General

  • Target

    rSCAN31804.zip

  • Size

    246KB

  • MD5

    101bdb677724d86650f9782be88cc538

  • SHA1

    f7920e73b43cfcf8f3457ed1cea90d68dcfecd6d

  • SHA256

    72422ffd1c7d2f609bc487c44b6b4b022d14f27b0e7cde1cd360588da857e0cc

  • SHA512

    8c0f5d563d91a835d764607d4f05506577b011ffe857f86e0c084382325d76d7097b2db8d85b59b548403c476ae64634fc7d619660a8d57c586a22f8fe33076f

  • SSDEEP

    6144:Z+XvwDSUjdpYcBA6iA8FX2DN7LF7hUdMUjzz4elv4+kqI:ZuvwDSgbBA6YFX2DN7LF7hjelvPkqI

Score
3/10

Malware Config

Signatures

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • rSCAN31804.zip
    .zip
  • rSCAN31804.exe
    .exe windows:4 windows x86 arch:x86

    f4639a0b3116c2cfc71144b88a929cfd


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    509a34b3a68a773e0afb4259e68f9f82


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    68b7023f8923dd087549802f8fa631c3


    Headers

    Imports

    Exports

    Sections

  • Acrook17.Ram59
  • Begot.ami
  • Bove.ska
  • Disbosom.kli
  • bnderkonerne/Samplingsfrekvenser.sal
  • bnderkonerne/Throeing.non
  • bnderkonerne/jobbere.aml
  • bnderkonerne/widdling.txt