| File name: | njRAT v0.7d - NYANxCAT.zip |
| Full analysis: | https://app.any.run/tasks/0af81d7d-c7ed-4563-91cc-280db91c2952 |
| Verdict: | Malicious activity |
| Analysis date: | August 04, 2020, 10:06:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 82C7D22BA02A04DB64E1BC0E8F0BE8AA |
| SHA1: | 0FB4218D05E671A59541F8910DF267CEF6EF07B6 |
| SHA256: | 00EF1CA313D70C30C0ED4724305612C33F367D73CE55AF9FF6F9E06546228568 |
| SSDEEP: | 24576:XHBS+ObH3zNiY+vV/se5MQuz1d19OQYOSIWoOfiYgsPy24fb1mUxMZ6:kDNQV/sAMkQYO2otsPK0fc |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2020:03:10 01:43:04 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | njRAT v0.7d - NYANxCAT/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1380 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\njRAT v0.7d - NYANxCAT.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1868 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Builder Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2300 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exe | — | WinRAR.exe | |||||||||||
User: admin Company: njq8 Integrity Level: MEDIUM Description: njRAT Exit code: 3221225547 Version: 0.7.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\njRAT v0.7d - NYANxCAT.zip | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (1380) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Builder.exe | executable | |
MD5:28B949C662B1EB00658D0837E3181979 | SHA256:0D1CD7685A09E1ECB2712A35DF0A45362BB76AE15DB42159708E0A292CD2DAC8 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\njRAT v0.7d.exe | executable | |
MD5:CBAAC60496CA65CFAAFBB5088169EDE5 | SHA256:759F58D5C856796BC8F42F7C549A9EC7B5BA7F5AAC9B4D5AA3671CE73251F3C7 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\GeoIP.dat | binary | |
MD5:797B96CC417D0CDE72E5C25D0898E95E | SHA256:8A0675001B5BC63D8389FC7ED80B4A7B0F9538C744350F00162533519E106426 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\sc2.dll | executable | |
MD5:D0B8C39D788598E5DBB0CE7231659278 | SHA256:DB0C2826FCC34446E501D8905233AB14091EF7D54D221C7DFEFB24B453F142E2 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\plg.dll | executable | |
MD5:236398B75D9874D847D5A6CE3099BE8A | SHA256:6F914E0F49DE7B84BC5B4E122AD6139E811257A26F59ED5A5790C54023EE38F3 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\mic.dll | executable | |
MD5:A968455D3EE0E40371DE1B1312137DE4 | SHA256:D1777036E63FDE518BC25C013194D2F8DDE67CE5B8E2AB05BBE22C455076AFB9 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\pw.dll | executable | |
MD5:A3D739997EE168AC64C92F5469DF9D7D | SHA256:0696897F6AEF4F9C56F31215BA5B19BAC1151F7F62FB47C93A72B477C4DEE869 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Builder.exe | executable | |
MD5:28B949C662B1EB00658D0837E3181979 | SHA256:0D1CD7685A09E1ECB2712A35DF0A45362BB76AE15DB42159708E0A292CD2DAC8 | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.47274\njRAT v0.7d - NYANxCAT\Plugin\cam.dll | executable | |
MD5:705246C13732C41DADAAED9336328698 | SHA256:4C24B93D5D3C5B2A8B73C7CA0E3EE1D5889FB9CA911AF689AA6EEEECAF4AC43B | |||
| 1380 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1380.1315\njRAT v0.7d - NYANxCAT\Plugin\ch.dll | executable | |
MD5:E96D7122637263BD3E18A47B1D806DB1 | SHA256:7F47E3F4AF42D44E8F006E6DD6B79EC7697C997771AF5C68CE38893E8DF8CE3B | |||