General

  • Target

    GlassWireSetup.exe

  • Size

    78.8MB

  • MD5

    7b6cc2a288ff0738ca69d4bf6688b5e2

  • SHA1

    06c050428c0708d2f20d464f4ec43b3518dab58e

  • SHA256

    4ddaa14f57744b2cac875ffb15a09e49246b9a45ab3c1122dca7aa47f820a1f2

  • SHA512

    25bd4b3680a0b83949b1b9b27307be14e22946e44415f1525fd42d6d32f7c414659b5652716220be34a3f65cd22dbd351b4309bd279f3fb72cd5178cc9b26da1

  • SSDEEP

    1572864:V0SU7bAyCN59pjGHal/j7CKh3/YtSh/2T3+IzVgEu6ns8g2zZxC5snRKEn/zNHMJ:V0SU7EJvrl7+C3AoNg35Zg12fC5snjxW

Score
7/10

Malware Config

Signatures

  • Themida packer 3 IoCs

    Detects Themida, an advanced Windows software protection system.

  • Unsigned PE 8 IoCs

    Checks for missing Authenticode signature.

Files

  • GlassWireSetup.exe
    .exe windows:4 windows x86 arch:x86

    f4639a0b3116c2cfc71144b88a929cfd


    Headers

    Imports

    Sections

  • $APPDATA/GlassWire/share/storage.db
  • $PLUGINSDIR/GWInstSt.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • $PLUGINSDIR/StartMenu.dll
    .dll windows:4 windows x86 arch:x86

    646971a3aef724d6f553f40ae84fe26b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    509a34b3a68a773e0afb4259e68f9f82


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/eventlog.man
    .xml
  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:4 windows x86 arch:x86

    3b477381217c97b22146297f93df2a92


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    68b7023f8923dd087549802f8fa631c3


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsihelper.dll
    .dll windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • $PLUGINSDIR/vc_redist.x86.exe
    .exe windows:5 windows x86 arch:x86

    1a5cdbf711fee14b077e599d13fddab2


    Code Sign

    Headers

    Imports

    Sections

  • GWCtlSrv.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • GWEventLog.dll
    .dll windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • GWIdlMon.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • GWUnlock.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • GWUpgradeMonitor.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • GlassWire.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • Qt5Core.dll
    .dll windows:6 windows x86 arch:x86

    92fc526ad6d9674f09604104cfa57819


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Qt5Gui.dll
    .dll windows:6 windows x86 arch:x86

    443275a6eb00ad3c85c2bc9c3fc2da3e


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Qt5OpenGL.dll
    .dll windows:6 windows x86 arch:x86

    001e5e687428b22462285c2750754dae


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Qt5Svg.dll
    .dll windows:6 windows x86 arch:x86

    079b726a4a2f3a027f09f1cb4e2ed381


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Qt5Widgets.dll
    .dll windows:6 windows x86 arch:x86

    7485e296f2ad020a3dedc3de1b20dcfc


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • Qt5WinExtras.dll
    .dll windows:6 windows x86 arch:x86

    6a5932ee8dcef2f266e2e0e799f280b3


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • copyrights/ASIO-LICENSE_1_0.txt
  • copyrights/CURL-COPYING.txt
  • copyrights/GEOIP-LICENSE.txt
  • copyrights/GEOLITE2-COPYRIGHT.txt
  • copyrights/GEOLITE2-LICENSE.txt
  • copyrights/LZ4-LICENSE.txt
  • copyrights/OPENSSL-LICENSE.txt
  • copyrights/PROTOBYUF-LICENSE.txt
  • copyrights/QT-LICENSE.GPL3-EXCEPT.txt
  • copyrights/QT-LICENSE.txt
  • copyrights/RAPIDJSON-LICENSE.txt
  • copyrights/RAPIDXML-LICENSE.txt
  • copyrights/RECOG-COPYING.txt
  • copyrights/RLOTTIE-COPYING.MIT.txt
  • copyrights/SQLITE-COPYING.txt
  • copyrights/ZLIB-LICENSE.txt
  • driver/win-x64/gwdrv.cat
  • driver/win-x64/gwdrv.inf
  • driver/win-x64/gwdrv.sys
    .sys windows:6 windows x64 arch:x64

    f5dcd03cf0a08bfffee94eee61f2b56e


    Code Sign

    Headers

    Imports

    Sections

  • driver/win-x86/gwdrv.cat
  • driver/win-x86/gwdrv.inf
  • driver/win-x86/gwdrv.sys
    .sys windows:6 windows x86 arch:x86

    bc0fcd1e1a98457542ab10b8485f843f


    Code Sign

    Headers

    Imports

    Sections

  • driver/win7-x64/gwdrv.cat
  • driver/win7-x64/gwdrv.inf
  • driver/win7-x64/gwdrv.sys
    .sys windows:6 windows x64 arch:x64

    f5dcd03cf0a08bfffee94eee61f2b56e


    Code Sign

    Headers

    Imports

    Sections

  • driver/win7-x86/gwdrv.cat
  • driver/win7-x86/gwdrv.inf
  • driver/win7-x86/gwdrv.sys
    .sys windows:6 windows x86 arch:x86

    bc0fcd1e1a98457542ab10b8485f843f


    Code Sign

    Headers

    Imports

    Sections

  • iconengines/qsvgicon.dll
    .dll windows:6 windows x86 arch:x86

    e2a8abb2f62e90497419fca861c4de3a


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • imageformats/qico.dll
    .dll windows:6 windows x86 arch:x86

    b127d2b5eb2d64741e8cf3a684f53083


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • lang/de_de.qm
  • lang/en_gb.qm
  • lang/en_us.qm
  • lang/es_es.qm
  • lang/fr_fr.qm
  • lang/it_it.qm
  • lang/ja_jp.qm
  • lang/ko_kr.qm
  • lang/pl_pl.qm
  • lang/pt_br.qm
  • lang/ru_ru.qm
  • lang/tr_tr.qm
  • lang/zh_cn.qm
  • lang/zh_tw.qm
  • platforms/qwindows.dll
    .dll windows:6 windows x86 arch:x86

    29ed2e73839186c2a3b5a58cddc0eb48


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • plugins/windows.dll
    .dll windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections

  • uninstall.exe
    .exe windows:4 windows x86 arch:x86

    f4639a0b3116c2cfc71144b88a929cfd


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/GWInstSt.exe
    .exe windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    509a34b3a68a773e0afb4259e68f9f82


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/eventlog.man
    .xml
  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:4 windows x86 arch:x86

    3b477381217c97b22146297f93df2a92


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:4 windows x86 arch:x86

    68b7023f8923dd087549802f8fa631c3


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsihelper.dll
    .dll windows:6 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections