Report - V2.exe

njRAT backdoor PhysicalDrive Generic Malware PE File .NET EXE PE32
ScreenShot
Created 2024.10.24 11:09 Machine s1_win7_x6401
Filename V2.exe
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score
11
Behavior Score
5.6
ZERO API file : clean
VT API (file) 61 detected (AIDetectMalware, lBQJ, TRFH796, Jalapeno, Unsafe, Save, malicious, confidence, 100%, Bladabindi, Attribute, HighConfidence, Windows, Njrat, CLASSIC, BladabindiNET, BLADABI, Real Protect, moderate, score, Bladab, Static AI, Malicious PE, Autoit, Detected, Gen7, atmn, Eldorado, Zapchast, FUTJ, Pabin, GdSda, susgen, RansomWare)
md5 1ddc055a8a01bd308f8241446643d642
sha256 feaee85a19690a9b85cc0aebb018d4f3915e9704ce27ce83547f74b6344bebac
ssdeep 1536:QUWNMDncNi9y6iRDIwsNMD0XExI3pmom:MNMDn9ULRDIwsNMD0XExI3pm
imphash f34d5f2d4577ed6d9ceec516c1f5a744
impfuzzy 3:rGsLdAIEK:tf
  Network IP location

Signature (12cnts)

Level Description
danger File has been identified by 61 AntiVirus engines on VirusTotal as malicious
watch A process attempted to delay the analysis task.
watch Looks for the Windows Idle Time to determine the uptime
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Created a process named as a common system process
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Drops a binary and executes it
notice Drops an executable to the user AppData folder
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (12cnts)

Level Name Description Collection
danger Win_Backdoor_njRAT_Zero Win Backdoor njRAT binaries (download)
danger Win_Backdoor_njRAT_Zero Win Backdoor njRAT binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (download)
warning Generic_Malware_Zero Generic Malware binaries (upload)
warning PhysicalDrive_20181001 (no description) binaries (download)
warning PhysicalDrive_20181001 (no description) binaries (upload)
info Is_DotNET_EXE (no description) binaries (download)
info Is_DotNET_EXE (no description) binaries (upload)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
away-displays.gl.at.ply.gg Unknown 147.185.221.20 clean

Suricata ids

PE API

IAT(Import Address Table) Library

mscoree.dll
 0x402000 _CorExeMain

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure