Suspicious
Suspect

aed52f1f140e93f7373e2504549eed60

Share on LinkedIn
Print
ZIP Archive
MD5: aed52f1f140e93f7373e2504549eed60
Size: 4.8 MB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 aed52f1f140e93f7373e2504549eed60
Sha1 5a15fd159f6984fcbe4d93f12847cfb6d53bcabc
Sha256 ed7240c8b599b5b5bbdafb145c1aa22547c7843b7c979fd82f1cee45a4ff580b
Sha384 e20248229bf35140435f8e09f5ba31bad3e59d2f31530c41b6091fd05adc6b78a24956f3418b43e67163a262296a9313
Sha512 a167446c0702c5ab8b4e56754ad67e97e2eef3a22add7fd1369b78745f911469584668e393632e92d9f77976f59fd984af4b141acee9f75a5d10152fbd30524c
SSDeep 98304:hO3vV//UWp0PsSFhZUaVe5hGsNXrg18sb7bEU8oDEzYK0aBfy4px:hO3v7JSDXbsN72lb7bEtRzLjx
TLSH B926338AC4E6A1AEEC372834C7E9395153770072ADC3296F13E196A3D1D1994F2B35CD
[Authenticode]_9e5aa671.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_df8e3a67.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.tls
.reloc
[Authenticode]_07bf70b0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.tls
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.managed
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
[Authenticode]_516297c7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.edata
.idata
.CRT
.tls
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_c434e7f7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_86e04f56.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.data
.rdata
.pdata
.xdata
.bss
.idata
.CRT
.tls
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
[Authenticode]_c7070076.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_add9f1e3.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
[Authenticode]_2441bb51.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
bin 4

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:dll
Shape arc:zip>pe:dll
2 nodes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙