Open tickets
Queue: evidence intakeTCB-IR-0417 Critical Open Loader binary recovered from a compromised host
Analysts pulled the loader binary itself off a workstation with access to the
payments network. It trips endpoint protection on sight, so it was zipped with the
password before it ever touched the evidence share, standard handling for anything
live, rather than let the mail gateway strip it in transit. Saved below as
bitsran.exe. The loader carries an embedded resource named
IMAGE. Extracted, it opens fine in an image viewer, a small, noisy
looking picture, but its file size does not match what an image that size should
need. Nothing has been run. Find out what else is really in that resource.
Static analysis only. Nothing here needs to run, including bitsran.exe itself.