Setup Factory Encrypted-Overlay Dropper
Technique: repurposing the legitimate Setup Factory installer-builder runtime as a malware dropper by embedding an encrypted payload in the installer data overlay.
Mechanism
- Outer Stub: The binary is the Setup Factory runtime launcher (
suf70_launch.exe), compiled with MSVC 6.0 and linked against the standard C runtime. It has no anti-analysis, no custom crypto, and no API hashing.^[rabin2-info.txt]^[pefile.txt] - Overlay: After the PE
.rsrcsection, the binary contains a large data region (3.7 MB in the observed sample). The first part of this region is encrypted/obfuscated; near its end, a password-protected ZIP archive begins. - Inner Archive: The ZIP is encrypted with traditional ZIP crypto and contains the actual malicious payloads. In the observed sample these were
libcef.dll,mediabox.exe, andPeLoader.^[strings.txt:5008,5270,6048] - Execution: At runtime, the Setup Factory launcher decrypts the overlay (mechanism unknown — likely a symmetric cipher with a key derived from the installer project settings) and extracts the archive to a temporary directory, then launches the setup engine (
irsetup.exe) to continue installation.^[strings.txt:7100]
Detection
- Look for PE files with VersionInfo mentioning "Setup Factory", "Indigo Rose", or
suf70_launch. - Large file size relative to section sizes (e.g. 3.8 MB file with 46 KB of mapped sections) indicates a heavy overlay.
- Strings references to
irsetup.exe,__IRAFN:%s,__IRAOFF:%u, orCould not find setup sizeare strong fingerprints.^[strings.txt:143-1591] - The overlay entropy is typically high (>7.5) due to encryption/compression.
Reproduction Notes
- Extract the raw overlay with pefile or any PE parser: overlay offset = max(PointerToRawData + SizeOfRawData) across all sections.
- If the overlay is a plain ZIP,
7zorunzipmay list contents. If encrypted, password recovery requires either brute-force or knowledge of the project key. - No CAPE detonation needed to confirm the installer nature; the static strings are definitive.
Related
- setup-factory-dropper — Entity page for this family.
- social-engineering-filename-lure — Frequently paired with this technique.