General

  • Target

    01072024_1113_30062024_P0-ADFUK.gz

  • Size

    389KB

  • MD5

    7400ced534ac88f7170ae2802999fee4

  • SHA1

    39b6aada175477fbd38f6b6c30e3afda5a3cbe98

  • SHA256

    e76e72cf637809c754a72a2f8f5d54cee242c5465e59ecf9ead85d69ef71fef7

  • SHA512

    9cefda228cb87cb094d8f96c322741170555d15b506fa899997e24da56914e1e4e7e47f6d05acf2d1570eb839aa30ac0e91ce2d8d8eb409a60850f3e6ade2a34

  • SSDEEP

    12288:ZAxCHw/r6zMpoJBNuAmkXaViDTjUeQLD1i6v:iVoJL5m4BrWv

Score
3/10

Malware Config

Signatures

  • Unsigned PE 5 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • 01072024_1113_30062024_P0-ADFUK.gz
    .gz

    Password: infected

  • P0-ADFUK.bat
    .exe windows:4 windows x86 arch:x86

    Password: infected

    671f2a1f8aee14d336bab98fea93d734


    Headers

    Imports

    Sections

  • $PLUGINSDIR/BgImage.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    0bf743a799aa40ec407e829cce14f6c8


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    240ca92ecc1c291801c451c447e16c12


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    13b1bef222622e1e4753306d634849ab


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    Password: infected

    9076fa7961baeaeda0746cb0928f486a


    Headers

    Imports

    Exports

    Sections

  • Allopurinol.flu
  • Brndenldes.Kao
  • Charting.skr
  • Gkkes.Vok
  • Ruineringernes/doubling.reg
  • Ruineringernes/hmoriderne.ner
  • Ruineringernes/lvens.flb
  • Ruineringernes/materialiter.sig
  • Ruineringernes/preinvest.pri
  • Strandbredden/ridningen.txt
  • chokoladeforretning.mar