Suspicious 80% Download

Trojan.Win32.Pakes.nfn

Impersonated Adobe signature, trojan name

PE directories in mismatched sectionsAuthenticode chain CN: Adobe Systems, Incorporated
SHA-2566f0118f7fca299fe5dd4d8f5c67c591ef0c705c08cb5503f20d0e9e92cc423d5

Evidence

PE directories in mismatched sections 0x0–0xe0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f8000000................
⋯11 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.