4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8eSetup Factory 7.0 Encrypted-Overlay Dropper
SHA-256: 4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8e
Original filename: 点击此处安装简体中文.exe (Chinese "Click here to install Simplified Chinese")^[triage.json]
Static-only analysis — CAPE skipped (no Windows guest available). Dynamic inferences are noted as such.
Build / RE
Toolchain & Identity
- MSVC 6.0 linker, compiled Wed 2004-10-13 15:10:17 UTC.^[pefile.txt:32-35]^[exiftool.json:18]
- PE32 x86 GUI, 4 sections (
.text,.rdata,.data,.rsrc).^[file.txt]^[rabin2-info.txt:1-5] - ImageBase 0x400000, EntryPoint 0x401d9d.^[pefile.txt:50-51]
- Unsigned;
signed: falsein rabin2.^[rabin2-info.txt:27] - VersionInfo claims "Setup Factory 7.0 Runtime" /
suf70_launch.exe/ Indigo Rose Corporation.^[exiftool.json:36-46]^[strings.txt:1591]
Packing / Obfuscation
- Not packed in the malware sense. The binary is the legitimate Setup Factory 7.0 runtime launcher repurposed as a dropper.
- Overlay begins at raw offset
0x11000and spans 3,744,346 bytes (~3.7 MB).^[rabin2-info.txt:23]^[pefile overlay calculation] - The overlay contains an encrypted/obfuscated data region followed by a password-protected ZIP archive with local file headers at offsets
0x2c19d4,0x2e5ebd, and0x358a67.^[strings.txt:5008,5270,6048] - ZIP contents (per header inspection):
libcef.dll(339,456 bytes),mediabox.exe(941,200 bytes),PeLoader(1,357 bytes).^[7z listing of extracted archive region] - ZIP encryption method: traditional ZIP crypto (flag
0x0009= encrypted + Deflate). Password is not recovered — brute-force of printable candidates near the headers and of strings fragments (cexGZ_t,%xERRj3cqZQ) failed to decrypt.^[terminal brute-force output] - Two ASCII fragments —
cexGZ_t(0x0a7f3, 0x7865f) and%xERRj3cqZQ(0x0a804, 0x78665) — appear twice in the binary, once in.rsrcand once inside the encrypted overlay. Their relationship to the ZIP password is unknown; they may be coincidental ciphertext artifacts or key material for the pre-ZIP decryption layer.
Anti-Analysis
- None observed. No debugger checks, no VM detection, no sandbox gates. The threat actor relies entirely on the installer-builder legitimacy and social-engineering filename for evasion.
Notable Functions (radare2)
entry0(0x401d9d): Standard C runtime initialisation —HeapCreate,TlsAlloc/TlsSetValue,GetCommandLineA,GetStartupInfoA, then dispatches tomain.^[r2:entry0]fcn.00402102: Heap allocator wrapper aroundHeapCreate(0x1000 bytes initial, 0x3f8 chunk size).^[r2:fcn.00402102]fcn.004037c7: C runtime handle table setup — maps stdin/stdout/stderr and initialises the lowio table.^[r2:fcn.004037c7]- No custom crypto, no API hashing, no PEB-walking. This is a vanilla 2004-era C runtime stub.
Resources
.rsrccontains 10RT_DIALOGentries, 1RT_GROUP_ICON, 1RT_VERSION, and an embedded application manifest (SUF60setup.exe,Setup Factory 6.0 Run-time).^[pefile.txt:resource directory]
Deploy / ATT&CK
| Technique | Implementation | Confidence |
|---|---|---|
| T1204.002 | User Execution — Malicious File. Chinese-language social-engineering filename masquerades as a language-pack installer. | High |
| T1027.002 | Obfuscated Files — Password-protected ZIP overlay conceals three payload files (libcef.dll, mediabox.exe, PeLoader). |
High (static) |
| T1055 | Process Injection — PeLoader filename strongly suggests reflective PE loading of the inner payload; unconfirmed without extraction or dynamic execution. |
Low (inferred) |
| T1071 | Application Layer Protocol — Bundled libcef.dll (Chromium Embedded Framework) enables browser-based network comms or webview masquerade if used by mediabox.exe. |
Low (inferred) |
Persistence / Privilege Escalation
- None observed in the outer stub. If the Setup Factory runtime requests elevation during installation (standard behaviour for legitimate installers), that constitutes implicit UAC elevation — this is likely the source of the OpenCTI
bypassuacmislabel.
Attribution
- Chinese-language filename lure. No other linguistic or infrastructure clues recoverable statically.
- OpenCTI co-labels
silverfoxandvalleyratare unsupported by this sample. There are no shared build artefacts, crypto constants, API dispatch patterns, or section structures with the confirmed SilverFox cluster (see silverfox). Treat as false-positive co-tagging.
Summary
A Setup Factory 7.0 runtime launcher (2004 vintage) repurposed as an encrypted dropper. The overlay conceals a password-protected ZIP archive containing three files — a Chromium DLL, a mediabox.exe payload, and a PeLoader stub. The outer binary has no anti-analysis and no UAC bypass logic; the bypassuac label is a misattribution. Without recovering the ZIP password or detonating the sample dynamically, the exact behaviour of the inner payload remains opaque.