ac9ec

  • splitter

    Y262SUCZ4UJJ

Signatures

  • Njrat family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 939255a91c0a2198e56d3f87286439bd.bin
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections