General

  • Target

    __x64___setup___x32__.zip

  • Size

    26.0MB

  • MD5

    834495947f826a32ec96ba9c4bb9ecfa

  • SHA1

    f5e122c0f5e8fb25189fdaf7667c620f5154bf24

  • SHA256

    d634a0cccedb8877e4f6e2dd9d59975f6a8dfcd767c75c478f2d7a97cd3469ef

  • SHA512

    3b9f713122426ddf78ad8ee1550e7ff9ae6e3f41e473c9a99e84735f001f523213b4b069b3dfeb3d1c60d324e38b41bddf1d2850efc677ce5f9571d246630c92

  • SSDEEP

    786432:k2dKy4NXj3zLVoPkc6w51UrcL2kpVFBO7PIUqM:PONXj3/Vmb51YQ2kpVFY7PItM

Score
3/10

Malware Config

Signatures

  • Unsigned PE 16 IoCs

    Checks for missing Authenticode signature.

Files

  • __x64___setup___x32__.zip
    .zip

    Password: 2024

  • AppxSip/AppxSip.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    Password: 2024

    e06fe0d53e5834d5eeea2d913edb0995


    Headers

    Imports

    Exports

    Sections

  • AppxSip/MSVidCtl.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    Password: 2024

    dd5e8a87d388e7f0e0dcb3f9ea5a64ef


    Headers

    Imports

    Exports

    Sections

  • AppxSip/deploymentcsps.dll
    .dll windows:10 windows x64 arch:x64

    Password: 2024

    2e29e86a1a3973521736ecbfb4f9b5b5


    Headers

    Imports

    Exports

    Sections

  • AppxSip/devenum.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    Password: 2024

    4c9079c33bef679868c8dc14bf0fe71a


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • SEMgrPS/SEMgrPS.dll
    .dll windows:10 windows x64 arch:x64

    Password: 2024

    7dcc2d309d96727b06e1bbb65b6597f9


    Headers

    Imports

    Exports

    Sections

  • SEMgrPS/SensorsApi.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    Password: 2024

    93f00183f6b2824f35a5ab3c1bf4de20


    Headers

    Imports

    Exports

    Sections

  • SEMgrPS/netprofmsvc.dll
    .dll windows:10 windows x64 arch:x64

    Password: 2024

    ad45623529f9b4402c7d26b5ea54d733


    Headers

    Imports

    Exports

    Sections

  • SEMgrPS/wcimage.dll
    .dll windows:10 windows x64 arch:x64

    Password: 2024

    f8fb756be0e3bc5854c867138bb76490


    Headers

    Imports

    Exports

    Sections

  • dsreg/dcntel.dll
    .dll windows:10 windows x64 arch:x64

    297a2ad90ecd0a9d6f27b16387dae5ef


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • dsreg/dsound.dll
    .dll windows:10 windows x64 arch:x64

    7257aa932ac77b1d2e29b45383b4e0a6


    Headers

    Imports

    Exports

    Sections

  • dsreg/dsreg.dll
    .dll windows:10 windows x64 arch:x64

    1cac4312a6dde042a044bb0a45c42d48


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • dsreg/sensrsvc.dll
    .dll windows:10 windows x64 arch:x64

    7980291b053dc0ce2145ce6b777cd2ca


    Headers

    Imports

    Exports

    Sections

  • netprofm/TapiSysprep.dll
    .dll windows:10 windows x64 arch:x64

    397bc475fccba616c4c1b87402a4b3b1


    Headers

    Imports

    Exports

    Sections

  • netprofm/netprofm.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    affb8b2ee176e881ad572d4ee006ac27


    Headers

    Imports

    Exports

    Sections

  • netprofm/rpcnsh.dll
    .dll windows:10 windows x64 arch:x64

    00ce5d3d7014818cc40866bdfd22be77


    Headers

    Imports

    Exports

    Sections

  • netprofm/socialapis.dll
    .dll windows:10 windows x64 arch:x64

    d9b95dc964953cd6b1c3f52ff54556e6


    Headers

    Imports

    Exports

    Sections

  • pcwum/AppxSip.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    e06fe0d53e5834d5eeea2d913edb0995


    Headers

    Imports

    Exports

    Sections

  • pcwum/asferror.dll
    .dll windows:10 windows x64 arch:x64


    Headers

    Sections

  • pcwum/pcwum.dll
    .dll windows:10 windows x64 arch:x64


    Code Sign

    Headers

    Exports

    Sections

  • pcwum/pdhui.dll
    .dll windows:10 windows x64 arch:x64

    aede04ec0542987e57567a203b6b82c7


    Headers

    Imports

    Exports

    Sections

  • setup.msi
    .msi