Suspicious
Suspect

69b4b40525cf20a70744f4d187bef90f

ZIP Archive
MD5: 69b4b40525cf20a70744f4d187bef90f
Size: 15.93 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 69b4b40525cf20a70744f4d187bef90f
Sha1 1ba70b32bc5a6c763362ff8d1b2aff0ebfd712f1
Sha256 e4c1d4e2524b4955784c61bf748346012e7546f8b1c3559f0815040687ed1069
Sha384 c9ebbe6ffd84d701586a1df2e318bc08a07620d0b37291e54d3686532fcc971bb2e1275a32d792368b28ea7508f476e1
Sha512 405f955021dcfaee76f0800f5d32f5cf522cc4df5a19bd97632a2f908385ad3f2b036c03b8bdf54c5938b444dec6d73f8d915afb78d3147f178d570d3cdb9c3f
SSDeep 196608:rkwDtLsuA6uh+jtr0Z5zZ3wwxZC8kJ/Js:rHZA6faNZReJ/Js
TLSH ACF69D56B67840D5C0B6C0B885E69647F3B138140B315BDB32AE866E6F37BE01E7B721
[Authenticode]_55e9ac65.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_74f618d1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
sessiondef59.cfg
[Authenticode]_554b0c36.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_4c1700f4.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.tls
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_8b952a95.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
mesh_base.map
[Authenticode]_e707271f.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
69b4b40525cf20a70744f4d187bef90f
0x00C6F940.svg
0x00C6F940.svg-preview.jpg
0x00C6FD20.svg
0x00C6FD20.svg-preview.jpg
0x00C70253.svg
0x00C70253.svg-preview.jpg
STICH beta

No STICH Path has been generated for this analysis yet.

5 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 4img 1
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Authenticode]_55e9ac65.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_74f618d1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
sessiondef59.cfg
[Authenticode]_554b0c36.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_4c1700f4.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.tls
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
[Authenticode]_8b952a95.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
mesh_base.map
[Authenticode]_e707271f.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
69b4b40525cf20a70744f4d187bef90f
0x00C6F940.svg
0x00C6F940.svg-preview.jpg
0x00C6FD20.svg
0x00C6FD20.svg-preview.jpg
0x00C70253.svg
0x00C70253.svg-preview.jpg
No malware configuration was found at this point.
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
69b4b40525cf20a70744f4d187bef90f › Xhe9Psl7E.exe
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙