General

  • Target

    2344-0-0x0000000000230000-0x000000000023D000-memory.dmp

  • Size

    52KB

  • MD5

    0c6c92b7c20dc9485f8e6f517c6abebf

  • SHA1

    621f0315f35f6387c914862af35d949a34d62dd9

  • SHA256

    dc7021e0754f10fbbaf7ac93d779ffec15016d8c7ba33cc0d5fee1186d1f2cce

  • SHA512

    5a127f5a4af47bacc90c6bb5607dbcedc23c0ab78809ef4af02ba395f5b83eaaf0e061e4d12b5b56fd6bb30357f14f3d87a5424f456aa71ee4b6715618559224

  • SSDEEP

    1536:7N/KMrXocaibNfo6LMh9vtDNlv9FCYV0BO:rzocvxfo6Yh9vtJlv9FCYV0Q

Score
10/10

Malware Config

Extracted

Family

koiloader

C2

http://81.19.141.115/marasmus.php

Attributes
  • payload_url

    https://www.dsestimation.com/wp-content/uploads/2015/10

Signatures

  • Detects KoiLoader payload 1 IoCs
  • Koiloader family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2344-0-0x0000000000230000-0x000000000023D000-memory.dmp
    .exe windows:6 windows x86 arch:x86


    Headers

    Sections