{"id":"a0bc75d72a1f793ef46893f919ef5791","title":"NjRAT — NjRAT · 木马/恶意软件 · PE32 .NET","md5":"a0bc75d72a1f793ef46893f919ef5791","sha256":"a585796634217ff4ab444ea95d43a01a1aa4b3a280b41eaea0e42223e491efae","family":"NjRAT","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C#","file_format":"PE32 .NET","compiler":"VB.NET","published_at":"2020-02-24T16:00:00.000Z","summary":"该样本被 DIE 识别为 NjRAT (NjWorm) 变种，使用 VB.NET 和 .NET Framework 2.0 编译。 编译于 2020-02-18 17:12:37，大小 35.5 KB。 NjRAT 是中东地区广泛使用的远程访问木马，功能包括: 远程Shell、文件管理、屏幕监控、键盘记录、摄像头访问、密码窃取等。 该变种引用了 screen, chrome, opera, trust 等关键词， 表明具备屏幕监控和浏览器凭据窃取能力。SHA256: a585796634217ff4ab444ea95d43a01a...","url":"https://zseceye.com/report/a0bc75d72a1f793ef46893f919ef5791","json_url":"https://zseceye.com/report/a0bc75d72a1f793ef46893f919ef5791.json","html_url":"https://zseceye.com/report/a0bc75d72a1f793ef46893f919ef5791","hash_urls":{"md5":"https://zseceye.com/hash/a0bc75d72a1f793ef46893f919ef5791","sha256":"https://zseceye.com/hash/a585796634217ff4ab444ea95d43a01a1aa4b3a280b41eaea0e42223e491efae"},"search_urls":{"md5":"https://zseceye.com/?q=a0bc75d72a1f793ef46893f919ef5791","sha256":"https://zseceye.com/?q=a585796634217ff4ab444ea95d43a01a1aa4b3a280b41eaea0e42223e491efae"},"sample_download_url":"https://zseceye.com/report/a0bc75d72a1f793ef46893f919ef5791/sample","sample_filename":"a5857966.zip","iocs":[],"ips":[]}