In this twitch stream we triage two simple malware downloaders and look for common characteristics that we can use to automatically detect them. One loader turns out to be a Cobalt Strike loader and we attempt to extend our detections...
Downloader #1
9211ebf25c3cd3641451c95c50c1d3b7b2a4c53c36fa36564f3c1a177a0cda3d
Downloader #2 (Cobalt Strike)
1a10e2940151982f2ab4f1e62be6e4f53074a2ffb90c7977e16d6a183db98695
Notes (including Yara rules)
Malware Downloader Triage Notes
Goovscoov
2022-07-10 19:12:32 +0000 UTCOALABS
2022-07-10 04:04:04 +0000 UTCGoovscoov
2022-07-09 19:25:52 +0000 UTC