{"id":1518,"date":"2024-03-04T11:34:31","date_gmt":"2024-03-04T11:34:31","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1518"},"modified":"2024-04-22T12:48:13","modified_gmt":"2024-04-22T12:48:13","slug":"trojan-win32-njrat","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/03\/04\/trojan-win32-njrat\/","title":{"rendered":"Trojan.Win32.NJrat"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Malware Name(s)<\/strong><\/h3>\n<ul>\n<li>Trojan.Win32.NJrat (Padvish)<\/li>\n<li>A Variant Of MSIL\/Bladabindi.AS (ESET-NOD32)<\/li>\n<li>Backdoor.MSIL.Bladabindi.AJ (Kaspersky)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>What is trojan?<\/strong><\/h3>\n<p>Trojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of damage to the computer system.<br \/>\nThere are different ways in which trojans could enter the system, some are: Entering through a software downloaded from the Internet, embedding in HTML text, attaching to an email, etc.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is NJRat Malware?<\/strong><\/h3>\n<p>NJRat, also known as a Remote Access Trojan (RAT), is a malware designed to infiltrate systems to steal sensitive information and spy on victims. Its capabilities are accessing the victim&#8217;s webcam, microphone, system files, and capturing keystrokes (keylogging).<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Technical Review<\/strong><\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>NJRat malware manifests in various versions, each with distinctive indicators of compromise (IoCs). Common signs (IoCs) include:<\/p>\n<p>\u2705Creation of specific registry keys upon execution, such as:<\/p>\n<p><span style=\"color: #0000ff\">HKU\\[SID]\\Environment\\SEE_MASK_NOZONECHECKS: &#8220;1&#8221;<\/span><\/p>\n<p><span style=\"color: #0000ff\">\u00a0..\u201dHKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\[RandomNumber]: \u201c\u201dPathToExe<\/span><\/p>\n<p><span style=\"color: #0000ff\">HKLM\\SYSTEM\\CurrentControlSet\\services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\[RandomValueName]\\\u201dv2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=PathToExe<\/span><br \/>\n<span style=\"color: #0000ff\">\u201c|Name=ExeName.exe|<\/span><\/p>\n<p><span style=\"color: #0000ff\">\u201c@\u201d :HKU\\[SID]\\Software\\ExeName\\US<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>?In these instances, <span style=\"color: #0000ff\">PathToExe<\/span> denotes the new location where the malware replicates itself (e.g., %tmp%), while &#8220;ExeName&#8221; represents an arbitrary name chosen by the attacker during file Building.<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>NJRat&#8217;s primary objectives encompass stealing information, and spying on the system. The malware capabilities are:<\/p>\n<p>&#8211; Accessing the victim&#8217;s webcam and microphone<br \/>\n&#8211; Real-time monitoring of victim&#8217;s desktop<br \/>\n&#8211; Logging keystrokes<br \/>\n&#8211; Stealing system files<br \/>\n&#8211; Uploading files to the system<br \/>\n&#8211; Executing files, commands, etc.<\/p>\n<p>Furthermore, NJRat&#8217;s capabilities, such as file placement and obfuscation, are adjustable during its construction, depending upon the utilized version.<\/p>\n<p>Following execution, the malware duplicates itself in the specified path, generating a random name, and ensures persistence within the victim&#8217;s system by creating a registry key at<span style=\"color: #0000ff\"> \\HKU\\[SID]\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\<\/span>Run.<\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><em>appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup%<\/em><\/span><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3957 \" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/03\/1.png\" alt=\"\u0645\u0633\u06cc\u0631 %appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup \u0628\u062f\u0627\u0641\u0632\u0627\u0631\" width=\"1315\" height=\"185\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3>Network Operation<\/h3>\n<p>The process of this malware involves establishing a TCP connection with a arbitrary destination port. It&#8217;s worth mentioning that certain packets sent by the malware are encoded using the Base64 algorithm. Furthermore, within the stream of data sent from the compromised system, a pipe symbol &#8220;|&#8221; is consistently present, as illustrated in the figure below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/03\/2.png\" alt=\"\u0648\u062c\u0648\u062f \u0639\u0644\u0627\u0645\u062a \u067e\u0627\u06cc\u067e \u0645\u06cc\u0627\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0627\u0631\u0633\u0627\u0644\u06cc \u0627\u0632 \u0633\u06cc\u0633\u062a\u0645\" width=\"1333\" height=\"108\" \/><\/p>\n<p>The information shown in the above image represents the initial packets transmitted from the victim&#8217;s system to the attacker, maintaining a consistent format across various iterations of the NJrat malware. Each data packet contains various system information, including usernames and OS versions, with some data encrypted by the malware.<\/p>\n<p>&nbsp;<\/p>\n<h2>How to deal with and clean the system<\/h2>\n<p>Padvish antivirus software effectively detects and removes NJRat from infected systems. To reduce the risk of NJRat infiltration:<br \/>\n\u2705\u00a0Avoid clicking on suspicious links and run antivirus scans on email attachments.<br \/>\n\u2705\u00a0Be cautious when executing files of uncertain or unknown sources.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: High Prevalence: Moderate &nbsp; Malware Name(s) Trojan.Win32.NJrat (Padvish) A Variant Of MSIL\/Bladabindi.AS (ESET-NOD32) Backdoor.MSIL.Bladabindi.AJ (Kaspersky) &nbsp; What is trojan? Trojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[43,61,62],"class_list":["post-1518","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-trojan","tag-trojan-win32-njrat","tag-njrat"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1518","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1518"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1518\/revisions"}],"predecessor-version":[{"id":1540,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1518\/revisions\/1540"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}