General

  • Target

    f5c5f4572e0dc9f3c210a636885c1e4b.bin

  • Size

    8.2MB

  • MD5

    f5c5f4572e0dc9f3c210a636885c1e4b

  • SHA1

    df7731584614d2414d9b14c5d0f2d5223e3e742f

  • SHA256

    f1f7dbd211cac3e16a911ad71a790c42d20a2f62711ff8a0918d8bd576cf41e4

  • SHA512

    446cd5c863a71a2c8d8558c9a162b99012805b636fc3f3cc555c6836c7bb6bebdced148c6de3a77d9c277f900819ce2e6cea39672ef120f0a24a1e40cae3d086

  • SSDEEP

    196608:NsjHWLtfvGzd6MZfeY5lqctrz8J+8uesYDYaASn1myj:Nsj2JOzt5k8z8J+8PTASB

Score
10/10

Malware Config

Signatures

  • A stealer written in Python and packaged with Pyinstaller 1 IoCs
  • Blankgrabber family
  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • f5c5f4572e0dc9f3c210a636885c1e4b.bin
    .zip

    Password: infected

  • CriticalFiles/SN.dll
  • CriticalFiles/SNInstallerHandler.exe
    .exe windows:6 windows x64 arch:x64

    Password: infected

    de41d4e0545d977de6ca665131bb479a


    Headers

    Imports

    Sections

  • CriticalFiles/StageSN.exe
    .exe windows:5 windows x64 arch:x64

    Password: infected

    2ac23c52e7647c5bbea38e98bb68c652


    Code Sign

    Headers

    Imports

    Sections

  • Լ��� V.pyc
  • InstHndl.dll
  • SuperNova.exe
    .exe windows:4 windows x86 arch:x86

    Password: infected

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • SuperNova.exe.config
  • SuperNova.pdb