File name:

njRAT v0.7d - NYANxCAT.zip

Full analysis: https://app.any.run/tasks/0af81d7d-c7ed-4563-91cc-280db91c2952
Verdict: Malicious activity
Analysis date: August 04, 2020, 10:06:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

82C7D22BA02A04DB64E1BC0E8F0BE8AA

SHA1:

0FB4218D05E671A59541F8910DF267CEF6EF07B6

SHA256:

00EF1CA313D70C30C0ED4724305612C33F367D73CE55AF9FF6F9E06546228568

SSDEEP:

24576:XHBS+ObH3zNiY+vV/se5MQuz1d19OQYOSIWoOfiYgsPy24fb1mUxMZ6:kDNQV/sAMkQYO2otsPK0fc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • njRAT v0.7d.exe (PID: 2300)
      • Builder.exe (PID: 1868)
    • Loads dropped or rewritten executable

      • njRAT v0.7d.exe (PID: 2300)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1380)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:03:10 01:43:04
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: njRAT v0.7d - NYANxCAT/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1380"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\njRAT v0.7d - NYANxCAT.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1868"C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Builder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1380.1315\njrat v0.7d - nyanxcat\builder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2300"C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exeWinRAR.exe
User:
admin
Company:
njq8
Integrity Level:
MEDIUM
Description:
njRAT
Exit code:
3221225547
Version:
0.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1380.47274\njrat v0.7d - nyanxcat\njrat v0.7d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
492
Read events
454
Write events
38
Delete events
0

Modification events

(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1380) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\njRAT v0.7d - NYANxCAT.zip
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
18
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Builder.exeexecutable
MD5:28B949C662B1EB00658D0837E3181979
SHA256:0D1CD7685A09E1ECB2712A35DF0A45362BB76AE15DB42159708E0A292CD2DAC8
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exeexecutable
MD5:CBAAC60496CA65CFAAFBB5088169EDE5
SHA256:759F58D5C856796BC8F42F7C549A9EC7B5BA7F5AAC9B4D5AA3671CE73251F3C7
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\GeoIP.datbinary
MD5:797B96CC417D0CDE72E5C25D0898E95E
SHA256:8A0675001B5BC63D8389FC7ED80B4A7B0F9538C744350F00162533519E106426
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\sc2.dllexecutable
MD5:D0B8C39D788598E5DBB0CE7231659278
SHA256:DB0C2826FCC34446E501D8905233AB14091EF7D54D221C7DFEFB24B453F142E2
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\plg.dllexecutable
MD5:236398B75D9874D847D5A6CE3099BE8A
SHA256:6F914E0F49DE7B84BC5B4E122AD6139E811257A26F59ED5A5790C54023EE38F3
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\mic.dllexecutable
MD5:A968455D3EE0E40371DE1B1312137DE4
SHA256:D1777036E63FDE518BC25C013194D2F8DDE67CE5B8E2AB05BBE22C455076AFB9
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\pw.dllexecutable
MD5:A3D739997EE168AC64C92F5469DF9D7D
SHA256:0696897F6AEF4F9C56F31215BA5B19BAC1151F7F62FB47C93A72B477C4DEE869
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exeexecutable
MD5:28B949C662B1EB00658D0837E3181979
SHA256:0D1CD7685A09E1ECB2712A35DF0A45362BB76AE15DB42159708E0A292CD2DAC8
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\cam.dllexecutable
MD5:705246C13732C41DADAAED9336328698
SHA256:4C24B93D5D3C5B2A8B73C7CA0E3EE1D5889FB9CA911AF689AA6EEEECAF4AC43B
1380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Plugin\ch.dllexecutable
MD5:E96D7122637263BD3E18A47B1D806DB1
SHA256:7F47E3F4AF42D44E8F006E6DD6B79EC7697C997771AF5C68CE38893E8DF8CE3B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info