Malicious
Malicious

284783bce2882423de458e2989a502a9

ZIP Archive
MD5: 284783bce2882423de458e2989a502a9
Size: 10.07 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 284783bce2882423de458e2989a502a9
Sha1 9d798150f8268f367c9aa7a2bf5a2dde07b0376e
Sha256 7e99e051cc6a925d1a860d36c332bf8095907823b6bddf5d21ae755e3568defc
Sha384 1f56b8c57523f79ba0db61f1dce16cdbe867e75f6717111ef94d6efb1c5ab45cc1a6179c7564623f4157a727f8898bb7
Sha512 288d7bf740789e87fd1f75a838b9b910b0e9f4bfcc87c4e6893c57ee5dd925447df9f163c4e82ff8464a1e08fffeacf90b1e1869cc075812b79d670bc0c7b79d
SSDeep 196608:TvbaGMlwmaLOPlYYmvkZj8FjZTHIjvkM21pa1WAy4Fk3ou7:Tv2xymaq9/mvkZjQdTHyp21QWAy73ou7
TLSH DCA63326F48B282DBBF7B3101A181D4F97F5615AB65A23768CC6097C8CEB77191A02C7
sellpoint-puente-win7
Malicious
INICIAR.bat
LEEME.txt
[Authenticode]_fb27af5a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:1033-preview.png
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00EDE669]
[Base64-Block-Decoded]
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 2secondary ignored: 4
bin 3img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>scr:ps1
malicious 2 nodes
Path arc:zip>pe:exe>enc:b64
Shape arc:zip>pe:exe>enc:b64
3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 http:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 URImalicious
http:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
sellpoint-puente-win7
Malicious
INICIAR.bat
LEEME.txt
[Authenticode]_fb27af5a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:1033-preview.png
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00EDE669]
[Base64-Block-Decoded]
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #4 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #5 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #6 http:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
URL in PowerShell #4 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
URL in PowerShell #5 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
URL in PowerShell #6 URImalicious
http:huhuhuhuhuhuhu
284783bce2882423de458e2989a502a9 › sellpoint-puente-win7 › bundle.js
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙