typeanalysisfamilysetup-factory-dropperconfidencemediumcreated2026-08-08updated2026-08-08
SHA-256: 4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8e

Setup Factory 7.0 Encrypted-Overlay Dropper

SHA-256: 4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8e Original filename: 点击此处安装简体中文.exe (Chinese "Click here to install Simplified Chinese")^[triage.json] Static-only analysis — CAPE skipped (no Windows guest available). Dynamic inferences are noted as such.

Build / RE

Toolchain & Identity

  • MSVC 6.0 linker, compiled Wed 2004-10-13 15:10:17 UTC.^[pefile.txt:32-35]^[exiftool.json:18]
  • PE32 x86 GUI, 4 sections (.text, .rdata, .data, .rsrc).^[file.txt]^[rabin2-info.txt:1-5]
  • ImageBase 0x400000, EntryPoint 0x401d9d.^[pefile.txt:50-51]
  • Unsigned; signed: false in rabin2.^[rabin2-info.txt:27]
  • VersionInfo claims "Setup Factory 7.0 Runtime" / suf70_launch.exe / Indigo Rose Corporation.^[exiftool.json:36-46]^[strings.txt:1591]

Packing / Obfuscation

  • Not packed in the malware sense. The binary is the legitimate Setup Factory 7.0 runtime launcher repurposed as a dropper.
  • Overlay begins at raw offset 0x11000 and spans 3,744,346 bytes (~3.7 MB).^[rabin2-info.txt:23]^[pefile overlay calculation]
  • The overlay contains an encrypted/obfuscated data region followed by a password-protected ZIP archive with local file headers at offsets 0x2c19d4, 0x2e5ebd, and 0x358a67.^[strings.txt:5008,5270,6048]
  • ZIP contents (per header inspection): libcef.dll (339,456 bytes), mediabox.exe (941,200 bytes), PeLoader (1,357 bytes).^[7z listing of extracted archive region]
  • ZIP encryption method: traditional ZIP crypto (flag 0x0009 = encrypted + Deflate). Password is not recovered — brute-force of printable candidates near the headers and of strings fragments (cexGZ_t, %xERRj3cqZQ) failed to decrypt.^[terminal brute-force output]
  • Two ASCII fragments — cexGZ_t (0x0a7f3, 0x7865f) and %xERRj3cqZQ (0x0a804, 0x78665) — appear twice in the binary, once in .rsrc and once inside the encrypted overlay. Their relationship to the ZIP password is unknown; they may be coincidental ciphertext artifacts or key material for the pre-ZIP decryption layer.

Anti-Analysis

  • None observed. No debugger checks, no VM detection, no sandbox gates. The threat actor relies entirely on the installer-builder legitimacy and social-engineering filename for evasion.

Notable Functions (radare2)

  • entry0 (0x401d9d): Standard C runtime initialisation — HeapCreate, TlsAlloc/TlsSetValue, GetCommandLineA, GetStartupInfoA, then dispatches to main.^[r2:entry0]
  • fcn.00402102: Heap allocator wrapper around HeapCreate (0x1000 bytes initial, 0x3f8 chunk size).^[r2:fcn.00402102]
  • fcn.004037c7: C runtime handle table setup — maps stdin/stdout/stderr and initialises the lowio table.^[r2:fcn.004037c7]
  • No custom crypto, no API hashing, no PEB-walking. This is a vanilla 2004-era C runtime stub.

Resources

  • .rsrc contains 10 RT_DIALOG entries, 1 RT_GROUP_ICON, 1 RT_VERSION, and an embedded application manifest (SUF60setup.exe, Setup Factory 6.0 Run-time).^[pefile.txt:resource directory]

Deploy / ATT&CK

Technique Implementation Confidence
T1204.002 User Execution — Malicious File. Chinese-language social-engineering filename masquerades as a language-pack installer. High
T1027.002 Obfuscated Files — Password-protected ZIP overlay conceals three payload files (libcef.dll, mediabox.exe, PeLoader). High (static)
T1055 Process Injection — PeLoader filename strongly suggests reflective PE loading of the inner payload; unconfirmed without extraction or dynamic execution. Low (inferred)
T1071 Application Layer Protocol — Bundled libcef.dll (Chromium Embedded Framework) enables browser-based network comms or webview masquerade if used by mediabox.exe. Low (inferred)

Persistence / Privilege Escalation

  • None observed in the outer stub. If the Setup Factory runtime requests elevation during installation (standard behaviour for legitimate installers), that constitutes implicit UAC elevation — this is likely the source of the OpenCTI bypassuac mislabel.

Attribution

  • Chinese-language filename lure. No other linguistic or infrastructure clues recoverable statically.
  • OpenCTI co-labels silverfox and valleyrat are unsupported by this sample. There are no shared build artefacts, crypto constants, API dispatch patterns, or section structures with the confirmed SilverFox cluster (see silverfox). Treat as false-positive co-tagging.

Summary

A Setup Factory 7.0 runtime launcher (2004 vintage) repurposed as an encrypted dropper. The overlay conceals a password-protected ZIP archive containing three files — a Chromium DLL, a mediabox.exe payload, and a PeLoader stub. The outer binary has no anti-analysis and no UAC bypass logic; the bypassuac label is a misattribution. Without recovering the ZIP password or detonating the sample dynamically, the exact behaviour of the inner payload remains opaque.