General

  • Target

    d4164b1dab1337e28d3ce097a32b8635c893e1acaaf7136e745b90c44ee2cf05

  • Size

    4.8MB

  • MD5

    4aabaf1f2d1daaba7ac4c9fc9498e59f

  • SHA1

    a975ce8ba928dc4e1562a7d277bb309f7c06f712

  • SHA256

    d4164b1dab1337e28d3ce097a32b8635c893e1acaaf7136e745b90c44ee2cf05

  • SHA512

    5a54a2bee850be430983af39a184c9fe2c42252e4e24dd3b9aa49d4de92c61226c7c0b00018221b8364f4c7ddfd35ea9b0958ddda6dae601d314ba526170f1d9

  • SSDEEP

    98304:66Q2rqI0O7L41KUOY3Aqrvj99849cOjk2WQV14ayHLQ3AA:66Q2rqI0O7Lfa3Aqrz849cckI14FMf

Score
10/10

Malware Config

Signatures

  • UPX dump on OEP (original entry point) 1 IoCs
  • ACProtect 1.3x - 1.4x DLL software 1 IoCs

    Detects file using ACProtect software.

  • ASPack v2.12-2.42 1 IoCs

    Detects executables packed with ASPack v2.12-2.42

  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 9 IoCs

    Checks for missing Authenticode signature.

Files

  • d4164b1dab1337e28d3ce097a32b8635c893e1acaaf7136e745b90c44ee2cf05
    .exe windows:5 windows x86 arch:x86

    b729b61eb1515fcf7b3e511e4e66258b


    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:5 windows x86 arch:x86

    039bcbc605477e8e87ec550c2e60e748


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/bar.bmp
  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:5 windows x86 arch:x86

    9ea5bdc8c90dfcffe309465c26c89758


    Headers

    Imports

    Exports

    Sections

  • $TEMP/ulicense.rtf
    .rtf
  • Data/Data.pack
  • FarmFrenzy3_America.exe
    .exe windows:5 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • FarmFrenzy3_America.wrp.exe
    .exe windows:4 windows x86 arch:x86

    e94e021976b1047ad56fe91cb5099023


    Headers

    Imports

    Sections

  • JNGLoad.dll
    .dll windows:4 windows x86 arch:x86

    b019958100a358b3512fda93f23b2ae9


    Headers

    Imports

    Exports

    Sections

  • Squall.dll
    .dll windows:4 windows x86 arch:x86

    683559c4c245f4cde98c8ffb08209927


    Headers

    Imports

    Exports

    Sections

  • htmlayout.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Exports

    Sections

  • out.upx
    .dll windows:4 windows x86 arch:x86


    Headers

    Sections

  • license.txt
  • manifest.xml
    .xml
  • partner.ini
  • registrator.ini
  • wrapper.dll
    .dll windows:5 windows x86 arch:x86


    Headers

    Exports

    Sections