| File name: | Bluetooth discovery protocol installer.exe |
| Full analysis: | https://app.any.run/tasks/218b6fd7-93e5-4232-b88b-7d9458552a38 |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | February 17, 2024, 09:45:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D8EB4E7E6C1ED19C0F1E150239B70B45 |
| SHA1: | F4A03AD59F8D0685873139636F36CD65256A6F38 |
| SHA256: | 8BDA33F106E522AB0B51052A035FC32877A2F6EAD6E5E7293C7D9E006F69FCA6 |
| SSDEEP: | 12288:LwQcgCzNHJj96xfKJStJkRm3bYXob0AnmFMcaGQxUGRhhJhhf4i5+ghhJhhfk:LwfQKgLIQmFuGQxUGH4+k |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:03 07:51:19+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.33 |
| CodeSize: | 214528 |
| InitializedDataSize: | 153088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21d50 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | netsh firewall add allowedprogram "C:\ProgramData\Bluetooth discovery protocol servises.exe" "Bluetooth discovery protocol servises.exe" ENABLE | C:\Windows\System32\netsh.exe | — | Bluetooth discovery protocol servises.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1772 | "C:\Program Files\winrar\rar.exe" x -y"MrBeast.zip" *.* "UnRAR_MrBeasp\" | C:\Program Files\WinRAR\Rar.exe | Bluetooth discovery protocol servises.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: Command line RAR Exit code: 6 Version: 5.91.0 Modules
| |||||||||||||||
| 2472 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2668 | "C:\UnRAR_MrBeasp\cheat.exe" | C:\UnRAR_MrBeasp\cheat.exe | — | Bluetooth discovery protocol servises.exe | |||||||||||
User: admin Integrity Level: HIGH Description: MSBREASTTTTTTTTTTTTTTT Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2672 | "C:\ProgramData\Bluetooth discovery protocol servises.exe" | C:\ProgramData\Bluetooth discovery protocol servises.exe | Bluetooth discovery protocol.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
NjRat(PID) Process(2672) Bluetooth discovery protocol servises.exe C2photography-ringtones.gl.at.ply.gg Ports29246 Botnetdaunisse Options Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\85a3e0c53d2ca04334c15e929598abdc Splitter|'|'| Versionim523 | |||||||||||||||
| 2752 | "C:\Users\admin\Desktop\Bluetooth discovery protocol installer.exe" | C:\Users\admin\Desktop\Bluetooth discovery protocol installer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3536 | "C:\Users\admin\Desktop\Bluetooth discovery protocol installer.exe" | C:\Users\admin\Desktop\Bluetooth discovery protocol installer.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 4044 | "C:\Program Files\BluetoothDiscoveryProtocol\Bluetooth discovery protocol.exe" | C:\Program Files\BluetoothDiscoveryProtocol\Bluetooth discovery protocol.exe | Bluetooth discovery protocol installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (2752) Bluetooth discovery protocol installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
| (PID) Process: | (4044) Bluetooth discovery protocol.exe | Key: | HKEY_CURRENT_USER |
| Operation: | write | Name: | di |
Value: ! | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1772 | Rar.exe | C:\UnRAR_MrBeasp\beast.wav | — | |
MD5:— | SHA256:— | |||
| 2752 | Bluetooth discovery protocol installer.exe | C:\Program Files\BluetoothDiscoveryProtocol\service.dll | text | |
MD5:57A0A47FE8C851CAB4432759D69063F3 | SHA256:C0BC270A29B0A55C880FEE80E44D166585FADCAA2D650BB4B00F1A1872638C7A | |||
| 2752 | Bluetooth discovery protocol installer.exe | C:\Program Files\BluetoothDiscoveryProtocol\Bluetooth discovery protocol.exe | executable | |
MD5:87224038CE10EDB583CA8CDE83A5BE43 | SHA256:22EE66AE0E2F7708F70BD1AE76E8F5E743C9CEF30EFFD6D106E4BE837E9439D7 | |||
| 2752 | Bluetooth discovery protocol installer.exe | C:\Program Files\BluetoothDiscoveryProtocol\Discovery.dll | text | |
MD5:94722AB7604211632CF78931068ABEDD | SHA256:F127BB3290C09255049B884A316082AC00F89F37260040DB4853BCF2DC71FA43 | |||
| 2752 | Bluetooth discovery protocol installer.exe | C:\Program Files\BluetoothDiscoveryProtocol\protocol.dll | text | |
MD5:BA9366283F870640263C9FFFC5866C09 | SHA256:569F02E01607B913BC94BFA38852F307B9F8297F8B75D159AD9BAC821E249264 | |||
| 2752 | Bluetooth discovery protocol installer.exe | C:\Program Files\BluetoothDiscoveryProtocol\StartModule.dll | text | |
MD5:BA8F3EA48F08B9CF063CD4130BB71060 | SHA256:9EB309100CA112EFD6C166C30FB973C8705C435057A97A8BF5BCEB6F036F6A9D | |||
| 2672 | Bluetooth discovery protocol servises.exe | C:\MrBeast.zip | compressed | |
MD5:B477B55E3DD71A7A62C3535746475019 | SHA256:88DD2DEB2E552CDB052C3359C36AA559F560DAFD5510D7DAF0472D4C62987F36 | |||
| 4044 | Bluetooth discovery protocol.exe | C:\ProgramData\Bluetooth discovery protocol servises.exe | executable | |
MD5:87224038CE10EDB583CA8CDE83A5BE43 | SHA256:22EE66AE0E2F7708F70BD1AE76E8F5E743C9CEF30EFFD6D106E4BE837E9439D7 | |||
| 2672 | Bluetooth discovery protocol servises.exe | C:\Bluetooth discovery protocol installer.exe | executable | |
MD5:87224038CE10EDB583CA8CDE83A5BE43 | SHA256:22EE66AE0E2F7708F70BD1AE76E8F5E743C9CEF30EFFD6D106E4BE837E9439D7 | |||
| 1772 | Rar.exe | C:\UnRAR_MrBeasp\cheat.exe | executable | |
MD5:08BB6FA5A0A54030C55B6DC60601209F | SHA256:E5502FD83ED9ED24F535D8EC4D56AEF2FF647AEAB47661D7DE6797A24BB593A5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2672 | Bluetooth discovery protocol servises.exe | 147.185.221.18:29246 | photography-ringtones.gl.at.ply.gg | PLAYIT-GG | US | malicious |
Domain | IP | Reputation |
|---|---|---|
photography-ringtones.gl.at.ply.gg |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO playit .gg Tunneling Domain in DNS Lookup |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback (File Manager Actions) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |
2672 | Bluetooth discovery protocol servises.exe | Malware Command and Control Activity Detected | ET MALWARE njrat ver 0.7d Malware CnC Callback Response (Remote Desktop) |