Resubmissions

01-07-2024 19:00

240701-xnp9zstfnc 5

01-07-2024 18:54

240701-xkj9kaxflj 4

01-07-2024 18:53

240701-xjrbgstdrf 10

01-07-2024 18:44

240701-xdytdatbqe 7

General

  • Target

    ezyZip.zip

  • Size

    1.0MB

  • MD5

    78bd0901f4a5a3476c8887c73e730d30

  • SHA1

    3c04901951285ada89943d42eda7020c54e24e84

  • SHA256

    9d0547070e294e4158e6c446fa2295f5ae170f31cc64d677c5261d14caf38ab8

  • SHA512

    383e5fde5928dd91526832934a0ed7e34b502be370407e8f05c6c67a427decc328e44c0ffe6aeb0357f51c7acc751a4f8167e6e043e744186821eaec5e619c07

  • SSDEEP

    24576:DxladE0NO6cWgTzE3+3pLVuLOhkC1xepCJ1FvNJW:DxlWE0NO6cbQ3+dVuG1uM1FVs

Score
3/10

Malware Config

Signatures

  • Unsigned PE 3 IoCs

    Checks for missing Authenticode signature.

Files

  • ezyZip.zip
    .zip
  • ARSoft.Tools.Net.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Autofac.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • GalaSoft.MvvmLight.Platform.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • GalaSoft.MvvmLight.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • JudgeLZT.exe
    .exe windows:6 windows x86 arch:x86

    56baef533a2c1ed14f3f4ef31918aea1


    Headers

    Imports

    Exports

    Sections

  • TapInstaller.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • WSearchMigPlugin.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    21438ba29a45a5e6f86523b4d07c6854


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • WpcMigration.Uplevel.dll
    .dll windows:10 windows x64 arch:x64

    bfbca9b8d50e954bd17d06c0d4c4155a


    Headers

    Imports

    Exports

    Sections

  • WsUpgrade.dll
    .dll regsvr32 windows:10 windows x64 arch:x64

    30ae43715c9ec65454cd7a4ef5927068


    Headers

    Imports

    Exports

    Sections