In this twitch stream we begin our triage of the Matanbuchus loader malware. First, we resolve the API hashes, and decrypt the strings, then we attempt to build a Yara rule and and automated config extractor.
Sample
f8cc2cf36e193774f13c9c5f23ab777496dcd7ca588f4f73b45a7a5ffa96145e
Notes
Stanislaus Hoppe
2022-07-10 00:05:40 +0000 UTCOALABS
2022-06-27 16:47:48 +0000 UTCRussianPanda
2022-06-27 12:53:12 +0000 UTCj0s3
2022-06-24 13:20:38 +0000 UTC