Malware Analysis Tricky adware or malicious ?

likeastar20

Level 9
Thread author
Verified
Forum Veteran
Mar 24, 2016
418
1,729
768
România
Requesting @struppigel to take a look.

This sample is spread on websites that host cracked games. However, the malicious file is not the downloaded cracked game itself. Instead, when you click the download link and you don't have an ad blocker, you will be redirected to another website. The file tricks the user into thinking it is the game by having the same name. The sample seems to be tricky to run in a sandbox/VM(it installs 7zip?). It may also install malicious extension(s)? I've seen a lot of people get infected by similar adware/malware and that's why I want to raise awareness.

Main installer:




—————————————————————————

One of the Dropped files?:



 
Last edited:
I myself am not a malware analysist, but on sandbox reports, there doesn’t seem to be malicious activity (no bad malicious indicators with Hybrid Analysis, and for Triage it’s just gets geo location. However, avast has a Evo Gen detection which I believe means the file has a signature (correct if wrong)

VT has no malicious indicators and K Opentip is clean.
 
It is malicious, I recognize the packer. Ridiculous version info too ("RigidFEELINGTool.exe"), plus the name on hybrid is "FREE-STEAM.txt_164164.exe" --> standard double extension trick, here followed by the _16416 to not trigger AV detection that look for txt.exe
Not sure if I have time this week to dig deeper, though.
 
I myself am not a malware analysist, but on sandbox reports, there doesn’t seem to be malicious activity (no bad malicious indicators with Hybrid Analysis, and for Triage it’s just gets geo location. However, avast has a Evo Gen detection which I believe means the file has a signature (correct if wrong)

VT has no malicious indicators and K Opentip is clean.
BitDefender has added detection for the dropped file. I love how quickly they add things after you submit them.

EDIT1: Kaspersky added a detection for the installer "UDS:Trojan.Win32.Delf.a" and dropped file "UDS:Trojan.Win32.Agentb.a".
 
Last edited:
BitDefender has added detection for the dropped file. I love how quickly they add things after you submit them.

EDIT1: Kaspersky added a detection for the installer "UDS:Trojan.Win32.Delf.a" and dropped file "UDS:Trojan.Win32.Agentb.a".
Well, guess I was wrong. Why didn’t VT show anything malicious on the MITRE ATT&CK matrix?

Also - I believe these are automatic cloud detections as apposed to Signatures - K Opentip detects it as VHO:Trojan.Win32.Delf.a and Trojan.Win32.Agentb.a implying it was detected either via Opentip or other means. It could be signatures, but I dont see it being a UDS_____ detection instead of a signature detection.
 
Last edited:
Well, guess I was wrong. Why didn’t VT show anything malicious on the MITRE ATT&CK matrix?

Also - I believe these are automatic cloud detections as apposed to Signatures - K Opentip detects it as VHO:Trojan.Win32.Delf.a and Trojan.Win32.Agentb.a implying it was detected either via Opentip or other means. It could be signatures, but I dont see it being a UDS_____ detection instead of a signature detection.
Maybe, I submitted the files through their support + from OpenTip as well.
 
  • Like
Reactions: Kongo
When did you see the detections? Opentip or through support?
They were never detected by OpenTip, but once the OpenTip analysis is complete, you can submit them to Kaspersky from there, so I did. But I also went to their support page and sent the sample to their email.
 
  • Like
Reactions: Kongo
They were never detected by OpenTip, but once the OpenTip analysis is complete, you can submit them to Kaspersky from there, so I did. But I also went to their support page and sent the sample to their email.
Did you get any responses saying a detection was added?
 
  • Like
Reactions: Kongo
I downloaded a sample and it was detected by Cloud Detection instead of databases - maybe a user was infected and K blocked it.
 
  • Like
Reactions: Kongo
@struppigel Found another one, i think it's related, same packer.

SFX Archive:

===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== ===== =====

Original rar:



EDIT1: Evasive 🤔

 
Last edited:
  • Like
Reactions: Kongo