Malicious
Malicious

5f9f9335f66a3c4e43662b0998f25e3b

Rar Archive
MD5: 5f9f9335f66a3c4e43662b0998f25e3b
Size: 952.14 KB
application/vnd.rar
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5f9f9335f66a3c4e43662b0998f25e3b
Sha1 832e66d7bf4ffb69e4d26253198578c15114f641
Sha256 ab282de6689911c7a81ecccb272f1f9f4e1e3705f8d81950f9e791edf79647a2
Sha384 05a61e1694a3dcb5e436bdae6b2befb204120b797588c04adee7e572f9933e79b8c75c5f3a1acb46ebd282d11a322ddb
Sha512 a890f59eede5f1434101d2539fde529671701f7ca0f14352e9832f1abe31037f6e9e019ade38817812db98d7e41250be49aa7e73a242edb50dc9d1cfc19259d6
SSDeep 12288:TEvX3XVsLtHqU1lKOp8OPgh9iCNTPnuXykiAEzHJMKfmej2XkcxAeLMOE5YHWYUr:TKlWK+b8lFxk7KT6xAgXCY2ou2H7DS
TLSH EE15233A58EE632445E78704462C9F3B9F6F0927253BB673ACE70174E41C21799F836A
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
dgw.ngC.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
ogm.Tg1.resources
hg0.agZ.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
vzJB
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path arc:rar>pe:exe>pe:rsrc>img
Shape arc:rar>pe:exe>pe:rsrc>img
malicious 4 nodes
Path arc:rar>pe:exe>pe:rsrc>bin
Shape arc:rar>pe:exe>pe:rsrc>bin
malicious 4 nodes
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
dgw.ngC.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
ogm.Tg1.resources
hg0.agZ.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
vzJB
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙