Indicators of Compromise (IOCs)

Hashes File Name
MD5: cbda24f8ac22d68c0c3bfad37d0c2ed8SHA-1: 07fff967d4b10ebf6b6c40584a5ddb27d8ce288a 

SHA-256: 59b9f82fd8e6f5aefbdd1c93d9e1d3012bbe843ddb958b1ca50c026b2217e25a


59b9f82fd8e6f5aefbdd1c93d9e1d3012bbe843ddb958b1ca50c026b2217e25a.dll
MD5: 091688921520012e70d61125c0f7c269SHA-1: 94d6b21d1b347d6d83c875c71927a6906927ebaa 

SHA-256: 1b0f24eb2149bc7ba10d98651488f651e12e00956adcdb90b9775e95168b2fdd


decoded.dll
MD5: aa9d7ce1d08ec1a4147846f91423f431SHA-1: 492d6cb1c6f30f628145a14180440dae9d8b2454 

SHA-256: 91d4ae2f55f71f13fea98d23c99a6e7110d5bff0217ea195df90d6f96c46c84b


payload.bin
MD5: 8ae185afebe306e8f84fda01a37094d3SHA-1: 9275da21ea5255df3d22d5f8b516234088ea2703 

SHA-256: e381d8d00e2d9686c5e0144bfafec980c806210e11331a0a9616c48c66667f7c


N/A
MD5: e18a9bb146ccb98e67c8cce6e69ac8b7SHA-1: 7d5df6177acfea5c572d26d0082e203719971b42 

SHA-256: 460842d20206c6e7709d28b0bb5d31b326f9af0596e9f76e3cfd017e939c9aee


460842d20206c6e7709d28b0bb5d31b326f9af0596e9f76e3cfd017e939c9aee.sample

Sources

https://malpedia.caad.fkie.fraunhofer.de/details/win.carbanak

https://malpedia.caad.fkie.fraunhofer.de/actor/fin7

https://en.wikipedia.org/wiki/Carbanak

https://www.mandiant.com/resources/blog/carbanak-week-part-two-continuing-carbanak-source-code-analysis