Malicious
Malicious

5d1d3b4bd5113a2ec1e089b212969532

ZIP Archive
MD5: 5d1d3b4bd5113a2ec1e089b212969532
Size: 5.19 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5d1d3b4bd5113a2ec1e089b212969532
Sha1 2628f6aec1d8afd2951ec731657679894d526541
Sha256 451f8c64c6b08f17306389d3212c5314e05fb493e8b153982d74e34cad8b0f8d
Sha384 24e435c5014715d07c6d3278a1a3abf7852a3c2b56033703dc43a81a677c8237df927466cd27afcd62ea722ad159beed
Sha512 5bc57a650153ad99c3f8ad718c5c4c46da36da19e18f60f1b9240c4547bb890d57e60f0f6504ce02772b3ae43bdaa9b1f5d79d35f671f624eb249d863157e282
SSDeep 98304:5cNttWfxtqZ4Pp7BuL0FuZYn/mk0E4RzUa9yBCKGSZb917cCFb/M:5SgHq+PpV6Au2K7qCKGSZb9NccY
TLSH F03633598C29D1B4C155343B2D7EED50520153EAACBE8BBCA393039AB56EF703377682
zapret-discord-youtube-1.10.1
Malicious
bin
ACTIVE_DISCORD_UDP.bin
ACTIVE_GAME_UDP.bin
Overlay_eba38089.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.edata
.reloc
.idata
.rsrc
4
19
38
Resources
RT_VERSION
ID:0001
ID:1033
quic_initial_5ka_ru.bin
quic_initial_rutube_ru.bin
quic_initial_tencent_com.bin
quic_initial_www_google_com.bin
stun2.bin
tls_clienthello_4pda_to.bin
tls_clienthello_5ka_ru.bin
tls_clienthello_max_ru.bin
tls_clienthello_www_google_com.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.reloc
[Authenticode]_f668fc99.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
INIT
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.idata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:0
general (ALT).bat
general (ALT10).bat
general (ALT11).bat
general (ALT12).bat
general (ALT2).bat
general (ALT3).bat
general (ALT4).bat
general (ALT5).bat
general (ALT6).bat
general (ALT7).bat
general (ALT8).bat
general (ALT9).bat
general (EXP).bat
general (FAKE TLS AUTO ALT).bat
general (FAKE TLS AUTO ALT2).bat
general (FAKE TLS AUTO ALT3).bat
general (FAKE TLS AUTO).bat
general (SIMPLE FAKE ALT).bat
general (SIMPLE FAKE ALT2).bat
general (SIMPLE FAKE).bat
general.bat
lists
ipset-all.txt
ipset-all.txt.backup
ipset-exclude.txt
list-exclude-user.txt
list-exclude.txt
list-general-user.txt
list-general.txt
list-google.txt
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
utils
check_updates.enabled
discordzapret.msi.enc
targets.txt
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 3secondary ignored: 5
bin 5

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path arc:zip>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1
malicious 2 nodes
Path arc:zip>scr:ps1~T1059.001
Shape arc:zip>scr:ps1
technique2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
write-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
zapret-discord-youtube-1.10.1
Malicious
bin
ACTIVE_DISCORD_UDP.bin
ACTIVE_GAME_UDP.bin
Overlay_eba38089.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.edata
.reloc
.idata
.rsrc
4
19
38
Resources
RT_VERSION
ID:0001
ID:1033
quic_initial_5ka_ru.bin
quic_initial_rutube_ru.bin
quic_initial_tencent_com.bin
quic_initial_www_google_com.bin
stun2.bin
tls_clienthello_4pda_to.bin
tls_clienthello_5ka_ru.bin
tls_clienthello_max_ru.bin
tls_clienthello_www_google_com.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.reloc
[Authenticode]_f668fc99.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
INIT
.rsrc
.reloc
Resources
RT_MESSAGETABLE
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.buildid
.pdata
.xdata
.bss
.idata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:0
general (ALT).bat
general (ALT10).bat
general (ALT11).bat
general (ALT12).bat
general (ALT2).bat
general (ALT3).bat
general (ALT4).bat
general (ALT5).bat
general (ALT6).bat
general (ALT7).bat
general (ALT8).bat
general (ALT9).bat
general (EXP).bat
general (FAKE TLS AUTO ALT).bat
general (FAKE TLS AUTO ALT2).bat
general (FAKE TLS AUTO ALT3).bat
general (FAKE TLS AUTO).bat
general (SIMPLE FAKE ALT).bat
general (SIMPLE FAKE ALT2).bat
general (SIMPLE FAKE).bat
general.bat
lists
ipset-all.txt
ipset-all.txt.backup
ipset-exclude.txt
list-exclude-user.txt
list-exclude.txt
list-general-user.txt
list-general.txt
list-google.txt
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
utils
check_updates.enabled
discordzapret.msi.enc
targets.txt
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
write-huhuhuhuhuhuhuhuhuhuhu
5d1d3b4bd5113a2ec1e089b212969532 › zapret-discord-youtube-1.10.1 › service.bat › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
5d1d3b4bd5113a2ec1e089b212969532 › zapret-discord-youtube-1.10.1 › service.bat › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"Writehuhuhuhuhuhuhuhuhuhuhu
5d1d3b4bd5113a2ec1e089b212969532 › zapret-discord-youtube-1.10.1 › service.bat › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [Deobfuscated PS] › [PowerShell Command] › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙