Talvane Commercial Bank Incident Response · Evidence Locker
1 open ticket

Open tickets

Queue: evidence intake
TCB-IR-0417 Critical Open Loader binary recovered from a compromised host
Source
Payments network jump host
Recovered by
Overnight IR sweep

Analysts pulled the loader binary itself off a workstation with access to the payments network. It trips endpoint protection on sight, so it was zipped with the password before it ever touched the evidence share, standard handling for anything live, rather than let the mail gateway strip it in transit. Saved below as bitsran.exe. The loader carries an embedded resource named IMAGE. Extracted, it opens fine in an image viewer, a small, noisy looking picture, but its file size does not match what an image that size should need. Nothing has been run. Find out what else is really in that resource.

bitsran.zip Archive password: infected
Download

Static analysis only. Nothing here needs to run, including bitsran.exe itself.