Malicious
Malicious

07f237960b144e9a29e3097e57e9f6d0

ZIP Archive
MD5: 07f237960b144e9a29e3097e57e9f6d0
Size: 246.12 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 07f237960b144e9a29e3097e57e9f6d0
Sha1 3859076b0e0279ea4af70d5277d6edd74ce3800b
Sha256 d3b067ae9c10194df86de21ee5ba3d77b94e8529808c2fe025ddd7f2bbf0487c
Sha384 91699d38cc4feba2fdd48a0974c06b449ffd7af4346d268a69579d8f721d244da26c798ca173105da9f39c5b12b32098
Sha512 3ada1634cfd79dcb5dbeeb54855853ea67beb248633f424a028f292aec2859786e88f8dbdadf1d4fde50534a70423e7fd660b0d66734a8c4d653ce3c0122d084
SSDeep 6144:s1YxGGhYtP9C3Bj+UwxPWC9E9YJATn93k7AsM:s1A1ePYj3YnSn93kEsM
TLSH FE34237BF74B0567AC0942F1DB589C3F803AC1A9F442D247AD2ED4E787816EDA6F8406
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
NAudio.Gui.Fader.resources
NAudio.Gui.PanSlider.resources
$this.DefaultModifiers
$this.GridSize
$this.Language
NAudio.Gui.VolumeSlider.resources
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 3

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
NAudio.Gui.Fader.resources
NAudio.Gui.PanSlider.resources
$this.DefaultModifiers
$this.GridSize
$this.Language
NAudio.Gui.VolumeSlider.resources
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhu
07f237960b144e9a29e3097e57e9f6d0 › Leeme.txt › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙