
Fireball/Elex Adware: 14 DLLs Built in a Four-Day Cycle
A cluster of unsigned Windows DLLs compiled within a four-day window in January 2017 shares a builder fingerprint tight enough to trace to a single toolkit. Filename-matched YARA rules, a shared vhash skeleton, and a reused service-path string tie the cohort to the Fireball/Elex/Sasquor adware family rather than a bespoke intrusion set.
A cluster of fourteen unsigned Windows DLLs — plus one companion executable — compiled between January 23 and January 26, 2017 shares a builder fingerprint tight enough to read like a single production run. The modules carry deliberately mundane names: RegKey.dll, Skytech.dll, ClearLog.dll, Packet.dll, MIO.dll, Berserker.dll, Install.dll, Lancer.dll, At.dll, and a standalone WinTooll.exe. None are signed.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read