Resubmissions

03-07-2024 08:39

240703-kkmcpsyfkm 10

02-07-2024 15:07

240702-shjg2asdmj 10

General

  • Target

    Nitro-zm19.exe

  • Size

    17.0MB

  • MD5

    5362038851f58dcf73e0d8c10f167353

  • SHA1

    edbc0b004eb14649627634741a0851fdbb9a831b

  • SHA256

    a326f30402fadc6980693337d5cdc70a94b24100ac4a4a8354c642570fa2508b

  • SHA512

    9a7661f95b7ddd6903a5de70567db4b36c6b077ca31068023f62368d8b4da0310d44084e847bd2aa41f6351afff94d19b4385e7790a434a09b2b0194d47fbb56

  • SSDEEP

    98304:VfDjWM8JEE1rY4amaHl3Ne4i3Tf2PkOpfW9hZMMoVmkzhxIdfXeRaYKJJcGhEIFz:Vf0o5eNTfm/pf+xk4dWRatrbWOjgKp

Score
10/10

Malware Config

Signatures

  • A stealer written in Python and packaged with Pyinstaller 1 IoCs
  • Blankgrabber family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Nitro-zm19.exe
    .exe windows:5 windows x64 arch:x64

    2ac23c52e7647c5bbea38e98bb68c652


    Headers

    Imports

    Sections

  • a�A'6o�.pyc