Malicious
ZIP Archive
MD5: 28fddd561924e2e2eab44cb95d76c3c6
Size: 726.57 KB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 28fddd561924e2e2eab44cb95d76c3c6 |
| Sha1 | 201810d06f3cb22ea6826440f57eae537a5845f1 |
| Sha256 | 4f67e0b3cfcf0297cd4cbc6449abf39962d2c40981bfd8f23a832b634e075a4a |
| Sha384 | 79a83b6a7d7559cf419335a6c472877165fe30354e7fc6cf57c3923d7555046ac39277c14c8e964dca63d376cd46402f |
| Sha512 | 73d3f52c98167690064c8137809bd285f15fcad6ac272ac4a04ca7fb73e82092af4632a3827d69e4b9da7f67d5d003358bc04bf841c8af14b8e3fc5cd396c342 |
| SSDeep | 12288:WMw/q3g8ojlPL8/IQSJXux3paQO16ydOc9Wo3Frr5d6XiO/nTf23WUAr4pIgtcYQ:Nud35NRJo3pa716jmxrPWzn4AUKUcd |
| TLSH | 44F4231642BB84B9EDCB727E18307B21B4F74C4F3F818B6D925C2D6ADE81858261D723 |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 17
STICH kept: 9secondary ignored: 8
bin
3img
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
9 / 9
Path
arc:zip>scr:vbs~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape
arc:zip>scr:vbs>scr:bat>scr:ps1
malicious
4 nodes
Path
arc:zip>oox:docm>ole:doc~T1059.005
Shape
arc:zip>oox:docm>ole:doc
technique3 nodes
Command (COM trace) #1
UNKNWOWNmalicious
powershuhuhuhuhuhuhu
Command (COM trace) #2
UNKNWOWNmalicious
powershuhuhuhuhuhuhu
Command (COM trace) #3
UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
(New-Ohuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
slehuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
slehuhuhuhu
Command (COM trace) #1
UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2
UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1
PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
renamehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential