Nymaim revisited
ID: c71747b2-af15-5faa-9e64-d438f818f6be
STIX ID: report--c71747b2-af15-5faa-9e64-d438f818f6be
Feed Name: CERT Polska
Nymaim (Goznym) is a heavily-obfuscated banking trojan analysed in this report: authors reverse-engineer its custom obfuscation, static configuration format, DGA and P2P network protocol, message encryption (RC4/Serpent/APLIB), and payload distribution. The report documents operational details (dropper/payload/bot_peer roles), extraction methods, IoCs (file hashes, YARA), and botnet measurements (thousands of supernodes, geolocated injects), and provides tooling and parsing guidance to recover configuration and injected binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
