General

  • Target

    Frozen Spoofer.rar

  • Size

    34.9MB

  • MD5

    8a93edd0031969834fc755632e90763c

  • SHA1

    ea710727accc41d50b894fb7798302f6011b3e50

  • SHA256

    85bbf058c82fa2979a3f3fa7e9b300711cacdf5da405006f3ef0265d29bf368d

  • SHA512

    9d156c5f2f64b37fc2ebf60997b4cfdf4f9953e12a0a059930ced74a9dde761431925e3c5127026edc5fe2781a9bc08902e2ba013056bb0c43bf2b1c39a66fb5

  • SSDEEP

    786432:YBJThnJEz1K4XtozlSrttrX9r3FcF6CSwKKnfFr0Mf:uJTpJM1dXtAlSBF97FJWfmMf

Score
7/10

Malware Config

Signatures

  • Obfuscated with Agile.Net obfuscator 2 IoCs

    Detects use of the Agile.Net commercial obfuscator, which is capable of entity renaming and control flow obfuscation.

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • Frozen Spoofer.rar
    .rar
  • Frozen Spoofer/AgileDotNet.VMRuntime.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Frozen Spoofer/Guna.UI.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Frozen Spoofer/Guna.UI2.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Frozen Spoofer/Siticone.UI.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Frozen Spoofer/permunban.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections