Suspicious
Suspect

0dac2a970cec91ea985ea1f79d50c06d

ZIP Archive
MD5: 0dac2a970cec91ea985ea1f79d50c06d
Size: 4.19 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0dac2a970cec91ea985ea1f79d50c06d
Sha1 8c85328ba0501ffe9284e957843361328222bd31
Sha256 254fff0fabd0b47ae67cc9e45539e2c7de33bee70e5e2e951d4db215f74af676
Sha384 ef7203f2032db0e9c169b54652b1f8b9cc06df0a6d429c312802097046c4e8a629257fd1d54fa468fa9711c70b7dd705
Sha512 ba2de69114ebba3583f911322491a10d5388338553afbe8131a24e362a44ae1e61801351d3a52498d75f5778a6a82f7467d1b7f275247bd93bf79c5b194982fa
SSDeep 49152:tLlepsLJEjLLvtL393OGiLkacvukXNzw1L43EZ/Yu5p1F/Iiq9KpUmTfFqSgdDPC:tAstxQvhmZ/Yu524p/8lu5dZD6C
TLSH 2516BE16A3AD01E4D16BE278C6969732D6B17C064331E6CB03E9D6292F37BE05B7B311
[Authenticode]_4a63b61f.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_GROUP_CURSOR4
ID:07D0
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
[Authenticode]_c434e7f7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_c7070076.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_add9f1e3.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_2441bb51.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
bin 4

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:dll
Shape arc:zip>pe:dll
2 nodes
[Authenticode]_4a63b61f.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_GROUP_CURSOR4
ID:07D0
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
[Authenticode]_c434e7f7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_c7070076.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_add9f1e3.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_2441bb51.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙