General

  • Target

    e6b91a52554e6adf43df0ffaa6b92d33.bin

  • Size

    415KB

  • MD5

    e7c1c3544f4fa6c40b430e2d9b4dbd6d

  • SHA1

    49af3656e9c64b67ebba8c516ee569532644715e

  • SHA256

    c3dd479040f9634af3679f6c935d3740c751a7dfbb81971b43ff106fa6e83148

  • SHA512

    adcf90afb74a34ada7923f4f5633016d3c809700750b7114fb5fbb6eb214b4041a84cd6274b06ec88f5e0d4c6b7585c7fa13a2b6490815f670be72c19dd6c46e

  • SSDEEP

    12288:+9HVnh3fg1B7OcQLgME9GczxwPgEEsoqsoPXubATq:i6HOzEVwcz6PjkovVTq

Score
3/10

Malware Config

Signatures

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • e6b91a52554e6adf43df0ffaa6b92d33.bin
    .zip

    Password: infected

  • 0a7f62793ce40e99600c729a97d80c02b4f8c80d16c32f5edaa8a6eac48d416e.exe
    .exe windows:4 windows x86 arch:x86

    Password: infected

    e160ef8e55bb9d162da4e266afd9eef3


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    8c8a576201f68de1a3f26fc723b9f30f


    Headers

    Imports

    Exports

    Sections

  • Skrigeballonernes207/Bef.sem
  • Springdansen/Fedterier.lli
  • Springdansen/Indkomstafhngiges.fif
  • Springdansen/Struktureres.txt
  • Springdansen/Yardage.tja
  • Springdansen/airway.Oms
  • Springdansen/frondescing.nov
  • Springdansen/monomark.dod