Hostile 92% Download

Backdoor.Win32.Ceckno.ayf

Named backdoor, embedded PE

Detects Nitol MalwareEmbedded PE binary at file offset 0x2c58 (~20392 bytes)
SHA-256f80b9d74f359c461c33a0d0d55c2db3d3299cab5dbe28b899aacfa65782616f9
MaleculeTh

Evidence

Embedded PE binary at file offset 0x2c58 (~20392 bytes) 0x2c18–0x2ce8
⋯3 more rows
0x2c486f006e00000000000408b00400000000o.n.............
0x2c584d5a90000300000004000000ffff0000MZ..............
0x2c68b8000000000000004000000000000000........@.......
0x2c7800000000000000000000000000000000................
⋯7 more rows
Detects Nitol Malware 0x59b0–0x5b60
⋯7 more rows
0x5a2000000000085a00000000000000000000.....Z..........
0x5a30474554205e2626252425245e2524235eGET ^&&%$%$^%$#^
0x5a40262a2a282a2828262a5e252423232425&**(*((&*^%$##$%
0x5a505e262a282a265e2524255e262a2e6874^&*(*&^%$%^&*.ht
0x5a606d474554205e2a25255254472a28265emGET ^*%%RTG*(&^
0x5a702546544759484a494a255e262a28292a%FTGYHJIJ%^&*()*
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.