IOCs
Indicators for njRAT
62 indicators · scoped to malware families · back to njRAT
Live IOCs from URLhaus, ThreatFox, MalwareBazaar, and abuse.ch SSLBL for malware families this tool uses. All indicators are defanged for safe handling.
⚠
Indicators
62 of 62
url
hxxps://github.com/demarcusnofatherington420-a11y/ScriptInstaller/raw/refs/heads/main/Puls
url
hxxps://github.com/demarcusnofatherington420-a11y/RickOwens/raw/refs/heads/main/Pulsar-Cli
sslbl_sha1
decc8cd1ba84392f1054e0d1394f4f0a9f64b7fa
sslbl_sha1
8cbc88ff795519ad5ad074eb520438922f8d3773
sslbl_sha1
f978cf56a838e9821b699784c9650a0baacdb528
sslbl_sha1
80bcab6a0fbe3162130168bd93efc26fd3ec6490
url
hxxp://196.251.107.24/n743.exe
url
hxxp://85.137.253.58:9000/csrss.exe
url
hxxp://216.126.239.100/bt/svchost.exe
url
hxxp://94.156.102.255/files/coolfile.exe
url
hxxp://94.156.102.255/files/mswincryptographdata.exe
url
hxxp://94.156.102.255/files/totallynotavirus.exe
url
hxxps://raw.githubusercontent.com/stevencohn8888-max/ghghg/refs/heads/main/SECURE.Ps1
url
hxxps://raw.githubusercontent.com/stevencohn8888-max/ghjjhj/refs/heads/main/ENCRYPT.Ps1
url
hxxps://raw.githubusercontent.com/stevencohn8888-max/NEW8933/refs/heads/main/SECURE.Ps1
sslbl_sha1
75f7cde979b32caa86130131435763d5f78cca06
sslbl_sha1
916509400d6f6be6c1e7bb743eec65fbe09dde21
url
hxxps://github.com/cybertoxin/Remcos-Professional-Cracked-By-Alcatraz3222/raw/master/Remco
url
hxxps://raw.githubusercontent.com/iluxa94/-3-/main/%D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9
url
hxxps://raw.githubusercontent.com/iluxa94/-3-/refs/heads/main/%D0%A4%D0%BE%D1%80%D0%BC%D0%
url
hxxps://github.com/ff245185/payload/raw/refs/heads/main/Fast%20Download.exe
url
hxxps://github.com/Grozniy1/folder/raw/refs/heads/main/444.exe
url
hxxps://raw.githubusercontent.com/ff245185/payload/refs/heads/main/Fast%20Download.exe
url
hxxps://raw.githubusercontent.com/Grozniy1/folder/refs/heads/main/444.exe
url
hxxp://github.com/Grozniy1/folder/raw/refs/heads/main/444.exe
url
hxxp://github.com/ff245185/payload/raw/refs/heads/main/Fast%20Download.exe
sslbl_sha1
8765d36a75e38174fd744d91deef9f3432b3f0d6
url
hxxps://raw.githubusercontent.com/Da2dalus/The-MALWARE-Repo/refs/heads/master/RAT/NJRat.ex
url
hxxps://raw.githubusercontent.com/ff245185/payload/main/Fast%20Download.exe
url
hxxps://raw.githubusercontent.com/Grozniy1/folder/main/444.exe
url
hxxp://github.com/Da2dalus/The-MALWARE-Repo/blob/master/RAT/NJRat.exe?raw=true
sslbl_sha1
66b40d248f57b2b2422f3300d15fd11076f47e6a
sslbl_sha1
003becd9037138c2ba7185abc0da32677c7ebef5
sslbl_sha1
327bb0d9abdff7b4c0ac35341275435104b5d5bf
sslbl_sha1
6dc62ba3d443223e31c419bc41882902663d5833
sslbl_sha1
ecbcd841f33ec6a40a26f3ff77e0e18f8a7e4949
url
hxxp://static.ilclock.com/gcld/updates_tw/gcmgr_tw.exe
domain
k7elan-43083[.]portmap[.]host
domain
1brainfix[.]ddns[.]net
domain
test[.]accendente[.]tn
domain
2ffahbg8eydhr96hx3x2lje2ymygt5iq[.]duckdns[.]org
domain
shadownbr[.]ddns[.]net
domain
ricardotro[.]duckdns[.]org
domain
rjnfjrtc[.]pwrp[.]cc
domain
rdntotoso[.]ddns[.]net
domain
phishing[.]two-i[.]com
domain
phishing[.]researchinstitute[.]io
domain
kad77[.]duckdns[.]org
domain
googlednsv1[.]gleeze[.]com
domain
same53-51830[.]portmap[.]host
domain
phishing[.]classofcovid[.]org
domain
stoneaged[.]ddns[.]net
domain
phishing[.]clubmilanovolley[.]com
domain
phishing[.]marthasvineyardfitness[.]com
domain
fuck-life007[.]no-ip[.]biz
domain
phishing[.]flyingdiscranchdates[.]com
domain
hacker[.]two-i[.]com
domain
phishing[.]www[.]cathedrale-images[.]com
domain
phishing[.]xoilacane[.]live
domain
mangy10[.]ddns[.]net
Showing 1-62 of 62