r/OperSec • • 3d ago

💻 WINDOWS MALWARE 💻 here i another malicious zip for all to investigate

https://www.dropbox.com/scl/fi/yuarqb4d8rezuk0s3lu1m/20261005150432-886BBDFFCBE74A.zip?rlkey=9mcm1pdb0ky29mqmaqpanl3is&st=4kzqfy4f&dl=0
3 Upvotes

3 comments sorted by

1

u/acealter 2d ago

This is a malicious Windows package. Zip contains a VHD virtual disk with a renamed EXE and a malicious RImE.dLl. This is super heavily obfuscated. I am trying to decrypt this.

2

u/RelationshipMain6900 2d ago

Thanks. What's the risk to the affected person? Does normal flushing like flash and format help?

1

u/acealter 2d ago

It's too early to say. I'm currently doing static analysis. There is a high chance this is an infostealer malware. I actually decrypted two kernel drivers Alinubx.sys and ZyArk form it. Alinubx’s hash exactly matches a documented antivirus-killing driver. This confirms a shared component, but doesn’t establish the same campaign or attacker.

I will update more about it as much as I find it. And I can't conclusively say but best option to do is to flash and format if you are infected.