Resubmissions

04-07-2024 22:35

240704-2hv1havgnh 10

04-07-2024 22:32

240704-2gcgrsshnp 10

General

  • Target

    SlottedAimV2.rar

  • Size

    7.1MB

  • MD5

    04b4440a4dd4c687a388d993c0be18b7

  • SHA1

    3f363a3d4c04bde4609168336033bbdcd5555bd5

  • SHA256

    1cdd2cd88644b2d634ac27b95031bddcbb69479bf6bdd090a2257e40132a69c2

  • SHA512

    7f72cef7397380ba583c4034de5f10e42e1d40c268b82f63e3d17e85e2a8c1b498665be6f9235031ed3dc3f8efb2114982ef513bee79b49c743a61f98a384cc8

  • SSDEEP

    98304:LtIGDf639tvIF2/rvPzRrHY5rjoMQeYqolZIed277vRtf323r85zQ65gBB9UBr+U:LJII2rvbZHYibeYqolZIl7vRpn1RoU6S

Score
10/10

Malware Config

Signatures

  • A stealer written in Python and packaged with Pyinstaller 1 IoCs
  • Blankgrabber family
  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • SlottedAimV2.rar
    .rar
  • Driver.dll
    .dll windows:10 windows x64 arch:x64

    e7be09a11268187c0db544b566d887c1


    Headers

    Imports

    Exports

    Sections

  • How to use.txt
  • SlottedAimV2.exe
    .exe windows:5 windows x64 arch:x64

    f4f2e2b03fe5666a721620fcea3aea9b


    Code Sign

    Headers

    Imports

    Sections

  • �� ���.pyc
  • mciavi32.dll
    .dll windows:10 windows x64 arch:x64

    64ac7fcfa1bf5a3af1997b9aef6cbfc9


    Headers

    Imports

    Exports

    Sections

  • spwizimg.dll
    .dll windows:10 windows x64 arch:x64


    Code Sign

    Headers

    Sections