General

  • Target

    a8c03dfe6c66acdf569a445ad9eba5795f699e78bb6c347db55dfbff03daa120.zip

  • Size

    424KB

  • MD5

    d73653fb655e3627f2ad3bcd7dbb2c82

  • SHA1

    4d5cc2bea8c2dc74ddd725fe9bea7389a2d39dd6

  • SHA256

    b71e123f35a70fe444f019c9b94fa65c383d14eced3647bb13ac4e50ec810af8

  • SHA512

    51091c0874b597012087fcb4d82c28234bffb75604db1c3fb9c788002dc91620010b7d4fc85d0d665e582da8a5d84f072045a4f1e36cc412331e1bb93780453c

  • SSDEEP

    12288:IHO3tKYRNkVJyq2NfoebDuedht+LEYuwKUTRZsGzhnHz:IXYRIyFAedhtGERwT9ZsGzhnHz

Score
3/10

Malware Config

Signatures

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • a8c03dfe6c66acdf569a445ad9eba5795f699e78bb6c347db55dfbff03daa120.zip
    .zip

    Password: infected

  • a8c03dfe6c66acdf569a445ad9eba5795f699e78bb6c347db55dfbff03daa120.img
    .iso

    Password: infected

  • AMENDED CONTRACT-pdf.bat
    .exe windows:4 windows x86 arch:x86

    Password: infected

    b78ecf47c0a3e24a6f4af114e2d1f5de


    Headers

    Imports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    46f8b6973f33717335c0f6d8087de67b


    Headers

    Imports

    Exports

    Sections

  • Pandekagernes.Ste
  • Ramular.Ung
  • Superartificially/fordicidia.txt
  • bengnaveriernes.roo