Malicious
Malicious

07f237960b144e9a29e3097e57e9f6d0

Share on LinkedIn
Print
ZIP Archive
MD5: 07f237960b144e9a29e3097e57e9f6d0
Size: 246.12 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 07f237960b144e9a29e3097e57e9f6d0
Sha1 3859076b0e0279ea4af70d5277d6edd74ce3800b
Sha256 d3b067ae9c10194df86de21ee5ba3d77b94e8529808c2fe025ddd7f2bbf0487c
Sha384 91699d38cc4feba2fdd48a0974c06b449ffd7af4346d268a69579d8f721d244da26c798ca173105da9f39c5b12b32098
Sha512 3ada1634cfd79dcb5dbeeb54855853ea67beb248633f424a028f292aec2859786e88f8dbdadf1d4fde50534a70423e7fd660b0d66734a8c4d653ce3c0122d084
SSDeep 6144:s1YxGGhYtP9C3Bj+UwxPWC9E9YJATn93k7AsM:s1A1ePYj3YnSn93kEsM
TLSH FE34237BF74B0567AC0942F1DB589C3F803AC1A9F442D247AD2ED4E787816EDA6F8406
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
NAudio.Gui.Fader.resources
NAudio.Gui.PanSlider.resources
$this.DefaultModifiers
$this.GridSize
$this.Language
NAudio.Gui.VolumeSlider.resources
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 3

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙