General

  • Target

    c0832c8de8dcb7e30f0385662e32b29e14fc176f6156a96feb6753ddef764e09

  • Size

    1.2MB

  • MD5

    361e714af955028a9d1c337e831140d0

  • SHA1

    489e5f437696e5574a82d59f34dfdb2b648ad4f9

  • SHA256

    c0832c8de8dcb7e30f0385662e32b29e14fc176f6156a96feb6753ddef764e09

  • SHA512

    454f8f793da5e2f99eada01356c209b90628307aec811bf98323df496dfab24a4e80822c1a603a0cff9f60ef54c50a423f4f55ee852e11a14be51df78f7861b8

  • SSDEEP

    24576:eeY0JfjXimMQpTdYS/OWtorq/1O1YneY0JfjXipMQpTdYS/OWtorq/1K:e10tLNTTW1Yn10tLoTTWx

Score
7/10
upx

Malware Config

Signatures

  • UPX packed file 2 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 4 IoCs

    Checks for missing Authenticode signature.

Files

  • c0832c8de8dcb7e30f0385662e32b29e14fc176f6156a96feb6753ddef764e09
    .zip
  • N3rwa/161A.dat
    .zip
  • N3rwa/161A.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • N3rwa/edge.xml
  • N3rwa/ryAMm0z9x.dat
    .zip
  • N3rwa/ryAMm0z9x.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections