General

  • Target

    archive.rar

  • Size

    17.7MB

  • MD5

    9d10f6f08ae1cc016c10b09007063417

  • SHA1

    9b440d571937c06865d148d05eac86d7bbb1d3ea

  • SHA256

    ce4d3cfc167dc8234d14cf91e20131b2c2fc10793a5aab4a76d1cd6a793dcf88

  • SHA512

    7ff1e08754df7d59d8d891c2b3b5d9b813f4834f33033d0998efd241374a4c65718aa8c0439c4c4c8fa767663ea19c7f286f24793ff48e07003fb8748b86830d

  • SSDEEP

    393216:haC3cy3EcC7LniVNZGfmpuoMv6uT9UXzcb+m+wtEVPK:hJ9xC7jievv6uRUXgiXwT

Score
3/10

Malware Config

Signatures

  • Unsigned PE 16 IoCs

    Checks for missing Authenticode signature.

Files

  • archive.rar
    .rar

    Password: 1234

  • ResIL.dll
    .dll windows:6 windows x86 arch:x86

    Password: 1234

    77b2a6efb5db23bab61e38152791c9e9


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • libGLESv2.dll
    .dll windows:5 windows x86 arch:x86

    Password: 1234

    3ae3956ab1353e92ed1a21ca2229382b


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • res_mods/1.23.0.0/scripts/client/gui/mods/7zA.exe
    .exe windows:4 windows x86 arch:x86

    Password: 1234

    1a9deef54b6b9763013f742bee84d533


    Headers

    Imports

    Sections

  • res_mods/1.24.0.0/readme.txt
  • res_mods/1.25.0.0/readme.txt
  • setup.exe
    .exe windows:6 windows x86 arch:x86

    Password: 1234

    448b6888b26145ced7ce018aab459303


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (10) — копия.dat
  • update/Uninstall/unins000 — копия (10) — копия.exe
    .exe windows:5 windows x86 arch:x86

    Password: 1234

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (11) — копия.dat
  • update/Uninstall/unins000 — копия (11) — копия.exe
    .exe windows:5 windows x86 arch:x86

    Password: 1234

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (12) — копия.dat
  • update/Uninstall/unins000 — копия (12) — копия.exe
    .exe windows:5 windows x86 arch:x86

    Password: 1234

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (13) — копия.dat
  • update/Uninstall/unins000 — копия (13) — копия.exe
    .exe windows:5 windows x86 arch:x86

    Password: 1234

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (2) — копия.dat
  • update/Uninstall/unins000 — копия (2) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (2).dat
  • update/Uninstall/unins000 — копия (2).exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (3) — копия.dat
  • update/Uninstall/unins000 — копия (3) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (5).dat
  • update/Uninstall/unins000 — копия (5).exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (6) — копия.dat
  • update/Uninstall/unins000 — копия (6) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (6).dat
  • update/Uninstall/unins000 — копия (6).exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (7) — копия.dat
  • update/Uninstall/unins000 — копия (7) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (7).dat
  • update/Uninstall/unins000 — копия (7).exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (8) — копия.dat
  • update/Uninstall/unins000 — копия (8) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/Uninstall/unins000 — копия (9) — копия.dat
  • update/Uninstall/unins000 — копия (9) — копия.exe
    .exe windows:5 windows x86 arch:x86

    ab2499e0e72dfad09db9c131cd20670f


    Headers

    Imports

    Sections

  • update/app_type.xml
    .xml
  • update/config.ini
  • update/part1.7z
    .7z
  • update/part2.7z
    .7z
  • update/part3.7z
    .7z
  • version.xml
  • vivoxsdk.dll
    .dll windows:6 windows x86 arch:x86

    efaa61aec68c12fcf59804931c998357


    Code Sign

    Headers

    Imports

    Exports

    Sections