| File name: | NjRat-0.7D-Green-Edition-SIGMASOFT-master.zip |
| Full analysis: | https://app.any.run/tasks/ed81a7ee-700d-408e-8c85-4037f8be01c0 |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | January 13, 2024, 20:02:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 96C131D98F96D3C190AB14486206132B |
| SHA1: | 7DFB425BD027831A96025F4C7010A7250E0397AD |
| SHA256: | 2F3B9845217E48C1DD0DAF32DB8981007F5964EC3D4CF24840229AB8F64FCF90 |
| SSDEEP: | 98304:8u2wPVwBPlvOKN7Zcpfv6uzWuNXXrk8LNyZ6jkPQ0bQsv/1/je9C3jXYCjNC6qly:NXyhH7f7 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 1980:01:01 00:00:00 |
| ZipCRC: | 0xffffffff |
| ZipCompressedSize: | 4294967295 |
| ZipUncompressedSize: | 4294967295 |
| ZipFileName: | NjRat-0.7D-Green-Edition-SIGMASOFT-master/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Users\admin\Documents\Server.exe" | C:\Users\admin\Documents\Server.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 128 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NjRat-0.7D-Green-Edition-SIGMASOFT-master.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 452 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1288 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\NjRat 0.7D Green Edition SIGMASOFT.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\NjRat 0.7D Green Edition SIGMASOFT.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: NjRat 0.7D Green Edition by im523 Exit code: 0 Version: 0.0.0.7 Modules
| |||||||||||||||
| 1424 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Documents\modelpicture.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2108 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.4.756863458\1369295226" -childID 3 -isForBrowser -prefsHandle 3660 -prefMapHandle 1612 -prefsLen 34336 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9c51de07-0c1b-438e-b01b-a2b2cc52efb4} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 3656 138486d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2156 | netsh firewall add allowedprogram "C:\ProgramData\server.exe" "server.exe" ENABLE | C:\Windows\System32\netsh.exe | — | server.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2160 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.7.181966184\14342203" -childID 6 -isForBrowser -prefsHandle 4184 -prefMapHandle 4164 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ac81edc7-d7d1-4c50-b81e-a0c23d474ea2} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 4172 190e9b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2228 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2380.5.1085965700\2141630143" -childID 4 -isForBrowser -prefsHandle 1636 -prefMapHandle 3864 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {72d0988e-8b8a-4a75-9658-180cf72c8236} 2380 "\\.\pipe\gecko-crash-server-pipe.2380" 3880 182f4e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2336 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe" /alignment=512 /QUIET "C:\Users\admin\AppData\Local\Temp\stub.il" /output:"C:\Users\admin\Documents\Server.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe | NjRat 0.7D Green Edition SIGMASOFT.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Framework IL assembler Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\mic.dll | executable | |
MD5:D4C5DDC00F27162FC0947830E0E762B7 | SHA256:B6FB6B66821E70A27A4750B0CD0393E4EE2603A47FEAC48D6A3D66D1C1CB56D5 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\ch.dll | executable | |
MD5:73C8A5CD64FCF87186A6A9AC870DF509 | SHA256:7722206DBA0CFB290F33093F9430CB770A160947001715AE11E6DBBFAEF1C0EE | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\plg.dll | executable | |
MD5:0CBC2D9703FEEAD9783439E551C2B673 | SHA256:EA9ECF8723788FEEF6492BF938CDFAB1266A1558DFFE75E1F78A998320F96E39 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMA SOFT.sln | text | |
MD5:7F94E0FB00C9562F3A4E75EB789B9B72 | SHA256:03F1B56DB0C2A75C7D08779A4177D699809E839F67AAABFD7781081DB737A1C0 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MyComputer.vb | text | |
MD5:C9717C1BAF9A83F104F229C4BA69E7C6 | SHA256:78FAF3CA541C78FBEA72B16EB6D3634CCB76EFC6A50E1FFE3CEA04C582C440CF | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\sc2.dll | executable | |
MD5:19967E886EDCD2F22F8D4A58C8EA3773 | SHA256:3E5141C75B7746C0EB2B332082A165DEACB943CEF26BD84668E6B79B47BDFD93 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\Plugin\pw.dll | executable | |
MD5:872401528FC94C90F3DE6658E776CC36 | SHA256:3A1CC072EFFD8C38406A6FDDF4D8F49C5366BB0E32071311D90DB669940987CE | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\Resources\Resources.vb | text | |
MD5:76861BB9FC9B5AC1BE6D83CBF351E8D6 | SHA256:D4F779A4A93820FD8B923FA53F898B9592E5B45542BF2AF8D4D06D3EFCA2B1CB | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MySettings.settings | xml | |
MD5:C9BDCCB5565BD459317380FAE14D1634 | SHA256:276C0F68FF287380AF1B934BFBE50B60A2FC35DB2AB20D63917629E1F029C5F5 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb128.14132\NjRat-0.7D-Green-Edition-SIGMASOFT-master\src\NjRat 0.7D Green Edition SIGMASOFT\My\MyApplication.vb | text | |
MD5:E7EA435EFDE50708788B14EDC0E4A09E | SHA256:19A1179804754E178B0C24409DD5D04F2DFD08EC554A0DB709A3F65280BF1929 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2380 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2380 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2380 | firefox.exe | POST | — | 184.24.77.61:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2380 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2380 | firefox.exe | 172.217.18.10:443 | safebrowsing.googleapis.com | — | — | whitelisted |
2380 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | unknown |
2380 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2380 | firefox.exe | 44.197.73.21:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2380 | firefox.exe | 184.24.77.61:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
2380 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
r3.o.lencr.org |
| shared |
firefox.settings.services.mozilla.com |
| whitelisted |
a1887.dscq.akamai.net |
| whitelisted |