General

  • Target

    1e1570b332641ddc61ec85c9b8b2be7178e967d301375d3cccca359c5dc91ee3

  • Size

    2.3MB

  • MD5

    1e78af6975b7314bbe9cae029539076f

  • SHA1

    3af4b0ab4f58061b9a3a06692b8766aaebffdebb

  • SHA256

    1e1570b332641ddc61ec85c9b8b2be7178e967d301375d3cccca359c5dc91ee3

  • SHA512

    bbb504de3b8857eee362032d5edc3415f4e3281988c6b59c6f0ff6a703724b4220c6b72ddf1dc0c70047f7e55f21b5eb04d0f56d9865e7538a1f282010fad6b9

  • SSDEEP

    49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6SNvFMs+o:BemTLkNdfE0pZrwo

Score
10/10

Malware Config

Signatures

  • KPOT Core Executable 1 IoCs
  • Kpot family
  • XMRig Miner payload 1 IoCs
  • Xmrig family
  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 1e1570b332641ddc61ec85c9b8b2be7178e967d301375d3cccca359c5dc91ee3
    .exe windows:6 windows x64 arch:x64


    Headers

    Sections