General

  • Target

    !!SetUp_!PaS$Kḙy$!_60814.zip

  • Size

    14.2MB

  • MD5

    34d313d321f156375b0c3f94ea9e4936

  • SHA1

    78450c7f1133106f206a8abeb111ca4e448ba4e2

  • SHA256

    5cf127ccb4d461cd11701d8b949ed45af04f6ca188a24c482cefc2a26583c721

  • SHA512

    6c578110b1d2c1d5d150182af4a5949ae63bf7c0c622ce519df83c954b3a8710596ec1546dbb01ea300fe408533f0c51604604720195d44947cca9b246bd4b52

  • SSDEEP

    393216:T6m4tr0MMMp/Ms3txYv0hAXV0rFQND/iA0uLyw:m9t4MZ/MyxYcWXW+9iBw

Score
3/10

Malware Config

Signatures

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • !!SetUp_!PaS$Kḙy$!_60814.zip
    .zip
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/am.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/ar.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fi.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fil.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/8514sys.fon
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/dosapp.fon
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/smalle.fon
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/symbol.ttf
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/trebucbd.ttf
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/trebucbi.ttf
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/verdana.ttf
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fonts/verdanab.ttf
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/fr.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/gu.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/he.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/hi.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/hr.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/hu.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/id.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/lt.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/Locals/lv.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/an.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ar.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/az.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ba.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/be.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/bg.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/bn.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ca.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/chrome_[1MB]_[1].exe
    .exe windows:5 windows x86 arch:x86

    53811707eb72202ebb2c8f39bfac68c5


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • !!SetUp_!PaS$Kḙy$!_60814/Language/co.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/cs.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/da.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/de.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/el.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/en-US/AutoWorkplaceN.dll.mui
    .dll windows:6 windows x86 arch:x86


    Headers

    Sections

  • !!SetUp_!PaS$Kḙy$!_60814/Language/en-US/avicap32.dll.mui
    .dll windows:6 windows x86 arch:x86


    Headers

    Sections

  • !!SetUp_!PaS$Kḙy$!_60814/Language/eng.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/es.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/et.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/eu.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ext.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/fa.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/fi.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/fr.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/fur.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/fy.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ga.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/gl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/gu.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/he.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/he.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hi.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hi.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hr.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hr.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hu.pak
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hu.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/hy.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/id.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/is.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/it.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ja.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ka.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/kaa.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/kab.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/kk.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ko.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ku-ckb.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ky.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/lij.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/lt.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/mk.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/mn.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/mng.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/mng2.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/mr.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ne.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/nl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/pa-in.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/pl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ps.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/pt-br.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/pt.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ro.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ru.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sa.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/si.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sk.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sr-spc.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sr-spl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sv.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/sw.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ta.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/tg.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/th.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/tk.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/tr.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/tt.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/ug.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/uk.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/uz-cyrl.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/uz.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/va.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/vi.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/yo.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/zh-cn.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Language/zh-tw.txt
  • !!SetUp_!PaS$Kḙy$!_60814/Setup.exe
    .exe windows:5 windows x64 arch:x64

    b7e244ba46aac2a40ea643244bcedc5b


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • !!SetUp_!PaS$Kḙy$!_60814/caret.xls
  • !!SetUp_!PaS$Kḙy$!_60814/identity_helper.zip
    .zip
  • caret.xls
  • identity_helper.exe
    .exe windows:5 windows x64 arch:x64

    b7e244ba46aac2a40ea643244bcedc5b


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • msedge_elf.dll
    .dll windows:5 windows x64 arch:x64

    e5e4f3f5367c0c82df24a4723fbd8a3c


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • test.asp
  • !!SetUp_!PaS$Kḙy$!_60814/msedge_elf.dll
    .dll windows:5 windows x64 arch:x64

    e5e4f3f5367c0c82df24a4723fbd8a3c


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • !!SetUp_!PaS$Kḙy$!_60814/resources.pak
  • !!SetUp_!PaS$Kḙy$!_60814/test.asp
  • !!SetUp_!PaS$Kḙy$!_60814/vcruntime140.dll
    .dll windows:6 windows x64 arch:x64

    44c3854843f7a3fccdf8ddbbea66f302


    Code Sign

    Headers

    Imports

    Exports

    Sections