Summary | ZeroBOX

njsirvorgroup.txt.exe

PE32 PE File .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 11, 2024, 3:58 p.m. Oct. 11, 2024, 4 p.m.
Size 26.5KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f8cfd88f0871e35b0e9ce296284dbfa7
SHA256 c12e2a13e38efaa69a3bab651cbc7256a5b48a522efd30319cfe9de8347f29f0
CRC32 FE9CEFB4
ssdeep 384:hLd6IGxVnZdgvnweeUHzCYe/OhY2OzRLTm3yilqr631bItVvGb:BBgnZdgfZT5e/MsE2VvGb
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
24.152.39.227 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 24.152.39.227
dead_host 24.152.39.227:4449
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Bladabindi.m!c
CAT-QuickHeal Trojan.Generic.TRFH1115
Skyhigh BehavesLike.Win32.Generic.mm
ALYac Generic.MSIL.Bladabindi.E88F6484
Cylance Unsafe
VIPRE Generic.MSIL.Bladabindi.E88F6484
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Generic.MSIL.Bladabindi.E88F6484
K7GW Trojan ( 700000121 )
K7AntiVirus Trojan ( 700000121 )
Arcabit Generic.MSIL.Bladabindi.E88F6484
Baidu MSIL.Backdoor.Bladabindi.a
VirIT Trojan.Win32.Genus.PRT
Symantec Backdoor.Ratenjay
Elastic Windows.Trojan.Njrat
ESET-NOD32 a variant of MSIL/Bladabindi.BC
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Win.Dropper.njRAT-10015886-0
Kaspersky HEUR:Backdoor.MSIL.SpyGate.gen
MicroWorld-eScan Generic.MSIL.Bladabindi.E88F6484
Rising Backdoor.njRAT!1.9E49 (CLASSIC)
Emsisoft Generic.MSIL.Bladabindi.E88F6484 (B)
F-Secure Trojan.TR/Dropper.Gen7
DrWeb BackDoor.BladabindiNET.27
Zillya Trojan.Bladabindi.Win32.145784
TrendMicro BKDR_BLADABI.SMC
McAfeeD Real Protect-LS!F8CFD88F0871
Trapmine malicious.high.ml.score
CTX exe.trojan.bladabindi
Sophos Troj/Bbindi-W
SentinelOne Static AI - Malicious PE
FireEye Generic.mg.f8cfd88f0871e35b
Google Detected
Avira TR/Dropper.Gen7
Kingsoft MSIL.Backdoor.SpyGate.gen
Microsoft Backdoor:MSIL/Bladabindi.B
ViRobot Backdoor.Win32.Bladabindi.Gen.A
ZoneAlarm HEUR:Backdoor.MSIL.SpyGate.gen
GData MSIL.Backdoor.Bladabindi.AV
Varist W32/MSIL_Agent.AQ.gen!Eldorado
AhnLab-V3 Malware/Win.SpyGate.R625845
McAfee BackDoor-FDNY!F8CFD88F0871
DeepInstinct MALICIOUS
VBA32 Trojan.MSIL.Bladabindi.Heur
Malwarebytes Bladabindi.Backdoor.Bot.DDS
Ikarus Backdoor.MSIL.NJRat
Panda Trj/GdSda.A