Malicious
Malicious

b78800cbda5d7e0a2bb33980abc65f34

Share on LinkedIn
Print
ZIP Archive
MD5: b78800cbda5d7e0a2bb33980abc65f34
Size: 1.24 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b78800cbda5d7e0a2bb33980abc65f34
Sha1 a7c3a3696bebec14256a842e14777c979a6a2c21
Sha256 fa76b2af590fa1fcc46ca38ec83ef40aa02616021bb88fb35106504342b3ac20
Sha384 7fa91e3e9f84f67faeea3c608ab3efebc40ce0e4a6342069df0c47add754681a09b4ad3a276e490c003bd48975b3c85e
Sha512 4fbe1af36e9be0e785b902b8845456708aacdc83ee18e22fcf1c1f31e1f5a3dbe362994f60ed9a2aea6c9ccbcbce50c8806e3fa6ccb6146ea9833ddf570f489b
SSDeep 24:9Uxz63kooBAuNlBrDTN4yU4aM0pwWPD8qXzhWoRFRGCKJ/zyRvezx0:9S63kJC6BrN4k01Thh+zAezm
TLSH 1E21E42C8A499046C83AF332A002F3C99ACDC652F009FE323F1EA6C204995C8A30380B
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbs~T1027~T1059.005~T1105
Shape arc:zip>scr:vbs
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Dropped path (COM trace) #1 PATHmalicious
C:\Winhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙