7f9da7d277b9bf41691f118cba5ad931e68194de17080102e8c39c34fafff367
Classification: Malicious
7f9da7d277b9bf41691f118cba5ad931e68194de17080102e8c39c34fafff367 is a malicious file sample. Linked to Njrat malware. Detected by 56 antivirus engines.
Detection summary
- 56 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 6 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: NJRAT (S0385)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 14:45:07 | 2026-09-02 14:45:07 | malicious-activity | |
| njrat | MalwareBazaar Abuse.ch | 2023-11-10 03:55:57 | 2023-11-10 03:55:57 | malicious-activity | S0385 njRAT |
Tags
evasive infostealerSample information
- Filenames
- 7f9da7d277b9bf41691f118cba5ad931e68194de17080102e8c39c34fafff367, 08f33348340885c6440c34af35550a91.exe
- File type
- application/x-dosexec
- MD5
08f33348340885c6440c34af35550a91- SHA-1
74c26b8b15c4fb126d8aa4749f142fb90343d24f- SHA-256
7f9da7d277b9bf41691f118cba5ad931e68194de17080102e8c39c34fafff367- First indexed
- 2023-11-10 04:20:19
- Last updated
- 2026-09-02 14:45:07
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.KillMBR.4!c |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Generic.KillMBR.B.5F627259 |
| CAT-QuickHeal | Trojan.YakbeexMSIL.ZZ4 |
| Skyhigh | BehavesLike.Win32.Ctsinf.dh |
| McAfee | GenericRXVS-PX!08F333483408 |
| Malwarebytes | Bladabindi.Backdoor.Bot.DDS |
| VIPRE | Generic.KillMBR.B.5F627259 |
| Sangfor | Suspicious.Win32.Save.a |
| K7AntiVirus | Trojan ( 700000121 ) |
| BitDefender | Generic.KillMBR.B.5F627259 |
| K7GW | Trojan ( 700000121 ) |
| Cybereason | malicious.b15c4f |
| BitDefenderTheta | Gen:NN.ZemsilF.36792.pqW@aCdIpJo |
| VirIT | Trojan.Win32.MSIL_Heur.B |
| Symantec | ML.Attribute.HighConfidence |
| tehtris | Generic.Malware |
| ESET-NOD32 | a variant of MSIL/Bladabindi.LX |
| APEX | Malicious |
| ClamAV | Win.Trojan.Killmbr-10004392-0 |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| Alibaba | Trojan:MSIL/Bladabindi.176d8504 |
| ViRobot | Trojan.Win.Z.Killmbr.252928.C |
| Rising | Backdoor.njRAT!1.9E49 (CLASSIC) |
| Sophos | Mal/Generic-S |
| Baidu | MSIL.Backdoor.Bladabindi.a |
| F-Secure | Trojan.TR/Dropper.Gen |
| TrendMicro | TROJ_GEN.R002C0PK523 |
| Trapmine | malicious.moderate.ml.score |
| FireEye | Generic.mg.08f33348340885c6 |
| Emsisoft | Generic.KillMBR.B.5F627259 (B) |
| Ikarus | Trojan.MSIL.Bladabindi |
| Jiangmin | Heur:Trojan/Agent |
| Detected | |
| Avira | TR/Dropper.Gen |
| Varist | W32/MSIL_Agent.FOV.gen!Eldorado |
| Antiy-AVL | Trojan/MSIL.Bladabindi |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Gridinsoft | Trojan.Win32.Bladabindi.sb!ni |
| Arcabit | Generic.KillMBR.B.5F627259 |
| ZoneAlarm | HEUR:Trojan.Win32.Generic |
| GData | Generic.KillMBR.B.5F627259 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win32.RL_Gen.C3638494 |
| ALYac | Generic.KillMBR.B.5F627259 |
| MAX | malware (ai score=88) |
| DeepInstinct | MALICIOUS |
| Cylance | unsafe |
| Panda | Trj/GdSda.A |
| TrendMicro-HouseCall | TROJ_GEN.R002C0PK523 |
| Tencent | Win32.Trojan.Generic.Cujl |
| SentinelOne | Static AI - Malicious PE |
| MaxSecure | Trojan.Malware.300983.susgen |
| AVG | Win32:RATX-gen [Trj] |
| Avast | Win32:RATX-gen [Trj] |
| CrowdStrike | win/malicious_confidence_100% (W) |
Network contacts
3.133.207.110 3.131.147.49 3.135.0.238 3.129.187.220 3.138.180.119 3.22.15.135