Hostile 92% windows Download

ratio_ghost.exe

Packed dropper with privilege escalation

Tampered UPX PE combines Winsock with memory unpackingTampered UPX PE with opaque overlay and memory unpacking
SHA-2564793b362747bd9cdfdb8a10bcfb6955f5a57dac1b71c5e1700df1af1b76b4468

Evidence

Inno Setup binary with Delphi runtime profile 0x3c0–0x490
⋯3 more rows
0x3f000000000000000000000000000000000................
0x4000a06737472696e670000000000000000..string........
0x41000000000000000003c10400000000000........<.@.....
0x4206d1140000400000000000000c4294000m.@..........)@.
⋯7 more rows
Probes for DLL sideloading targets 0x3d90–0x3e80
⋯3 more rows
0x3dc070692e646c6c0000ffffffff0d000000pi.dll..........
0x3dd06372797074626173652e646c6c000000cryptbase.dll...
0x3de0ffffffff0a0000006f6c656163632e64........oleacc.d
0x3df06c6c0000ffffffff0b00000076657273ll..........vers
0x3e00696f6e2e646c6c00ffffffff0b000000ion.dll.........
0x3e1070726f666170692e646c6c00ffffffffprofapi.dll.....
⋯7 more rows
USERPROFILE path environment variable 0x661c–0x66dc
⋯3 more rows
0x664c54454d5000000000ffffffff0b000000TEMP............
0x665c5553455250524f46494c45005356578bUSERPROFILE.SVW.
0x666cf28bf88b07e87ec0ffff3bc60f9fc38b......~...;.....
⋯7 more rows
References the LZMA SDK LzmaDec routine 0x789c–0x795c
⋯3 more rows
0x78cc145f5e5bc3000000ffffffff16000000._^[............
0x78dc4c7a6d614465636f6465206661696c65LzmaDecode faile
0x78ec6420282564290000c6400d00c6400c00d (%d)...@...@..
⋯7 more rows
Cleartext http:// URL 0x9dd0–0x9ef0
⋯7 more rows
0x9e406f6e2c20706c65617365207669736974on, please visit
0x9e5020687474703a2f2f7777772e6a72736f http://www.jrso
0x9e606674776172652e6f72672f697368656cftware.org/ishel
0x9e70702f696e6465782e7068703f746f7069p/index.php?topi
0x9e80633d7365747570636d646c696e650000c=setupcmdline..
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.