Resubmissions

04-07-2024 17:22

240704-vxyavazeql 10

04-07-2024 17:19

240704-vv7rhazenr 10

General

  • Target

    pepsi (5).rar

  • Size

    71.8MB

  • MD5

    f5f163cbcc1e6c5dc86e9df0daa0f200

  • SHA1

    2dfdfabd15e90a09e64dedce5fdea5f3529cbbfb

  • SHA256

    e2cadb0766cf2fc20a527c917f4475388ef3fbd73b8e0c6d071b695afbb1dba3

  • SHA512

    895048370d6fa90f1b842e1fd087d26f58da81d288ef344a5a412409c394222a3da9f89e19260b83a7634dd7c923ffd0bd339e4cff6da5a8ef4786ace6719e1d

  • SSDEEP

    1572864:4eXLeXak7DEoGipeXAeXUdeXoJAku3eXgb/BJ3/8XZPawDyXt3FYH:4eber7DEodewekdeFku3eQb/H+Zyx3Fu

Malware Config

Signatures

  • Blackmoon family
  • Detect Blackmoon payload 1 IoCs
  • Themida packer 1 IoCs

    Detects Themida, an advanced Windows software protection system.

  • UPX packed file 3 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • VMProtect packed file 1 IoCs

    Detects executables packed with VMProtect commercial packer.

  • AutoIT Executable 5 IoCs

    AutoIT scripts compiled to PE executables.

  • Unsigned PE 73 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 4 IoCs

Files

  • pepsi (5).rar
    .rar
  • [DemonArchives]01be7be288126004a6b6013cfa9630f3.exe
    .exe windows:1 windows x86 arch:x86

    95e6f8741083e0c7d9a63d45e2472360


    Headers

    Imports

    Sections

  • [DemonArchives]02352cbf001e9c8176a5b7d381ef9b5e.exe
    .exe windows:1 windows x86 arch:x86

    26babd76bbb7f9c516a338b0601b4c9f


    Headers

    Imports

    Sections

  • [DemonArchives]02fa60c2391dc09e9a0b748a9d89c6a8.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]04a8e202d70a574213680cdb7c82fb55.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]05e82b287218043df6c8560cd0e2719c.exe
    .exe windows:5 windows x86 arch:x86

    a8c436d9a0e5e9875d8e3a40db9db0a8


    Headers

    Imports

    Sections

  • [DemonArchives]07fe5f7c673e5faa200611f9cb716aac.exe
    .exe windows:1 windows x86 arch:x86

    c2a87fabf96470db507b2e6b43bd92eb


    Headers

    Imports

    Sections

  • [DemonArchives]086b605fada00eaa39fca0581712f10f.exe
    .exe windows:1 windows x86 arch:x86

    0b36fc85e0cb5e337c80982db5210969


    Headers

    Imports

    Sections

  • [DemonArchives]09f326448c37d99a61bb064e68ac6b94.exe
    .exe windows:1 windows x86 arch:x86

    0b36fc85e0cb5e337c80982db5210969


    Headers

    Imports

    Sections

  • [DemonArchives]0a47e2885329b83d82525cb438e57f7e.exe
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]0d061414e840b27ea6109e573bd2165a.exe
    .exe windows:4 windows x86 arch:x86

    8abecba2211e61763c4c9ffcaa13369e


    Headers

    Imports

    Sections

  • [DemonArchives]1192a915b81f1f7878472391f42cb6c4.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]14049d0a3afad0faa21ab1fff2e417f3.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]149dd5469233f52aa4287362ce85b88f.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]1df7772347bfd34ecb1685a1ba69c285.exe
    .exe windows:1 windows x86 arch:x86

    26babd76bbb7f9c516a338b0601b4c9f


    Headers

    Imports

    Sections

  • [DemonArchives]1e0dc068677f96c9da7f43cf4d4acd92.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]1ee7f65b0c08c4ff7e1047c14851575b.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]1fa9dbcc19fb2ae5cd344f559e95b759.exe
    .exe windows:4 windows x86 arch:x86

    9d5552b3a103c723c650b0d7a6310980


    Headers

    Imports

    Sections

  • [DemonArchives]227f3ff19943a0e8c1b26a563246280f.exe
    .exe windows:1 windows x86 arch:x86

    26babd76bbb7f9c516a338b0601b4c9f


    Headers

    Imports

    Sections

  • [DemonArchives]2353c3f467be78e36e934caf5f3c3b61.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]26add802e0e75416385317658b116216.exe
    .exe windows:1 windows x86 arch:x86

    3235d0a66c0a8ca4d8b84f3bea439dce


    Headers

    Imports

    Sections

  • [DemonArchives]2bf9e607accd325cfb734cd594b00723.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]3825817f6028f26ff0b5cd748559286d.exe
    .exe windows:5 windows x86 arch:x86

    9cc1c069ad89fcb9f40f4af896733a4c


    Headers

    Imports

    Sections

  • [DemonArchives]3e70eabf850c2134ac1acd815a2a90af.exe
    .exe windows:1 windows x86 arch:x86

    26babd76bbb7f9c516a338b0601b4c9f


    Headers

    Imports

    Sections

  • [DemonArchives]41637d74a16e50cafe6cb72974a1cf5c.exe
    .exe windows:5 windows x86 arch:x86

    270ef27c034d928c4437a4fdbd9809c4


    Headers

    Imports

    Sections

  • [DemonArchives]42971155e95ad8ace7b6fc53d70fb952.exe
    .exe windows:10 windows x86 arch:x86

    646167cce332c1c252cdcb1839e0cf48


    Headers

    Imports

    Sections

  • [DemonArchives]47522f57257b441811cf5f87c9118faf.exe
    .exe windows:1 windows x86 arch:x86

    95e6f8741083e0c7d9a63d45e2472360


    Headers

    Imports

    Sections

  • [DemonArchives]4782545d269557614be88caef0383cfa.exe
    .exe windows:1 windows x86 arch:x86

    3235d0a66c0a8ca4d8b84f3bea439dce


    Headers

    Imports

    Sections

  • [DemonArchives]4bed82d2182d95951a4dd3b090868cf1.exe
    .exe windows:4 windows x86 arch:x86

    1a611a7df1f3828b0157c4725145a721


    Headers

    Imports

    Sections

  • [DemonArchives]4c1ca9436c971190f7082f5c108a007b.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]4fd60e9aed5ab9ed5326da37806b2502.exe
    .exe windows:5 windows x86 arch:x86

    270ef27c034d928c4437a4fdbd9809c4


    Headers

    Imports

    Sections

  • [DemonArchives]550ad0e50316dfca7c0bfd14f9060880.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]55a0c8c7e6c8b2be4ebd164d43e746c8.exe
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]560184b003e9c461fdfa4ab15cd3b6fb.exe
    .exe windows:4 windows x86 arch:x86

    248461eeaf5ea1b28d70b9495192cb5d


    Headers

    Imports

    Exports

    Sections

  • [DemonArchives]58b00f133ec3b7efa68faf94233d594e.exe
    .exe windows:4 windows x86 arch:x86

    099c0646ea7282d232219f8807883be0


    Headers

    Imports

    Sections

  • $PLUGINSDIR/CheckInstall.exe
    .exe windows:5 windows x86 arch:x86

    1e06b1e51c07b4f145d681ea3c56d9b6


    Headers

    Imports

    Sections

  • $PLUGINSDIR/InstallOptions.dll
    .dll windows:4 windows x86 arch:x86

    dec6b15c0428dbfe68002d314aeabddf


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/ioSpecial.ini
  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/modern-wizard.bmp
  • AutoShutdown.exe
    .exe windows:5 windows x86 arch:x86

    8f6ab9ff71d108d0e3816839ecec811b


    Headers

    Imports

    Sections

  • ClonedFileCleaner.exe
    .exe windows:5 windows x86 arch:x86

    68e7fb65f33a2170ff7a847adb260cef


    Headers

    Imports

    Sections

  • FilePulverizer.exe
    .exe windows:5 windows x86 arch:x86

    534a01922bcaf1cfc0ccede17be13f25


    Headers

    Imports

    Sections

  • StartupManager.exe
    .exe windows:5 windows x86 arch:x86

    43571c92784d74a1beab6ff2eeb57dbc


    Headers

    Imports

    Sections

  • SweepHelper.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • SystemInformation.exe
    .exe windows:5 windows x86 arch:x86

    3e1894e298aa282e9eb9e8668bc36691


    Headers

    Imports

    Sections

  • SystemSpeedBooster.exe
    .exe windows:5 windows x86 arch:x86

    4d3e6dc8104daa9dcdba98c9782a5279


    Code Sign

    Headers

    Imports

    Sections

  • const.dat
  • data/topic.db
  • data/utilities.db
  • lang/English.lan
  • res/16.png
    .png
  • res/32.png
    .png
  • res/btnpanel.dat
  • res/icon.ico
  • res/images/about.png
    .png
  • res/images/background.png
    .png
  • res/info.html
    .html
  • res/trialnotify.mht
    .eml
  • attachment-2
    .gif
  • email-html-1.txt
  • skins/default.skn
  • uninst.exe
    .exe windows:4 windows x86 arch:x86

    099c0646ea7282d232219f8807883be0


    Headers

    Imports

    Sections

  • $PLUGINSDIR/modern-header.bmp
  • [DemonArchives]627ba000cff6d43aa031da4020d15186.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]68d0fb679004d3c27c9efa840010881e.exe
    .exe windows:1 windows x86 arch:x86

    0b36fc85e0cb5e337c80982db5210969


    Headers

    Imports

    Sections

  • [DemonArchives]6a1fe8f4fbbc726b6ee093b2688a33a6.exe
    .exe windows:4 windows x86 arch:x86

    1a611a7df1f3828b0157c4725145a721


    Headers

    Imports

    Sections

  • [DemonArchives]6bc2fcef470b064c9bd339c7e2553ea8.exe
    .exe windows:5 windows x86 arch:x86

    34f0650968d4cf389ecba63cd4240d8c


    Headers

    Imports

    Sections

  • [DemonArchives]6bf80d8b5b235df5efb621da1dd61b4b.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]6e102d15d6af7c43d43141e9d2a1206b.exe
    .dll windows:5 windows x86 arch:x86

    ed1351e76ec05c9dcdf307ed99cbd875


    Headers

    Imports

    Sections

  • [DemonArchives]6e4f9763c17ea31c3d1406eabd7db423.exe
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]720d7d1deff763aee99bcc266f96b238.exe
    .exe windows:1 windows x86 arch:x86

    0b36fc85e0cb5e337c80982db5210969


    Headers

    Imports

    Sections

  • [DemonArchives]7a8bde6d1942443bdbf09e610eb1b794.exe
    .exe windows:4 windows x86 arch:x86

    98f67c550a7da65513e63ffd998f6b2e


    Headers

    Imports

    Sections

  • [DemonArchives]7da028810a703bb926d39a9b4ba50703.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • [DemonArchives]7e020e96f43c40b26aa7f880ad0f8a96.exe
    .exe windows:1 windows x86 arch:x86

    c2a87fabf96470db507b2e6b43bd92eb


    Headers

    Imports

    Sections

  • [DemonArchives]81759dd56bd4387d02cb20d44422c8f0.exe
    .dll windows:6 windows x86 arch:x86

    8e64c0c5fe194df2e468a04e1c25abec


    Headers

    Imports

    Exports

    Sections

  • [DemonArchives]853a559e0dcb25ab9605685ec776224c.exe
    .exe windows:10 windows x86 arch:x86

    646167cce332c1c252cdcb1839e0cf48


    Headers

    Imports

    Sections

  • [DemonArchives]887a4917f4af1126d489a4f4d56b2eb3.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]8edcc9bf66c21c55cf482dcac1c18c44.exe
    .exe windows:86 windows x86 arch:x86

    5b36115ff362711943f368adb695e60e


    Headers

    Imports

    Sections

  • [DemonArchives]973465ab358797d8d056e4f04bda2513.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]9a6f31f789128531e4c714e44915f822.exe
    .exe windows:5 windows x86 arch:x86

    74cc9952e23a9741f32b30126b550126


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • [DemonArchives]9afac07fd6517652d6e659963db8b87e.exe
    .exe windows:4 windows x86 arch:x86

    8abecba2211e61763c4c9ffcaa13369e


    Headers

    Imports

    Sections

  • [DemonArchives]a367e7069b0df249dbcd93f02f05a573.exe
    .exe windows:5 windows x86 arch:x86

    270ef27c034d928c4437a4fdbd9809c4


    Headers

    Imports

    Sections

  • [DemonArchives]a410ac0c141ebeb019661a692020fb94.exe
    .exe windows:1 windows x86 arch:x86

    95e6f8741083e0c7d9a63d45e2472360


    Headers

    Imports

    Sections

  • [DemonArchives]a62aacc19cac89138571eec242bcd4f6.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]a7f2bf63baba5ffe2b5e76ab67d25bb6.exe
    .exe windows:4 windows x86 arch:x86

    8abecba2211e61763c4c9ffcaa13369e


    Headers

    Imports

    Sections

  • [DemonArchives]a9ea383aca2b60aece3a27c899e3f784.exe
    .exe windows:4 windows x86 arch:x86

    670b061ece19946558cf91f72defb2e2


    Headers

    Imports

    Sections

  • [DemonArchives]ad9972de71fbca864e9303a043d203a0.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]adefb3d586e8f74af30155d21ac5fc9e.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]b00c6b1b2a79fc9c57f97d16d58d00f2.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • [DemonArchives]b2d7c4f62aa3abc7e398981d5c280af4.exe
    .exe windows:1 windows x86 arch:x86

    95e6f8741083e0c7d9a63d45e2472360


    Headers

    Imports

    Sections

  • [DemonArchives]c30111080c9e6acc70dd86ff97188ac8.exe
    .dll windows:5 windows x86 arch:x86

    b6aad74aec7592c0039872b49b30b9bc


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • [DemonArchives]ddc0d08019efa4cc5f2a39de99cc0a85.exe
    .dll windows:4 windows x86 arch:x86

    5ba06ef679dceed9eed0a5dd66af8eae


    Headers

    Imports

    Exports

    Sections

  • [DemonArchives]e28fe1917c5ffe9a3062ee369087f971.exe