File name:

njRAT-0.8.0-LIME-EDITION-main.zip

Full analysis: https://app.any.run/tasks/89802dd2-d416-4e59-9c5b-83f28c2028ac
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: January 25, 2024, 09:12:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
njrat
bladabindi
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

13FF54CE26A0175FBA427BE4CEADABD5

SHA1:

81200C7DA7585E558147617D8E4F22790D8091D5

SHA256:

BD247718429E52D8E49D1F2C36E339BA7AE8451F6DD08E9E93A2ABE222DF2159

SSDEEP:

196608:4QgpIyptiJoKTZiuanQZAmZPKeLE+e9yhYOO:2plpti6Oi0Amce/e96YOO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2404)
      • ilasm.exe (PID: 2424)
      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • 123e43212343232.exe (PID: 3360)
    • NjRAT is detected

      • Client.exe (PID: 3656)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 3548)
    • Changes appearance of the Explorer extensions

      • Client.exe (PID: 3656)
    • NJRAT has been detected (YARA)

      • Client.exe (PID: 3656)
    • Changes the autorun value in the registry

      • Client.exe (PID: 3656)
  • SUSPICIOUS

    • Reads the Internet Settings

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • 123e43212343232.exe (PID: 3360)
    • Executable content was dropped or overwritten

      • ilasm.exe (PID: 2424)
      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • 123e43212343232.exe (PID: 3360)
    • Reads security settings of Internet Explorer

      • Client.exe (PID: 3656)
      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
    • Adds/modifies Windows certificates

      • 123e43212343232.exe (PID: 3360)
    • Checks Windows Trust Settings

      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 3656)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 3548)
      • Client.exe (PID: 1000)
    • Reads settings of System Certificates

      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 3656)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
      • Client.exe (PID: 1732)
    • Starts itself from another location

      • 123e43212343232.exe (PID: 3360)
    • Uses TASKKILL.EXE to kill process

      • Client.exe (PID: 3656)
      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
    • The process executes via Task Scheduler

      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2404)
    • Checks supported languages

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • wmpnscfg.exe (PID: 3012)
      • ilasm.exe (PID: 2424)
      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 3656)
      • Plugin Compiler.exe (PID: 2020)
      • Plugin Compiler.exe (PID: 2096)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
    • Reads the computer name

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • wmpnscfg.exe (PID: 3012)
      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 3656)
      • Plugin Compiler.exe (PID: 2020)
      • Plugin Compiler.exe (PID: 2096)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
    • Reads the machine GUID from the registry

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • 123e43212343232.exe (PID: 3360)
      • Client.exe (PID: 3656)
      • Plugin Compiler.exe (PID: 2020)
      • Plugin Compiler.exe (PID: 2096)
      • Client.exe (PID: 1732)
      • Client.exe (PID: 1000)
      • Client.exe (PID: 3548)
    • Creates files or folders in the user directory

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
    • Manual execution by a user

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • wmpnscfg.exe (PID: 3012)
      • 123e43212343232.exe (PID: 3360)
      • Plugin Compiler.exe (PID: 2020)
      • Plugin Compiler.exe (PID: 2096)
    • Reads Environment values

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • Client.exe (PID: 3656)
    • Create files in a temporary directory

      • NjRat Lime Edition 0.8.0.exe (PID: 2060)
      • 123e43212343232.exe (PID: 3360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

NjRat

(PID) Process(3656) Client.exe
C2127.0.0.1
Ports6522
BotnetLime
Options
Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\Client.exe
Splitter1
Version0.7.3
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:11:08 22:47:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: njRAT-0.8.0-LIME-EDITION-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
99
Monitored processes
31
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1000C:\Users\admin\AppData\Local\Temp\Client.exe C:\Users\admin\AppData\Local\Temp\Client.exe
taskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1220schtasks /Delete /tn NYAN /FC:\Windows\System32\schtasks.exeClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1348TASKKILL /F /IM cmd.exeC:\Windows\System32\taskkill.exeClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1732C:\Users\admin\AppData\Local\Temp\Client.exe C:\Users\admin\AppData\Local\Temp\Client.exe
taskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2020"C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\Plugin Compiler.exe" C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\Plugin Compiler.exeexplorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
NJRAT
Exit code:
0
Version:
7.0.0.0
Modules
Images
c:\users\admin\desktop\njrat-0.8.0-lime-edition-main\plugin compiler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2060"C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\NjRat Lime Edition 0.8.0.exe" C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\NjRat Lime Edition 0.8.0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
njRAT Lime Edition
Exit code:
0
Version:
0.8.0.0
Modules
Images
c:\users\admin\desktop\njrat-0.8.0-lime-edition-main\njrat lime edition 0.8.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2096"C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\Plugin Compiler.exe" C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main\Plugin Compiler.exeexplorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
NJRAT
Exit code:
0
Version:
7.0.0.0
Modules
Images
c:\users\admin\desktop\njrat-0.8.0-lime-edition-main\plugin compiler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2124TASKKILL /F /IM wscript.exeC:\Windows\System32\taskkill.exeClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2368schtasks /Delete /tn NYAN /FC:\Windows\System32\schtasks.exeClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2404"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\njRAT-0.8.0-LIME-EDITION-main.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
23 801
Read events
23 294
Write events
502
Delete events
5

Modification events

(PID) Process:(2404) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2060) NjRat Lime Edition 0.8.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
16
Suspicious files
3
Text files
26
Unknown types
0

Dropped files

PID
Process
Filename
Type
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\GeoIP.datbinary
MD5:A0A228C187329AD148F33C81DDB430BB
SHA256:B4BFD1EBC50F0EAAB3D3F4C2152FEAE7AA8EFAD380B85064153A6BFD006C6210
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (4).icoimage
MD5:CA33B28F5F6DDB6C8974FD78D1E167FE
SHA256:96AE6B12864258DA631D896E2AB1BA247957FF0DC45AA935AAD453C5447DFC42
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (6).icoimage
MD5:0C24EDEC606ABDA7C6570B7DCF439298
SHA256:8FC693238AFC49A8098DAC1762BFAE891E818BB84749C6EEF5F1B0C6C8FFDDB2
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (10).icoimage
MD5:ECED1DE1BF2067570510D36C6863BC53
SHA256:C3E80AC14CBC29CA45DA4BE38AF545988A3626F90C142F75D69552BADA6B26DD
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (2).icoimage
MD5:4EA9AB789F5AE96766E3F64C8A4E2480
SHA256:84B48CA52DFCD7C74171CF291D2EF1247C3C7591A56B538083834D82857FEE50
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (11).icoimage
MD5:8527B2D62C1A051A1E4A8DD8F6F3524D
SHA256:59DCB6C0FF03D989A50D94DE56091787CC99FF4F35B7D92D54D3093762F4CF61
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (1).icoimage
MD5:1C2CEA154DEEDC5A39DAEC2F1DADF991
SHA256:3B64B79E4092251EBF090164CD2C4815390F34849BBD76FB51085B6A13301B6D
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (13).icoimage
MD5:E8897B34F81D635ABA478737DC1EA06B
SHA256:2929C71FCCDD683B953E0A59A4EF21DF703D59E5D08D0BFA193EF078BFC90F25
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Icons\icon (12).icoimage
MD5:167425A3FA7114B1800AA903ADC35B2A
SHA256:12F600B09C0DB00877684A950FC14936ECC28DF8F0DDC6821D68E4B82077AD92
2404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2404.44145\njRAT-0.8.0-LIME-EDITION-main\Support\Media\Setup.mp4
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info