Suspicious 86% pe-machine-learning-dataset Download

46789

Signed installer bundles 7z SFX, evasive stubs

InstallVibes-signed elevated 7-Zip SFX carries opaque payloadInstallVibes-signed opaque 7-Zip SFX bundler
SHA-2560dab5ae236398890815b103f3517c7e1d2431a71c7439a3a958afafdccc6d613

Evidence

Resource section dominates PE size 0x0–0x120
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000f0000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯13 more rows
Exact runas ShellExecute verb token 0x154ac–0x1565c
0x154ac2e657865000000004544393331333144.exe....ED93131D
0x154bc2d383936432d343341302d394132362d-896C-43A0-9A26-
0x154cc3034394230454436363638362e657865049B0ED66686.exe
0x154dc000000005c0000004346343738314236....\...CF4781B6
0x154ec2d313341452d343238372d383731352d-13AE-4287-8715-
0x154fc41433735423330373142363100000000AC75B3071B61....
0x1550c2d79202d700000002e646c6c00000000-y -p....dll....
0x1551c496e7374616c6c657248656c70657200InstallerHelper.
0x1552c663635363433000042696e0077620000f65643..Bin.wb..
0x1553c737472696e6720746f6f206c6f6e6700string too long.
0x1554c696e76616c696420737472696e672070invalid string p
0x1555c6f736974696f6e0072756e6173000000osition.runas...
0x1556c5c2a2e2a000000002e0000002e2e0000\*.*............
⋯15 more rows
ShellExecuteEx API call 0x16284–0x16514
0x162844c6f61644c6962726172794100004502LoadLibraryA..E.
0x1629447657450726f63416464726573730000GetProcAddress..
0x162a46201467265654c696272617279008402b.FreeLibrary...
0x162b447657454656d70506174684100007c00GetTempPathA..|.
0x162c44372656174654469726563746f727941CreateDirectoryA
⋯6 more rows
0x163345200436c6f736548616e646c65003201R.CloseHandle.2.
0x1634446696e64466972737446696c65410000FindFirstFileA..
0x16354000452656d6f76654469726563746f72..RemoveDirector
0x16364794100002e0146696e64436c6f736500yA....FindClose.
0x16374430146696e644e65787446696c654100C.FindNextFileA.
0x16384d30044656c65746546696c6541004b01..DeleteFileA.K.
⋯4 more rows
0x163d44b45524e454c33322e646c6c00002001KERNEL32.dll.. .
0x163e45368656c6c4578656375746545784100ShellExecuteExA.
0x163f45348454c4c33322e646c6c00fb015575SHELL32.dll...Uu
0x1640469644372656174650000030255756964idCreate....Uuid
⋯6 more rows
0x1647465457863657074696f6e000018045274eException....Rt
0x164846c556e77696e64000003497344656275lUnwind...IsDebu
0x164946767657250726573656e740004034973ggerPresent...Is
0x164a450726f636573736f7246656174757265ProcessorFeature
⋯7 more rows
PE resource entropy is at least 6.6 0x17fa0–0x180d0
⋯5 more rows
0x17ff000000000000000000000000000000000................
0x1800000000000000000000000000001000300................
0x18010c0010080300000800300000048000080....0.......H...
0x180200e000000780000801800000090000080....x...........
0x1803000000000000000000000000000000100................
⋯10 more rows
7-Zip archive signature in PE resource section 0x3d628–0x3d7b8
⋯7 more rows
0x3d6986e0020006500720072006f0072000000n. .e.r.r.o.r...
0x3d6a8377abcaf271c0000acfe4100000000007z..'.....A.....
0x3d6b82e3f415643496e417263686976654578.?AVCInArchiveEx
0x3d6c863657074696f6e404e377a404e417263ception@N7z@NArc
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.