Backdoor

Backdoor.njRAT (file analysis)

Malware Removal

The Backdoor.njRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.njRAT virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Backdoor.njRAT?


File Info:

name: FA627A7C109337879135.mlw
path: /opt/CAPEv2/storage/binaries/65404f0aac73835629562ebdc94969c6c0187a8049518589ee78b5815e80fa0b
crc32: 90C91CF1
md5: fa627a7c10933787913533ef9da9b1ac
sha1: dedb1d962e4292c536e4a7848251b94260f35fab
sha256: 65404f0aac73835629562ebdc94969c6c0187a8049518589ee78b5815e80fa0b
sha512: 7f573990c6bb84a5af5d5e47a9179777875f90da3db9a691641725447f13a62b97edebd055a7aa06cc3c50a36fa4f1a81da8f72ad923e736ef7fe40329f007f2
ssdeep: 49152:J845nIrTfNxeO4GYtJV47D4rnpTKECEyjaMWdJpcM:JnmX4Y7sjMECPjRWdJ7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172852303F98555B2C921093115399B60667EBE301F28DBEFB3D4AA3DD9340E1BB346A7
sha3_384: fe293263d02bad6e53ac7d048a94b76ec47fee8bf791d7e6c85b3848b2f85cd65781a6f7cc9efc1d779a68173bba6bc7
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Backdoor.njRAT also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.NanoBot.trQD
MicroWorld-eScanTrojan.Rasftuby.Gen.14
FireEyeGeneric.mg.fa627a7c10933787
ALYacTrojan.Rasftuby.Gen.14
CylanceUnsafe
VIPRETrojan.Rasftuby.Gen.14
SangforTrojan.Win32.Agent.Vof7
K7AntiVirusTrojan ( 0050b5d91 )
BitDefenderTrojan.Rasftuby.Gen.14
K7GWTrojan ( 0050b5d91 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Bladabindi.AR
TrendMicro-HouseCallTROJ_GEN.R003C0WGI22
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Rasftuby.jqallo
ViRobotTrojan.Win32.Z.Sabsik.1761617
Ad-AwareTrojan.Rasftuby.Gen.14
SophosMal/Generic-S
ComodoMalware@#amotm3zywum5
DrWebTrojan.Siggen18.23131
TrendMicroTROJ_GEN.R003C0WGI22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Rasftuby.Gen.14 (B)
APEXMalicious
WebrootW32.Trojan.Rasftuby
Antiy-AVLTrojan/Generic.ASCommon.24D
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Rasftuby.Gen.14
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Rasftuby.Gen.14
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.NetShrink.C5204089
Acronissuspicious
McAfeeArtemis!FA627A7C1093
MAXmalware (ai score=89)
VBA32Backdoor.njRAT
MalwarebytesMalware.AI.2992588170
PandaTrj/CI.A
TencentWin32.Trojan.Generic.Eegw
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.c10933
AvastWin32:Malware-gen

How to remove Backdoor.njRAT?

Backdoor.njRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment