Suspicious
Suspect

b062484550d2ebf1ce8302417c0ff716

Share on LinkedIn
Print
ZIP Archive
MD5: b062484550d2ebf1ce8302417c0ff716
Size: 493.86 KB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b062484550d2ebf1ce8302417c0ff716
Sha1 d9e5cb0b4086ece2f1666a146682d9d16789f03e
Sha256 d34d1b55201f0318e0fd5a7cd4feacff0edb825e57d45ea9507f1d06303ff97c
Sha384 0800740008d30c1bdf60e576f961e8b1503b45671a14b2e13cf5dd698d03c01f4b5a839cbfe33c773bdba4fe56d2fa36
Sha512 a6c2be474bc120c72180ef3d8c46439dc7efa6870767354ac9a0dc0fba403191fac6b946dd8a1d651e51480ea7eaa96ef523ec45d5941f8124522db709b296f3
SSDeep 12288:UnL36rrXKULp4SYxNQA4Q8PtE5aCyq93DvUrA4eQVU:vrjRF4S+tp8PW5arY3DH
TLSH ACB423EEC34B61188407DD736F65E82A5A9B1EE07FC98DC12A35774278C436BADE21C4
llImges_AngelaWhite-Albomghrvy
llImges_AngelaWhite-Albomghrvy.js
[Authenticode]_b3419fd0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0061
ID:1033
RT_STRING
ID:0001
ID:1033
ID:0005
ID:1033
ID:00BC
ID:1033
ID:00CF
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:0
[Authenticode]_1299717a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0007
ID:1033
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[NSIS Installer] @ #0001C408
Overlay_6682b84b.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Overlay_5cf0bcaf.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
.reloc
Resources
RT_DIALOG
ID:0065
ID:1033
Overlay_3ec4b0a0.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Overlay_78c3ba13.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Overlay_533092a5.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_DIALOG
ID:0065
ID:2058
RT_MANIFEST
ID:0002
ID:1033
installing.html
installing_page.css
installing.js
Overlay_f2e2cd67.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.00cfg
.rsrc
.reloc
Resources
LIMITEDACCESSFEATURE
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
Overlay_f88ef5f9.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Overlay_7a1ec51c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:2057
bgstub.jpg
bgstub.jpg-preview.png
stub_common.css
stub_common.js
profile_cleanup.html
profile_cleanup_page.css
profile_cleanup.js
[SETUP_DECOMPILED.NSI]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 10 STICH kept: 1secondary ignored: 9
bin 7img 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe>arc:7zsfx>pe:exe>html
Shape arc:zip>pe:exe>arc:7zsfx>pe:exe>html
5 nodes
An error has occurred. This application may no longer respond until reloaded. Reload 🗙