| File name: | NjRat Builder.7z |
| Full analysis: | https://app.any.run/tasks/9ed9de7f-4dfe-4f25-b02b-b77a01b029e0 |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | December 29, 2023, 12:36:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | B80CD3589E08AB120E4CADED272EDCD9 |
| SHA1: | C288255C0E171476974D26D53B508B13710672C0 |
| SHA256: | 41542DFC3594967B151C43E18FCE9194B656AB0B6EADA7F4C3C126A5A3EC2197 |
| SSDEEP: | 98304:MMtGs/pGWxyfx6LIaANx4ttsafu6bayPlsvMl2FACv0pVuorPltbTIspT+y19A3+:zQ6/PSw |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\NjRat Builder.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1192 | "C:\Users\admin\AppData\Local\Temp\server.exe" | C:\Users\admin\AppData\Local\Temp\server.exe | Server.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
NjRat(PID) Process(1192) server.exe C2127.0.0.1 Ports5552 BotnetHacKed Options Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\f8782a013a20610e09216f21b705d856 Splitter|'|'| Versionim523 | |||||||||||||||
| 1636 | "C:\Users\admin\Desktop\BuilderNjRat\NjRat.07d\NjRat 0.7D Green Edition by im523.exe" | C:\Users\admin\Desktop\BuilderNjRat\NjRat.07d\NjRat 0.7D Green Edition by im523.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: NjRat 0.7D Green Edition by im523 Exit code: 0 Version: 0.0.0.7 Modules
| |||||||||||||||
| 1956 | "C:\Users\admin\Desktop\Server.exe" | C:\Users\admin\Desktop\Server.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2508 | netsh firewall add allowedprogram "C:\Users\admin\AppData\Local\Temp\server.exe" "server.exe" ENABLE | C:\Windows\System32\netsh.exe | — | server.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2568 | "C:\Users\admin\Desktop\BuilderNjRat\njRAT v0.7\njRAT v0.7d.exe" | C:\Users\admin\Desktop\BuilderNjRat\njRAT v0.7\njRAT v0.7d.exe | — | explorer.exe | |||||||||||
User: admin Company: njq8 Integrity Level: MEDIUM Description: njRAT Exit code: 3221225547 Version: 0.7.0.0 Modules
| |||||||||||||||
| 2672 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe" /alignment=512 /QUIET "C:\Users\admin\AppData\Local\Temp\stub.il" /output:"C:\Users\admin\Desktop\Server.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe | — | NjRat 0.7D Green Edition by im523.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Framework IL assembler Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 3060 | taskkill /F /IM Exsample.exe | C:\Windows\System32\taskkill.exe | — | server.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3096 | shutdown -l -t 00 | C:\Windows\System32\shutdown.exe | — | server.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Shutdown and Annotation Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3244 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1636) NjRat 0.7D Green Edition by im523.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.6.4\stub.il | text | |
MD5:1B92496B750A26F2450E34500A2C4215 | SHA256:A1B65F18C7E882B1606A4EF9387D8988E6FD755D7D03214B677AD528A487D73A | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\NjRat.07d\README.md | text | |
MD5:D621EF72336F55A09C80B055A91DD13D | SHA256:4B55045ACC6B7CFE93341DEB62283DAF14EC4C4E7F13DEF8E40E02FA2B3A97CC | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.5.0\stubSRC.rar | compressed | |
MD5:64F49FA1111B4D0894012422EEB0DCE6 | SHA256:9A418406FDC61F98E9CFBA6C2BC5B34FB139DF2E97B6F60E2879C13220D374B0 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.6.4\Map\1416662483.jpg | image | |
MD5:5756169F9E385DD7F0A90C43CD050034 | SHA256:842F230B004DC7744A1B885E00ADBC6737E5DD4A695BC2531C848ABE0ECA97A8 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.6.4\Stub.manifest | xml | |
MD5:4D18AC38A92D15A64E2B80447B025B7E | SHA256:835A00D6E7C43DB49AE7B3FA12559F23C2920B7530F4D3F960FD285B42B1EFB5 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.7\stub.il | text | |
MD5:2041E64BFFCCFBC9379235FDF294F188 | SHA256:DAA4362A762A472F717A480102883382B41DC5C17484F649272C5BDB5142917C | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\njRAT v0.7\Stub.manifest | xml | |
MD5:4D18AC38A92D15A64E2B80447B025B7E | SHA256:835A00D6E7C43DB49AE7B3FA12559F23C2920B7530F4D3F960FD285B42B1EFB5 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\NjRat.07d\Sound\Sound.wav | binary | |
MD5:562FB3B4B1B1EAFD2CF107F2E92E0670 | SHA256:5FF592B183B2C990448F1DCD842A29CFE17A3EAA9956E0135C945C578676344A | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\NjRat.07d\.gitignore | text | |
MD5:F4D61F06FF1F26F8A4BFD8CE606936CF | SHA256:FDC17FD35182CA77A4888C8682F48BA5B57463CA5865B96EB8A652BA15C63664 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.39718\BuilderNjRat\NjRat.07d\GeoIP.dat | binary | |
MD5:797B96CC417D0CDE72E5C25D0898E95E | SHA256:8A0675001B5BC63D8389FC7ED80B4A7B0F9538C744350F00162533519E106426 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3244 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 314 b | unknown |
3244 | iexplore.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b760a1c8c8f99fe1 | unknown | compressed | 4.66 Kb | unknown |
3244 | iexplore.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5343d09680a02013 | unknown | compressed | 4.66 Kb | unknown |
3244 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3244 | iexplore.exe | 104.126.37.186:443 | www.bing.com | Akamai International B.V. | DE | unknown |
3244 | iexplore.exe | 184.24.77.194:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3244 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3244 | iexplore.exe | 152.199.19.161:443 | r20swj13mr.microsoft.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |