Malicious
Malicious

65102ecb6a3a0429ca78531ae1876450

ZIP Archive
MD5: 65102ecb6a3a0429ca78531ae1876450
Size: 389.59 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 65102ecb6a3a0429ca78531ae1876450
Sha1 2b818996ab33e3e8be07d777e034713dc78b83b2
Sha256 f656b47e2337fea418a36933f173da98901d9ba4c0e05e3457ee3c59f94ad458
Sha384 b71f81f909fe607111b7eba79eac2f0de8ee0955867cc3aa1f21d65d90a96deaf99cb697312cc01f3bafa3ac1b7a8d2b
Sha512 1ac215265a73b9fbb1db39767c851fb37cbb5d33dd99234f9f33a5468cab8bb57760b666f7cc8b9e16a55b445d929af0f1716bb45b0f858a1b57447bc7a9cfd8
SSDeep 6144:tdD8Xb68R3e/txOMr5nEBW3LQ04TuKyRrRhtR7thHR9HTMkM8CI6rTVKFvoQ2Ie:/DOb+/tx7iBM2oJ7T7thx9HgkM0WTs5e
TLSH CC8423DCBE2F6A3E8B6DAA8CF41F425164B57191044875480CB2FCFDC9A901B963E5F2
Overlay_f3ee3492.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.sdata
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ns26OTDdao7rsfxrjS.lyelFfExKM4kMikcZI
eoQ1g5Ht8LBftB96b1.FaawXIIt8QjuQgkwe5
HATp6iBBFOyEtyQExO.GOdG2LC9IHOxHLtGPb
HsdP7nFckBQldRdXuJ.AxiBZdG6KVqlUXhLsl
almohtraf.bat
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 2secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe>pe:rsrc>bin
Shape arc:zip>pe:exe>pe:rsrc>bin
malicious 4 nodes
Path arc:zip>pe:exe>bin
Shape arc:zip>pe:exe>bin
malicious 3 nodes
Overlay_f3ee3492.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.sdata
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ns26OTDdao7rsfxrjS.lyelFfExKM4kMikcZI
eoQ1g5Ht8LBftB96b1.FaawXIIt8QjuQgkwe5
HATp6iBBFOyEtyQExO.GOdG2LC9IHOxHLtGPb
HsdP7nFckBQldRdXuJ.AxiBZdG6KVqlUXhLsl
almohtraf.bat
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙