Suspicious
Suspect

a09a20a6fc558fe39af29647f4395a9d

ZIP Archive
MD5: a09a20a6fc558fe39af29647f4395a9d
Size: 13 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a09a20a6fc558fe39af29647f4395a9d
Sha1 9e8a6c0cfad9a0d778e1abd1fc4986a59071991e
Sha256 33a7b824bc687c330c33c1870a9243d2f527c43d63a1fa95b3ad02c12dfe5f81
Sha384 c8297a5a8334ce5010226eedd2039356c7e8391b9680cf77d4538fe607cef8083e171663fbdc3084ef7dd9fba545800b
Sha512 83775dd39a0e633bc48c8e3e4b8ac2277453f90de3169e61e6993cab17eb658720ca8984e507b260f4e365f604567f58bb6a51b41aa286f7b1225ba68a94ef4c
SSDeep 393216:YoZC1rnGsdLZHaMH44F8GIuM1ck+38C+uyz0:PAlDPNO+Mt0
TLSH A3D63362675B374F097293F53A378D7F9264FC526C38B9784E8F9EB58422281646CC38
Account_Transcript
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.eh_fram
.pdata
.xdata
.bss
.edata
.idata
.tls
.reloc
.Net Resources
EnableLoopback.frmMain.resources
$this.Icon
[NBF]root.IconData
EnableLoopback.Properties.Resources.resources
EnableLoopbackRefresh
[NBF]root.Data
[NBF]root.Data-preview.png
[Authenticode]_d34a56ad.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:dll
Shape arc:zip>pe:dll
2 nodes
Account_Transcript
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.eh_fram
.pdata
.xdata
.bss
.edata
.idata
.tls
.reloc
.Net Resources
EnableLoopback.frmMain.resources
$this.Icon
[NBF]root.IconData
EnableLoopback.Properties.Resources.resources
EnableLoopbackRefresh
[NBF]root.Data
[NBF]root.Data-preview.png
[Authenticode]_d34a56ad.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙