Malicious
Malicious

4100b976150cb4015e1856d875637861

Share on LinkedIn
Print
ZIP Archive
MD5: 4100b976150cb4015e1856d875637861
Size: 6.75 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4100b976150cb4015e1856d875637861
Sha1 ddee4ee51bf954bafd69256fa47f0a8e2ea2551c
Sha256 b4f661e53edd813aa5919ffe4607f1aa4c031f6a027fec47b434675b2a6fc636
Sha384 217317e1971f0bb523b579ed9249df36709e39a13d2b3db5c7649f0c988907fcafb0ac6f439e21f4dbc0d109fcbf7449
Sha512 8a457247fd33f0978a79e09f8fd42176991f0e9ccd62fe8ed84e224fec8da2c8f5aa8c7395cad5f4aead0f9590a4eb8ba0a90bdc0193baf920f027ccb35e2457
SSDeep 196608:zsLD6bmXv8UNTQxAHyksE4YHt2N0G0fJJPF:QCbmEhANsEpNOP2JJPF
TLSH 0B66337FDFEAB6C2D937DB75842A1589AFF4C7AB32D47092242C449279CD1A2D8E0301
dz-doc
Malicious
dz-doc
Malicious
blocker.php
config.php
Device-error.php
index.php
invite.php
Mac
download
docusign.dmg
index.php
index.php
settings.php
[Base64-Block@0x000000F3]
[Base64-Block-Decoded]
[Base64-Block@0x00020185]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
utility.php
0x00020B0A.svg
[Base64-Block@0x00021853]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
[Base64-Block@0x0003B3E0]
[Base64-Block-Decoded]
[Base64-Block-Decoded]-preview.png
visit.php
Windows
Malicious
assets
doc.png-preview.png
Just a moment..._files
v8c78df7c7c0f484497ecbca7046644da1771523124516
Justamoment....php
Justamoment....php
0x00001409.svg
0x00001409.svg-preview.jpg
0x00001604.svg
0x00001604.svg-preview.jpg
0x00001F2E.svg
0x00001F2E.svg-preview.jpg
0x000028B9.svg
0x000028B9.svg-preview.jpg
settings.php
visit.php
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 3secondary ignored: 3
img 2bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path arc:zip>scr:vbs~T1027~T1059~T1059.005~T1105
Shape arc:zip>scr:vbs
malicious 2 nodes
Path arc:zip>html>enc:b64
Shape arc:zip>html>enc:b64
3 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙