Behavioral task
behavioral1
Sample
e61eed96def408b119e90903e3eb6744de28ebe8707227c1d11d82d9dd2dc643.exe
Resource
win7-20240611-en
General
-
Target
e61eed96def408b119e90903e3eb6744de28ebe8707227c1d11d82d9dd2dc643
-
Size
489KB
-
MD5
44760b49c001c67749e2ca1eae3fc253
-
SHA1
d55904227bf350a2824db27df52e79c853cd7ac0
-
SHA256
e61eed96def408b119e90903e3eb6744de28ebe8707227c1d11d82d9dd2dc643
-
SHA512
8d0560cf61938e8cbb4c4f92b2a008780344ebdcc8650df8611a598bf0df9b5352e894482fb4a50c412c6de4378c23f5894701e7d2f965edace091b0412ff36a
-
SSDEEP
6144:n3C9BRo7tvnJ9oH0IRgZvjkUo7tvnJ9oH0IiVByq9CPobNVj:n3C9ytvngQjgtvngSV3CPobNVj
Malware Config
Signatures
-
Njrat family
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource e61eed96def408b119e90903e3eb6744de28ebe8707227c1d11d82d9dd2dc643
Files
-
e61eed96def408b119e90903e3eb6744de28ebe8707227c1d11d82d9dd2dc643.exe windows:4 windows x86 arch:x86
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Sections
Size: 47KB - Virtual size: 156KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
petite Size: 274B - Virtual size: 274B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ