Malicious
Malicious

a9d5e4d8cac3ed22c44216b59524a24e

ZIP Archive
MD5: a9d5e4d8cac3ed22c44216b59524a24e
Size: 352.21 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a9d5e4d8cac3ed22c44216b59524a24e
Sha1 881a32c29ba02d34b250ceba63e394a82f1f9708
Sha256 6717780a2fc1b767672bae74c58be8141eee8daf80c3dc1136c3953c29b98eb5
Sha384 734926d52c8a490e706a83c317303c029ecb1694676b20ae3514432a8078377b089bc50f90ab501f17ced7bcc686908f
Sha512 b517d60516d800788bd900fc2e2b1b8dd7fe26c8dc0075dee90d9597c01b42a67a72f8cb36d88117e2a6b28e62a955b367a5307a227aac9b4bf05d74c6c0c1e3
SSDeep 6144:ZL5tgnIrDJY4EZlPQIhyzMYYUo4ryHlO6xfN3wDJY4EglPQcTyz2qYUOgryHeuj:ZdtgkYtZlo/EwryHlOMNoYtglo3WQryD
TLSH 3D741254964A24AECBD21011C76B90D47F98EB4C654BC8DB6D84A718F3901ECF2BD3EB
.Net Resources
Malicious
Optimizer.ps1
Malicious
app.ico
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe>scr:ps1~T1059.001~T1105
Shape arc:zip>pe:exe>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
.Net Resources
Malicious
Optimizer.ps1
Malicious
app.ico
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
a9d5e4d8cac3ed22c44216b59524a24e › 清控.exe › .Net Resources › Optimizer.ps1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙