General

  • Target

    de52002c9566018c61b816f862325c681c756758e693c9d40b70670caf22a2c4.rar

  • Size

    242KB

  • MD5

    905ea903cc9cccce0c3a3e4eaa699f66

  • SHA1

    69d1b7740f9c968215fb44c20a02759d2ee9f7d2

  • SHA256

    de52002c9566018c61b816f862325c681c756758e693c9d40b70670caf22a2c4

  • SHA512

    22e8fb03c0aee000567f353a9eba70e59c01faa1f19fe4d93ebd5cccafdb25aec52aa4661cd5ad8d85737521aecab93878943e630be19d7f0d8e718343346620

  • SSDEEP

    6144:LipIgTrTl/jSXwn251cdEWzNIhMlgSpy5L3yAur/aolLm02:LOVTl/jSBONT3pyxCRLLR2

Score
3/10

Malware Config

Signatures

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • de52002c9566018c61b816f862325c681c756758e693c9d40b70670caf22a2c4.rar
    .rar
  • SMKT_COPY20240604.exe
    .exe windows:4 windows x86 arch:x86

    f4639a0b3116c2cfc71144b88a929cfd


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    509a34b3a68a773e0afb4259e68f9f82


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    68b7023f8923dd087549802f8fa631c3


    Headers

    Imports

    Exports

    Sections

  • Acrook17.Ram59
  • Begot.ami
  • Bove.ska
  • Disbosom.kli
  • bnderkonerne/Samplingsfrekvenser.sal
  • bnderkonerne/Throeing.non
  • bnderkonerne/jobbere.aml
  • bnderkonerne/widdling.txt