I think you missed most important thing, scans.
Here they are:
Yahoo 10:
San the bai:
IE - Luyen skill:
Hack hiphop 9d:
Firefox - thien long:
Firefox New - Hack multi:
Revolution 8.3:
CheatEngine55:
NoDis73:
autoit-v3-setup:
DotNet2.0:
DotNet3.1:
DotNet3.5:
I'd still recommend to run it in sandbox.
NoDis73 virus definition(I think?):
Quote:
Description
This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Aliases -
Backdoor:Win32/Daserf.A - Microsoft
Sus/Behav-1010 - Sophos
Indication of Infection
These symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Methods of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
So did you have time to analyze it? Worth setting up a sandbox to download it?
I haven't yet. It's always worth using a sandbox for any zipped file containing random executables.
Checked the headers, none of them were packed with any malicious packer - all of them were mostly packed with the c# packer. None of them work AFAIK. No hidden processes or memory injections, no malicious ports being created for either UDP/TCP.
They're useless. They're outdated and none of the packet structures will be the same.