Suspicious
Suspect

a6e0f7672f95e90c07a6eeec3b45bbee

Share on LinkedIn
Print
ZIP Archive
MD5: a6e0f7672f95e90c07a6eeec3b45bbee
Size: 14.17 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a6e0f7672f95e90c07a6eeec3b45bbee
Sha1 5d02868f43bea2940bcf2ccbb1d4b1188771c709
Sha256 08417ee172bb264fa4bb4ab089e4a4b385180f58232b4dfbe4c35688acecc839
Sha384 7bed6df41ce9176ff9bf7a1075312b75be63c2d304b2afefb8c5e51ca6fac20f96b1288b9f645e8b77cb8345205c5a2d
Sha512 f27c7df2ae6dad25cb6f0af1dc62efe48a91dd2b9691164500b028e8f6206fa96034f33c2f1afd273ae6d6d873ba0cd58fb90d91a2fedb37de046a03673b8bf4
SSDeep 393216:ExCbWglIbORr4NTjM/Cz90L6ZWfeQUiQKwDXisXcJD:iCXZRr4N8/+90mKeK02D
TLSH 29E633E11097EC5BA36B62249C1D4DC9E85D0518A4EB6A38C3CEF4D977C72D21138FEA
features.lua
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.fptable
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
.update
installed.json
Assets
minimap.ofmm
Tibia.dat
Tibia.otfi
Tibia.pic
Tibia.spr
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:dll
Shape arc:zip>pe:dll
2 nodes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙