- Mar 24, 2016
- 421
Requesting @struppigel to take a look.
This sample is spread on websites that host cracked games. However, the malicious file is not the downloaded cracked game itself. Instead, when you click the download link and you don't have an ad blocker, you will be redirected to another website. The file tricks the user into thinking it is the game by having the same name. The sample seems to be tricky to run in a sandbox/VM(it installs 7zip?). It may also install malicious extension(s)? I've seen a lot of people get infected by similar adware/malware and that's why I want to raise awareness.
Main installer:
—————————————————————————
One of the Dropped files?:
This sample is spread on websites that host cracked games. However, the malicious file is not the downloaded cracked game itself. Instead, when you click the download link and you don't have an ad blocker, you will be redirected to another website. The file tricks the user into thinking it is the game by having the same name. The sample seems to be tricky to run in a sandbox/VM(it installs 7zip?). It may also install malicious extension(s)? I've seen a lot of people get infected by similar adware/malware and that's why I want to raise awareness.
Main installer:
dc287b1f38dfd32bdd479048022dba205674c378882867499ae216cbd251f6f5 | Triage
Check this report malware sample dc287b1f38dfd32bdd479048022dba205674c378882867499ae216cbd251f6f5, with a score of 5 out of 10.
tria.ge
—————————————————————————
One of the Dropped files?:
f52e4263afa3bcb5124ebd6da3a246453e0a009149cf01c17d72b51a6f5bf094 | Triage
Check this report malware sample f52e4263afa3bcb5124ebd6da3a246453e0a009149cf01c17d72b51a6f5bf094, with a score of 1 out of 10.
tria.ge
Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'RigidvApp.exe'
Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.
www.hybrid-analysis.com
Last edited: