General

  • Target

    f9f5342074462fa1048fea806eef535f.bin

  • Size

    254KB

  • MD5

    4c812f8564b707afa05bea3d2e39bbdf

  • SHA1

    e8be6e0c2888b8341a801f41038e5141142f3c70

  • SHA256

    af9fd96e4a0de2860cb9ed5e8f3a70cf55e1d6f4c910e33c91c4d8b6413ffb2f

  • SHA512

    b42b1283f855304684e4121339026ed6cf8ac35c116c5e0b0f3ea5ce371007113fe7c80c5658d55d0ffa2f3c832c1292d04650ec6fe606fce20d0e3a6e5f9e18

  • SSDEEP

    6144:KwGmO9R2mIuSjbM1ddO0fPLB7mNo4STnIcoBOBrd5MuAiaj:vGmu2mIuywjw0fP12STN6OBx+b

Score
10/10

Malware Config

Signatures

  • Blackmoon family
  • Detect Blackmoon payload 1 IoCs
  • Gh0st RAT payload 1 IoCs
  • Gh0strat family
  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • f9f5342074462fa1048fea806eef535f.bin
    .zip

    Password: infected

  • 5d87bd723f8267c3c0bef75f2b502321c518ac6a09696f3971ace53d0ba505cd.exe
    .exe windows:4 windows x86 arch:x86

    Password: infected


    Headers

    Sections

  • out.upx
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections