Suspicious
Suspect

6e73a261e556a4064e885cb01ff40682

ZIP Archive
MD5: 6e73a261e556a4064e885cb01ff40682
Size: 2.07 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6e73a261e556a4064e885cb01ff40682
Sha1 10da5dcf895cb449478c340451792a172da7d048
Sha256 4abcd5e7df9188710db8acad440136393d8480ea33a58f6c67627eb5dbc66ec9
Sha384 4d0d6598d23de4ada6a2fd65ac8cf40c160c5eb90b1aa7f21c858fc110553fb1ecb0e8e929dafc75cdbcfa8abc2b5064
Sha512 fdd2cf31ed13f768fd3a8940c6519e4b9586ea532bc49faea61e174b0ceb3c6d027c33e06220a5e8c8fe1386642afff368b8984f4f3eddc6d36977a116dedc5f
SSDeep 49152:exGPm2YX/6ddmxkKFU6o9xPDywJN1lMJgpK5ekj4agMPfmACu:fPmZvcmLFQ91Dy6bOJgEskjHjn99
TLSH 91A533A4FC60FBB9713E80D4A8F6A83C6A438E533CBA14B6C75393651D6573FA463184
6e73a261e556a4064e885cb01ff40682
[Base64-Block@0x001E90A6]
[Base64-Block-Decoded]
[Base64-Block@0x001EE7B4]
[Base64-Block-Decoded]
app.asar
0x0011F478.svg
0x0011F478.svg-preview.jpg
0x0011FB92.svg
0x0011FB92.svg-preview.jpg
0x00120341.svg
0x00120341.svg-preview.jpg
0x00465580.svg
0x00465580.svg-preview.jpg
0x00466221.svg
0x00466409.svg
0x004761AB.svg
0x004761AB.svg-preview.jpg
0x004C58EE.svg
0x004C58EE.svg-preview.jpg
0x004C6284.svg
0x004C6284.svg-preview.jpg
0x004C65AC.svg
0x004C65AC.svg-preview.jpg
0x004D86D7.svg
0x004D86D7.svg-preview.jpg
0x004D88AE.svg
0x004D88AE.svg-preview.jpg
Info.plist
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 1img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbs>enc:b64
Shape arc:zip>scr:vbs>enc:b64
3 nodes
6e73a261e556a4064e885cb01ff40682
[Base64-Block@0x001E90A6]
[Base64-Block-Decoded]
[Base64-Block@0x001EE7B4]
[Base64-Block-Decoded]
app.asar
0x0011F478.svg
0x0011F478.svg-preview.jpg
0x0011FB92.svg
0x0011FB92.svg-preview.jpg
0x00120341.svg
0x00120341.svg-preview.jpg
0x00465580.svg
0x00465580.svg-preview.jpg
0x00466221.svg
0x00466409.svg
0x004761AB.svg
0x004761AB.svg-preview.jpg
0x004C58EE.svg
0x004C58EE.svg-preview.jpg
0x004C6284.svg
0x004C6284.svg-preview.jpg
0x004C65AC.svg
0x004C65AC.svg-preview.jpg
0x004D86D7.svg
0x004D86D7.svg-preview.jpg
0x004D88AE.svg
0x004D88AE.svg-preview.jpg
Info.plist
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙