njRAT runs MassLogger
A PCAP file with njRAT traffic was published on malware-traffic-analysis.net last week. After loading this PCAP file, NetworkMiner Professional reveals that the attacker downloaded full resolution screenshots of the victim’s screen.
Image: Overview of screenshots sent to C2 server
Image: Screenshot extracted from njRAT traffic by NetworkMiner
The file “New Purchase Order and Specifications.exe” in this screenshot is the njRAT binary that was used to infect the PC.
A list of njRAT commands sent from the C2 server to the victim can be viewed on NetworkMiner’s Parameters tab by filtering for ”njRAT server command”.
The following njRAT commands are present here:
Additional njRAT commands can be found in our writeup for the Decoding njRAT traffic with NetworkMiner video, which we published last year.
njRAT File Transfers
The “inv” and “rn” commands both transfer and execute additional code on the victim machine. The “inv” command typically transfers a DLL file that is used as a plugin, while the “rn” commands sends an executable file. These DLL and EXE files are transferred in gzip compressed format, which is why NetworkMiner extracts them as .gz files.
Image: Gzip compressed files extracted from njRAT traffic
This oneliner command lists the internal/original file names and corresponding MD5 hashes of the gzip compressed executables sent to the victim PC:
The MD5 hashes of the files inside the gzip compressed streams can also be seen on the Parameters tab in NetworkMiner.
MassLogger
The “CloudServices.exe” executable is a known credential stealer called MassLogger. This particular MassLogger sample is hard coded to exfiltrate data in an email to kingsnakeresult@mcnzxz[.]com. The email is sent through the SMTP server cphost14.qhoster[.]net. See the execution of this sample on Triage for additional details regarding the MassLogger payload in CloudServices.exe.
IOC List
njRAT
MassLogger
The second season of Star Wars Disney+ series Ahsoka won't arrive until early 2027 —…
Former Call of Duty: Black Ops multiplayer design director, David Vonderhaar, has teased his next…
The cyber insurance industry set out to manage financial risk. Along the way, it has…
On Tuesday, May 5, Boston Review convened a panel of three prominent writers—Kevin T. Baker,…
April 2026 Highlights 112 premium XYZ Registry domains were registered* Most popular TLDs in premium…
Star Wars: Fate of the Old Republic won't be another bloated single-player game that takes…
This website uses cookies.