Malicious
Malicious

ada8b9ddedd43791a25669ee83dd49fc

Share on LinkedIn
Print
Disk Image
MD5: ada8b9ddedd43791a25669ee83dd49fc
Size: 6.52 MB
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ada8b9ddedd43791a25669ee83dd49fc
Sha1 92df3acdfcc3982a19d719dd43949f1038f3f45a
Sha256 b74cab9d6eac63c8aa8bc5b022405ca71c24ad0386014c2e7d4a7d9fa82d0d71
Sha384 46d3b72ffca7a81b3ec7089d1ab4aef2e7ad6afbfb66ba8cbb30535ee785b0cb2e3dab59ead2cad49635e89a1c117c81
Sha512 cc12f7b594e955f22a0fbba336cff177668da4d25ca625f06c4c7b1ba80495d3e37e4eb13b6ba66af4a1151b02619f7b88ca63f24bcbee7245cb3f2ebef9fb72
SSDeep 24576:Ui0mAhJtAltnt8h6gs4vZ+H5yPYx6ykpH0vFuf+uspTkYoLAcMVIdyjoyQBdbfSu:Ui0xPtA/t8hps4EZI2PVyUeVBdH3
TLSH CD66C6E0D9A659C2E013D47C54A8B6E201323893FFD40DF3977E6708CF7DAA56A59A0C
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0000
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 3secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path img:disk>pe:exe~T1027~T1055>pe:rsrc>bin
Shape img:disk>pe:exe>pe:rsrc>bin
malicious 4 nodes
Path img:disk>pe:exe~T1027~T1055>pe:rsrc>img
Shape img:disk>pe:exe>pe:rsrc>img
malicious 4 nodes
Name Value
ISO
DiskImage extraction mode: DiscUtils (ISO)
LNK: Command Execution UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙