General

  • Target

    sarexlogistics receipt document,pdf.exe

  • Size

    675KB

  • MD5

    7752f357a75ddb3e3f1412f559ef2a7a

  • SHA1

    a75f8ed934a8525e09b8a8ff24cf8f49c9aba90c

  • SHA256

    c527daf2491bb0c007246173bd7dee7926a01418ae3550f60f6971f2fb8caa94

  • SHA512

    ee22afcd9ef860a60e9626454fd7e576d09c3d30412cc8af82b56273f8da07711233940f9e4c6babbcdeae3b86df65ea33b8dfc60486fa56618e53ba6c752ca8

  • SSDEEP

    12288:kH+/vBkZcYasAtiieQeCpqpydrYTDyumSuoZ2hQ:i+/JqcLNeCQyVe2u7Vsi

Score
3/10

Malware Config

Signatures

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • sarexlogistics receipt document,pdf.exe
    .exe windows:4 windows x86 arch:x86

    3abe302b6d9a1256e6a915429af4ffd2


    Headers

    Imports

    Sections

  • AdminTools.exe
    .exe windows:5 windows x64 arch:x64

    28070773af9ae36cbe9cb3201e3a64fe


    Code Sign

    Headers

    Imports

    Sections

  • Appetises/Osaka/Fusionsenergi/network-wireless-disabled-symbolic.symbolic.png
    .png
  • Blinkhindens/multimedia-player.png
    .png
  • Flexive/Undertrykkelsesmiddel/Unassertive/Concelebrating/battery-level-60-charging-symbolic.symbolic.png
    .png
  • Flexive/Undertrykkelsesmiddel/Unassertive/Concelebrating/mail-send-receive-symbolic.svg
  • Ruchernes.Pre
    .ps1
  • Unentrenched.Ned