Suspicious
Suspect

bbfc4f7b5328a3d188703d18dfee5407

HTML
MD5: bbfc4f7b5328a3d188703d18dfee5407
Size: 17.35 MB
text/html

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bbfc4f7b5328a3d188703d18dfee5407
Sha1 e5cc4cc2fab108758443e85ece1f4a48ad7de98d
Sha256 fb8a82d843199bbfa0367265ccf883c602101886d78b4bdb71b2668552aed831
Sha384 32278548b85e257c7076f24c1b1e820751648a2ffd41f3ad5b10b7fd3ef69f00f7ef2911106bcbbf01042e9b0744619c
Sha512 f1b4fabaa8a071133b255dc4080cc4dfca95e9cc9c8097bb683fc6566aa233439cb01b5fb31445ce308d14d920a79709a27e122e83464d7b8a1251645b78f5cf
SSDeep 393216:nq5WsCI4rAyKKeFOLIYfzA4/pW1zCkq1gQ3M:q5WsCI4l9sY7b/pW51GQ
TLSH 3107AD43F66280F8C16AC175835A6232FB21BC4907357AEB5BE44B213E66FD06B3DB54
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_GROUP_CURSOR4
ID:7F00
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00EF7D5B]
[Base64-Block-Decoded]
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>enc:b64
Shape pe:exe>enc:b64
2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Nexomia.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_GROUP_CURSOR4
ID:7F00
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Base64-Block@0x00EF7D5B]
[Base64-Block-Decoded]
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙