A sample of Ocean Lotus, also known as APT 32, a threat group associated with Vietnam. Malware authors use atypical formats in order to make static detection more difficult, because custom formats are not recognized as executable by AV scanners. The malware manages to bypass UAC at default level. The key malware functionality is, however, not provided by any dropped PE files, but they are just used as loaders. They are hidden in the core files: BLOB and CAB files.”]