A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30896  by Antelox
 Wed Oct 11, 2017 7:10 am
ikolor wrote:next ..

https://www.virustotal.com/#/file/25300 ... /detection


https://www.virustotal.com/#/file/6a252 ... /detection
SHA256: 253006c07ec3a20197c9a30c8a8015a5923a349447a2115ec04630b54be29852

It looks like Nymaim.

SHA256: 6a252444d857097d3195863b528d818ad64f6671c6d78af682acb5b77b960143

It's a self-extracting archive which drops Retefe trojan banker.

BR,

Antelox