Malicious
Malicious

57f01391064cac371eed2be1281070af

Share on LinkedIn
Print
ZIP Archive
MD5: 57f01391064cac371eed2be1281070af
Size: 1.51 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 57f01391064cac371eed2be1281070af
Sha1 79e45f117df27c1cffa22b1fc5276d89f9aafe8a
Sha256 8d538435f6048919c10abd27cf3f1315afeb5c815b6346d0ec9dcfda5afc5b51
Sha384 59c2f30dcdd4a29f3182bafa16cba0bf9c025fd1da52cab65a25a45a3872884e8e290b44697e36268ddd0699c526f452
Sha512 82f39cb9509c78af480871a9def0ba4766f124147a40b656fd660e7948af65201c1ff17a42dd9274c461103d193e5ee7200acc6d827bbd420c3453d7da36684e
SSDeep 24576:/cjh9+TiOV9A7D0AtWL+kcatqOCRcKNEiN5GrZP/x7GQrYmILWj:/cL+uUAtWfxtqOQ154P57RrYFLWj
TLSH 40653343CC2E429EC71A3837084C692E510377823CEA57B4A75253DCF9AFBA53774A96
zapret-discord-youtube-1.0.0c
Malicious
bin
Overlay_eba38089.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.edata
.reloc
.idata
.rsrc
4
19
38
Resources
RT_VERSION
ID:0001
ID:1033
quic_initial_dbankcloud_ru.bin
quic_initial_www_google_com.bin
tls_clienthello_4pda_to.bin
tls_clienthello_max_ru.bin
tls_clienthello_www_google_com.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.reloc
[Authenticode]_f668fc99.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
INIT
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.idata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:0
general (ALT).bat
general (ALT10).bat
general (ALT11).bat
general (ALT12).bat
general (ALT2).bat
general (ALT3).bat
general (ALT4).bat
general (ALT5).bat
general (ALT6).bat
general (ALT7).bat
general (ALT8).bat
general (ALT9).bat
general (FAKE TLS AUTO ALT).bat
general (FAKE TLS AUTO ALT2).bat
general (FAKE TLS AUTO ALT3).bat
general (FAKE TLS AUTO).bat
general (SIMPLE FAKE ALT).bat
general (SIMPLE FAKE ALT2).bat
general (SIMPLE FAKE).bat
general.bat
gitignore
LICENSE.txt
lists
ipset-all.txt
ipset-all.txt.backup
ipset-exclude-user.txt
ipset-exclude.txt
list-exclude-user.txt
list-exclude.txt
list-general-user.txt
list-general.txt
list-google.txt
README.md
SECURITY.md
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
SHA256SUMS.txt
utils
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
gamein_config.bat
game_filter.enabled
targets.txt
test results
test_results_2026-06-26_23-21-30.txt
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 3secondary ignored: 5
bin 5

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path arc:zip>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1
malicious 2 nodes
Path arc:zip>scr:ps1~T1059.001
Shape arc:zip>scr:ps1
technique2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙