unclassified-nsis-dropper
Family confidence: Medium. Eleven confirmed siblings (4978e16a, f7f089f7, cf9a061d, b3fb616d, 9c43b920, 78c5e8ca, 5212423b, 3a13583c, 3c63a3c0, 11a56375, cbdff40b). Cluster uses NSIS v3
exeheadwith fabricated self-signed certificates (27% unsigned rate across the cluster), Danish/French word-salad VS_VERSIONINFO, LZMA/BZip2/Deflate-compressed encrypted payloads, and Danish-themed character-skip PowerShell obfuscation (stride values: 4, 6, 8 across siblings).
Overview
A malware distribution cluster using the Nullsoft Scriptable Install System (NSIS) v3 as the outer loader. Observed samples masquerade as payment documents or PDFs and embed multiple encrypted second-stage payloads with machine-generated nonsense filenames inside the LZMA-compressed archive. Anti-analysis is achieved by encrypting the payloads (not hardening the stub), fabricating a self-signed X.509 certificate with word-salad subject fields, populating VS_VERSIONINFO with semantically empty strings, and deploying a Danish-variable character-skip PowerShell cipher (stride 6, offset 5) to decode the execution chain.
Build Stack
- Outer loader: NSIS v3.12 Unicode self-extracting
exehead^[raw/analyses/4978e16a.../strings.txt:228] - Compiler: MSVC 6.0 linker (MajorLinkerVersion 0x6) ^[raw/analyses/4978e16a.../pefile.txt]
- Compression: LZMA:23 solid archive embedded after PE header ^[raw/analyses/4978e16a.../binwalk.txt]
- Certificate: Fabricated self-signed X.509 v3 with nonsense CN/O/OU/email ^[raw/analyses/4978e16a.../strings.txt:935-950]
- Version info: Nonsense ProductName/Comments/LegalTrademarks ^[raw/analyses/4978e16a.../exiftool.json]
- Payload naming: Computer-generated gibberish words (
Tyrolerne,Afruster,glasrrets)
Deploy / TTPs
- T1204.002 — Malicious Link / User Execution: relies on social-engineering filename (
Pagamento22052026.exe) - T1071 — Application Layer Protocol: expected from decrypted inner payload (not observable statically)
- T1574.002 — Hijack Execution Flow: NSIS stub hijacks legitimate installer trust model
- T1036.004 — Masquerade Task or Service: payment-document lure
- T1036.005 — Match Legitimate Name or Location: uses real NSIS installer framework
- T1620 — Reflective Code Loading: inferred — inner payload likely loaded/decrypted in memory by NSIS script
Capabilities
pdf-filename-masqueradecertificate-polymorphism-per-sample— fresh fabricated self-signed X.509 per sample (same structure, different word-salad subject)version-info-template-reuse— identical VS_VERSIONINFO block copied across buildsnsis-sfx-lzma-dropperfabricated-self-signed-certificate-masqueradeversion-info-word-salad-obfuscationencrypted-multi-payload-embedded-archivegibberish-filename-anti-triagedanish-character-skip-powershell-ciphercharacter-skip-polymorphism-stride-incrementnull-padding-archive-anti-triagebzip2-compression-variant— This sample uses BZip2 instead of LZMA in the NSIS archive, a minor toolchain variance observed also in sibling5212423bdeflate-compression-variant— This sample uses Deflate instead of LZMA or BZip2 in the NSIS archive, a new toolchain variance first observed in siblingcbdff40bpdf-masquerade-filename-engineeringmulti-pe-payload-stagingregistry-write-persistence(inferred from import profile)process-creation-payload-launch(inferred from import profile)iex-reflective-execution(inferred from PowerShell decode)multi-pe-payload-stagingsnydendes-hex-payload-helper— XOR-decoded hex payload segments processed by asnydendeshelper inside the decoded PowerShell; observed in sibling11a56375unsigned-nsis-variant— completely absent certificate directory, not even a fabricated self-signed cert; observed in siblings3c63a3c0and11a56375
Notable Analyses
- /intel/analyses/4978e16a7f6b716c324810ec44d5a82eeecd80382e4d5ccb4dc031cdc2559d9f.html — First observed sample; Italian payment lure (
Pagamento22052026.exe), single encrypted 145 KB payloadTyrolerne, static-only deep dive - /intel/analyses/f7f089f7f7753da939649fe98a4d274e44b837a61b72d022897858e1998cc7c4.html — Second confirmed sibling; PDF masquerade (
Quots-875-765-pdf.exe), four encrypted PE payloads (~2.5 MB total), Danish character-skip PowerShell obfuscation (Labourhoods.Mas, stride 6), static-only deep dive - /intel/analyses/cf9a061d02b0601036e3fd138e6b59ee6cdba3e5a40f8472171a56771ace341c.html — Third confirmed sibling; PDF masquerade (
EX777915904751.PDF.exe), two encrypted PE payloads (~679 KB total), Danish character-skip PowerShell obfuscation (Articulators.Inc, stride 8), null-padding decoy file, static-only deep dive - /intel/analyses/b3fb616de3993830d09c675bca2c146618abd5fbf8cd564702642d2eeb8aef10.html — Fourth confirmed sibling; "Revised_PI_2024.exe" payment-document lure, NSIS v3.02 exehead, six embedded payloads (four low-entropy encrypted PEs + one high-entropy encrypted blob + one PowerShell cradle), stride-6 Danish character-skip cipher (
Yod.Kat→IEX+ 8,710-char secondary payload). Static-only. - /intel/analyses/9c43b920900fe218212dec879c49c6b31b17ad0cda091818acff94a062b75fb8.html — Fifth confirmed sibling; "Documents.exe" generic-document masquerade, NSIS v3.02 exehead with MSVC 14.29 linker, six embedded payloads (three low-entropy encrypted PEs + one high-entropy encrypted binary + one obfuscated script + Danish word-salad text), fabricated self-signed cert (
Earthboard Venstrehngt Yock), no visible PowerShell cradle in extracted archive. Static-only. - /intel/analyses/78c5e8ca9474815c1cd85825b00d9be487a0e049fb827b12ef74bc57580cd3f5.html — Sixth confirmed sibling;
Ref_7021929821US20240709031221650.exeUS payment-reference lure, NSIS v3exeheadwith MSVC 6.0 linker, six embedded payloads (three low-entropy encrypted PEs + one high-entropy encrypted blob + one obfuscated PowerShell script + Danish word-salad text), stride-6 Danish character-skip cipher with fresh variable names ($Spirobranchiateuddhismens,$forbrndingsprocessernes), fabricated self-signed cert (Udskoling Begravedes Subscheme/Comoquer), reuses VS_VERSIONINFO template fromb3fb616d. Static-only. - /intel/analyses/5212423bac835b8c3268e4cf2b195043bdcd403e7d98f9182830098585ef2d1a.html — Seventh confirmed sibling;
PI_24000032.exeproforma-invoice lure, NSIS v3exeheadwith MSVC 14.29 linker (Oct 2022 — toolchain upgrade from MSVC 6.0), four embedded payloads (one obfuscated 161 KB PowerShell cradle + one 347 KB null-padded encrypted blob + one 7 KB high-entropy encrypted blob + Danish word-salad text), US-themed fabricated self-signed cert (Florida/Miami/Nonsuccessive), fresh VS_VERSIONINFO word-salad (bedimpled,excerpting,uddybendes cranberries). Static-only. - /intel/analyses/3a13583c51add43997b963edaabc063c1abf9600d404e1d0e49bf4d09665d104.html — Eighth confirmed sibling;
Product_samples_pdf.exePDF masquerade, NSIS v3exeheadwith MSVC 6.0 linker, five embedded payloads (one 344 KB high-entropy encrypted PEGravhje.Lse+ two null-padded blobs + one 55 KB stride-6 Danish character-skip PowerShell cradlePrsteskabets.Bes+ one Danish word-salad text decoyLakker153.txt), BZip2 compression (not LZMA — minor toolchain variance), fabricated self-signed cert (broomweed Dockyards Whelphood/Mazed/Westmont/Illinois), VS_VERSIONINFO word-salad (tyender marmoromkransedes,smrkages,wellhead). Static-only. - /intel/analyses/3c63a3c0670132e07fb90ca3c29ba35d898f6293bd40619a5611cb705e8b8212.html — Ninth confirmed sibling;
WORK_REPORT_FOR_YOUR_FILLING_AND_SUBMITTING_SCAN0012_PDF.com— first observed.comextension masquerade (not.exe), unsigned (no fabricated certificate, unlike all prior siblings), NSIS v3exeheadwith MSVC 6.0 linker, six embedded payloads (two high-entropy encrypted blobs + two low-entropy null-padded PEs + one 55 KB stride-6 Danish character-skip PowerShell cradleRockendes.Pot+ one Danish word-salad text decoyRooing.txt), LZMA:23 solid compression. VS_VERSIONINFO Comments:shrugs stoppekurvens droges, InternalName:forventnings.exe. Static-only. - /intel/analyses/11a563757a79333564f1eda8325816a621d4f404c282245c8a382f0ec9e2dcfb.html — Tenth confirmed sibling;
MY00111Q0562482MYKUL.pdf.exePDF masquerade, NSIS v3exeheadwith MSVC 6.0 linker, unsigned (no certificate directory at all — second unsigned sibling after3c63a3c0), BZip2 compression (not LZMA), ten embedded payloads (one 52 KB stride-6 Danish character-skip PowerShell cradleLabourhoods.Mas+ six encrypted blobs + two Danish decoy texts + one directory placeholder). VS_VERSIONINFO word-salad (standpat pejsene predestinarianism,mouser brazenface computerberegnendes,koagulere.exe). Decoded PowerShell revealssnydendeshex-payload helper processing four XOR-keyed segments (94B3A8,81A3B28BA9A2B3AAA38EA7A8A2AAA3,85AAA7B5B5EAE696B3A4AAAFA5EAE695A3A7AAA3A2EAE687A8B5AF85AAA7B5B5,9A). Largest payload count in cluster to date. Static-only. - /intel/analyses/cbdff40bf525a8fdbb771e23e9da6463a380c7e6264236226a9909c8bc141889.html — Eleventh confirmed sibling;
inquiry_4387.exebusiness-inquiry lure, NSIS v3.06.1exeheadwith MSVC 6.0 linker, unsigned (third unsigned sibling, ~27% unsigned rate across cluster), Deflate compression (first Deflate variant — prior siblings used LZMA or BZip2), six embedded payloads inDerms/subdirectory (four null-padded encrypted PEs + one high-entropy blobthwack.Ins+ one mid-entropyAbnormal78.Nep+ Danish word-salad decoyRehang.txt). VS_VERSIONINFO word-salad (dechifrerbare merceress,pompejansk husdyrsygdom.exe,bellied peafowls saddelplads). No PowerShell cradle recovered statically. Static-only.
Related
- iexpress-sfx-dropper — Another legitimate Microsoft self-extractor repurposed for malware delivery
- version-info-masquerade — Shared concept of falsifying VS_VERSIONINFO fields
- nsis-lzma-embedded-payload — Technique page for NSIS archive payload hiding
- character-skip-cipher-powershell-obfuscation — Technique page for the Danish PowerShell obfuscation pattern observed in the
f7f089f7sibling