njrat.exe

The executable njrat.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from malwr.com.
MD5:
6b65d58031845f290f2a109ead245ab4

SHA-1:
60054f5e08983c148808d0e90bb16d9852779c12

SHA-256:
72dbccd101da722c7d572f79efa7c65c87968dee6a444a3c27a9c12876a929d1

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/26/2024 7:37:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2593985
555

Avira AntiVirus
TR/Dropper.MSIL.174661
8.3.1.6

Arcabit
Trojan.Generic.D2794C1
1.0.0.425

AVG
Atros
2016.0.3033

Baidu Antivirus
Backdoor.Win32.Androm
4.0.3.15730

Bitdefender
Trojan.GenericKD.2593985
1.0.20.1055

Dr.Web
Trojan.DownLoader15.9402
9.0.1.0211

Emsisoft Anti-Malware
Trojan.GenericKD.2593985
8.15.07.30.02

ESET NOD32
MSIL/Kryptik.DAI (variant)
9.12002

Fortinet FortiGate
W32/Androm.DAI!tr
7/30/2015

F-Secure
Trojan.GenericKD.2593985
11.2015-30-07_5

G Data
Trojan.GenericKD.2593985
15.7.25

IKARUS anti.virus
Trojan.MSIL.Crypt
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.207.16698

Kaspersky
Backdoor.Win32.Androm
14.0.0.1659

Malwarebytes
Backdoor.DarkKomet.MSIL
v2015.07.30.02

McAfee
Artemis!6B65D5803184
5600.6689

Microsoft Security Essentials
Backdoor:Win32/Fynloski.K
1.1.11903.0

MicroWorld eScan
Trojan.GenericKD.2593985
16.0.0.633

nProtect
Backdoor/W32.Androm.449536.B
15.07.27.01

Panda Antivirus
Generic Suspicious
15.07.30.02

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Troj/MSIL-DTH
4.98

VIPRE Antivirus
Trojan.Win32.Generic
42382

ViRobot
Trojan.Win32.U.Agent.449536.B[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Kryptik.Win32.760776
2.0.0.2317

File size:
439 KB (449,536 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/24/2015 2:42:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:d51ZHokmD60tTgroWYrDfiY5vOpEVovXdmNa+mBV76w1sCeXLd3e/6MEi:vgO0tsro5Ph4mVovNmBIDeXLd386

Entry address:
0x4DB2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6465

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
303 KB (310,272 bytes)

The file njrat.exe has been seen being distributed by the following URL.

Remove njrat.exe - Powered by Reason Core Security