typeentityfamilyunclassified-nsis-dropperconfidencemediumcreated2026-06-10updated2026-07-19pedropperevasionsigninginstallerscriptobfuscationc2defense-evasion

unclassified-nsis-dropper

Family confidence: Medium. Eleven confirmed siblings (4978e16a, f7f089f7, cf9a061d, b3fb616d, 9c43b920, 78c5e8ca, 5212423b, 3a13583c, 3c63a3c0, 11a56375, cbdff40b). Cluster uses NSIS v3 exehead with fabricated self-signed certificates (27% unsigned rate across the cluster), Danish/French word-salad VS_VERSIONINFO, LZMA/BZip2/Deflate-compressed encrypted payloads, and Danish-themed character-skip PowerShell obfuscation (stride values: 4, 6, 8 across siblings).

Overview

A malware distribution cluster using the Nullsoft Scriptable Install System (NSIS) v3 as the outer loader. Observed samples masquerade as payment documents or PDFs and embed multiple encrypted second-stage payloads with machine-generated nonsense filenames inside the LZMA-compressed archive. Anti-analysis is achieved by encrypting the payloads (not hardening the stub), fabricating a self-signed X.509 certificate with word-salad subject fields, populating VS_VERSIONINFO with semantically empty strings, and deploying a Danish-variable character-skip PowerShell cipher (stride 6, offset 5) to decode the execution chain.

Build Stack

  • Outer loader: NSIS v3.12 Unicode self-extracting exehead ^[raw/analyses/4978e16a.../strings.txt:228]
  • Compiler: MSVC 6.0 linker (MajorLinkerVersion 0x6) ^[raw/analyses/4978e16a.../pefile.txt]
  • Compression: LZMA:23 solid archive embedded after PE header ^[raw/analyses/4978e16a.../binwalk.txt]
  • Certificate: Fabricated self-signed X.509 v3 with nonsense CN/O/OU/email ^[raw/analyses/4978e16a.../strings.txt:935-950]
  • Version info: Nonsense ProductName/Comments/LegalTrademarks ^[raw/analyses/4978e16a.../exiftool.json]
  • Payload naming: Computer-generated gibberish words (Tyrolerne, Afruster, glasrrets)

Deploy / TTPs

  • T1204.002 — Malicious Link / User Execution: relies on social-engineering filename (Pagamento22052026.exe)
  • T1071 — Application Layer Protocol: expected from decrypted inner payload (not observable statically)
  • T1574.002 — Hijack Execution Flow: NSIS stub hijacks legitimate installer trust model
  • T1036.004 — Masquerade Task or Service: payment-document lure
  • T1036.005 — Match Legitimate Name or Location: uses real NSIS installer framework
  • T1620 — Reflective Code Loading: inferred — inner payload likely loaded/decrypted in memory by NSIS script

Capabilities

  • pdf-filename-masquerade
  • certificate-polymorphism-per-sample — fresh fabricated self-signed X.509 per sample (same structure, different word-salad subject)
  • version-info-template-reuse — identical VS_VERSIONINFO block copied across builds
  • nsis-sfx-lzma-dropper
  • fabricated-self-signed-certificate-masquerade
  • version-info-word-salad-obfuscation
  • encrypted-multi-payload-embedded-archive
  • gibberish-filename-anti-triage
  • danish-character-skip-powershell-cipher
  • character-skip-polymorphism-stride-increment
  • null-padding-archive-anti-triage
  • bzip2-compression-variant — This sample uses BZip2 instead of LZMA in the NSIS archive, a minor toolchain variance observed also in sibling 5212423b
  • deflate-compression-variant — This sample uses Deflate instead of LZMA or BZip2 in the NSIS archive, a new toolchain variance first observed in sibling cbdff40b
  • pdf-masquerade-filename-engineering
  • multi-pe-payload-staging
  • registry-write-persistence (inferred from import profile)
  • process-creation-payload-launch (inferred from import profile)
  • iex-reflective-execution (inferred from PowerShell decode)
  • multi-pe-payload-staging
  • snydendes-hex-payload-helper — XOR-decoded hex payload segments processed by a snydendes helper inside the decoded PowerShell; observed in sibling 11a56375
  • unsigned-nsis-variant — completely absent certificate directory, not even a fabricated self-signed cert; observed in siblings 3c63a3c0 and 11a56375

Notable Analyses

  • /intel/analyses/4978e16a7f6b716c324810ec44d5a82eeecd80382e4d5ccb4dc031cdc2559d9f.html — First observed sample; Italian payment lure (Pagamento22052026.exe), single encrypted 145 KB payload Tyrolerne, static-only deep dive
  • /intel/analyses/f7f089f7f7753da939649fe98a4d274e44b837a61b72d022897858e1998cc7c4.html — Second confirmed sibling; PDF masquerade (Quots-875-765-pdf.exe), four encrypted PE payloads (~2.5 MB total), Danish character-skip PowerShell obfuscation (Labourhoods.Mas, stride 6), static-only deep dive
  • /intel/analyses/cf9a061d02b0601036e3fd138e6b59ee6cdba3e5a40f8472171a56771ace341c.html — Third confirmed sibling; PDF masquerade (EX777915904751.PDF.exe), two encrypted PE payloads (~679 KB total), Danish character-skip PowerShell obfuscation (Articulators.Inc, stride 8), null-padding decoy file, static-only deep dive
  • /intel/analyses/b3fb616de3993830d09c675bca2c146618abd5fbf8cd564702642d2eeb8aef10.html — Fourth confirmed sibling; "Revised_PI_2024.exe" payment-document lure, NSIS v3.02 exehead, six embedded payloads (four low-entropy encrypted PEs + one high-entropy encrypted blob + one PowerShell cradle), stride-6 Danish character-skip cipher (Yod.KatIEX + 8,710-char secondary payload). Static-only.
  • /intel/analyses/9c43b920900fe218212dec879c49c6b31b17ad0cda091818acff94a062b75fb8.html — Fifth confirmed sibling; "Documents.exe" generic-document masquerade, NSIS v3.02 exehead with MSVC 14.29 linker, six embedded payloads (three low-entropy encrypted PEs + one high-entropy encrypted binary + one obfuscated script + Danish word-salad text), fabricated self-signed cert (Earthboard Venstrehngt Yock), no visible PowerShell cradle in extracted archive. Static-only.
  • /intel/analyses/78c5e8ca9474815c1cd85825b00d9be487a0e049fb827b12ef74bc57580cd3f5.htmlSixth confirmed sibling; Ref_7021929821US20240709031221650.exe US payment-reference lure, NSIS v3 exehead with MSVC 6.0 linker, six embedded payloads (three low-entropy encrypted PEs + one high-entropy encrypted blob + one obfuscated PowerShell script + Danish word-salad text), stride-6 Danish character-skip cipher with fresh variable names ($Spirobranchiateuddhismens, $forbrndingsprocessernes), fabricated self-signed cert (Udskoling Begravedes Subscheme / Comoquer), reuses VS_VERSIONINFO template from b3fb616d. Static-only.
  • /intel/analyses/5212423bac835b8c3268e4cf2b195043bdcd403e7d98f9182830098585ef2d1a.html — Seventh confirmed sibling; PI_24000032.exe proforma-invoice lure, NSIS v3 exehead with MSVC 14.29 linker (Oct 2022 — toolchain upgrade from MSVC 6.0), four embedded payloads (one obfuscated 161 KB PowerShell cradle + one 347 KB null-padded encrypted blob + one 7 KB high-entropy encrypted blob + Danish word-salad text), US-themed fabricated self-signed cert (Florida/Miami/Nonsuccessive), fresh VS_VERSIONINFO word-salad (bedimpled, excerpting, uddybendes cranberries). Static-only.
  • /intel/analyses/3a13583c51add43997b963edaabc063c1abf9600d404e1d0e49bf4d09665d104.htmlEighth confirmed sibling; Product_samples_pdf.exe PDF masquerade, NSIS v3 exehead with MSVC 6.0 linker, five embedded payloads (one 344 KB high-entropy encrypted PE Gravhje.Lse + two null-padded blobs + one 55 KB stride-6 Danish character-skip PowerShell cradle Prsteskabets.Bes + one Danish word-salad text decoy Lakker153.txt), BZip2 compression (not LZMA — minor toolchain variance), fabricated self-signed cert (broomweed Dockyards Whelphood / Mazed / Westmont / Illinois), VS_VERSIONINFO word-salad (tyender marmoromkransedes, smrkages, wellhead). Static-only.
  • /intel/analyses/3c63a3c0670132e07fb90ca3c29ba35d898f6293bd40619a5611cb705e8b8212.htmlNinth confirmed sibling; WORK_REPORT_FOR_YOUR_FILLING_AND_SUBMITTING_SCAN0012_PDF.com — first observed .com extension masquerade (not .exe), unsigned (no fabricated certificate, unlike all prior siblings), NSIS v3 exehead with MSVC 6.0 linker, six embedded payloads (two high-entropy encrypted blobs + two low-entropy null-padded PEs + one 55 KB stride-6 Danish character-skip PowerShell cradle Rockendes.Pot + one Danish word-salad text decoy Rooing.txt), LZMA:23 solid compression. VS_VERSIONINFO Comments: shrugs stoppekurvens droges, InternalName: forventnings.exe. Static-only.
  • /intel/analyses/11a563757a79333564f1eda8325816a621d4f404c282245c8a382f0ec9e2dcfb.htmlTenth confirmed sibling; MY00111Q0562482MYKUL.pdf.exe PDF masquerade, NSIS v3 exehead with MSVC 6.0 linker, unsigned (no certificate directory at all — second unsigned sibling after 3c63a3c0), BZip2 compression (not LZMA), ten embedded payloads (one 52 KB stride-6 Danish character-skip PowerShell cradle Labourhoods.Mas + six encrypted blobs + two Danish decoy texts + one directory placeholder). VS_VERSIONINFO word-salad (standpat pejsene predestinarianism, mouser brazenface computerberegnendes, koagulere.exe). Decoded PowerShell reveals snydendes hex-payload helper processing four XOR-keyed segments (94B3A8, 81A3B28BA9A2B3AAA38EA7A8A2AAA3, 85AAA7B5B5EAE696B3A4AAAFA5EAE695A3A7AAA3A2EAE687A8B5AF85AAA7B5B5, 9A). Largest payload count in cluster to date. Static-only.
  • /intel/analyses/cbdff40bf525a8fdbb771e23e9da6463a380c7e6264236226a9909c8bc141889.htmlEleventh confirmed sibling; inquiry_4387.exe business-inquiry lure, NSIS v3.06.1 exehead with MSVC 6.0 linker, unsigned (third unsigned sibling, ~27% unsigned rate across cluster), Deflate compression (first Deflate variant — prior siblings used LZMA or BZip2), six embedded payloads in Derms/ subdirectory (four null-padded encrypted PEs + one high-entropy blob thwack.Ins + one mid-entropy Abnormal78.Nep + Danish word-salad decoy Rehang.txt). VS_VERSIONINFO word-salad (dechifrerbare merceress, pompejansk husdyrsygdom.exe, bellied peafowls saddelplads). No PowerShell cradle recovered statically. Static-only.

Related