Malware
Machete
aka El Machete
According to ESET, Machete’s dropper is a RAR SFX executable.
Machete, also known as El Machete, is a Windows malware family.
Background
ESET notes that Machete arrives via a RAR SFX dropper that unpacks three py2exe components: GoogleCrash.exe, Chrome.exe and GoogleUpdate.exe. It also drops one configuration file, jer.dll, which holds base64‑encoded text representing AES‑encrypted strings. GoogleCrash.exe acts as the core component, orchestrating when the other two run and establishing persistence through Windows Task Scheduler tasks. For victim geolocation, Chrome.exe gathers details about nearby Wi-Fi networks and submits them to the Mozilla Location Service API, which returns coordinates derived from inputs like Bluetooth beacons, cell towers or Wi-Fi access points. The resulting latitude and longitude are then assembled into a Google Maps URL. GoogleUpdate.exe handles contact with the remote C&C server, reading the connection settings (domain name, username and password) from jer.dll. Machete primarily relies on FTP for communication, with HTTP added as a fallback channel in 2019.
Source: Malpedia (Fraunhofer FKIE).