Malicious
bfabd10cc55cdda854a763ff8bba0f72
ZIP Archive
MD5: bfabd10cc55cdda854a763ff8bba0f72
Size: 7.6 MB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | bfabd10cc55cdda854a763ff8bba0f72 |
| Sha1 | aa3589322313f36ff2f401bcb6171d5b4adb8c27 |
| Sha256 | fcb25bcd035d93e2791be4990119bc3980ffc16209faec1cb557208168dc7f72 |
| Sha384 | f0a3d3a91572438de0164377ae036b7902d56f6a5cf9f6f9fe2adba74db5c1a7b7783adccf0abc6bc48c416a17f5124d |
| Sha512 | 1df860df5f2eb6be86e9673162917c28c0d93b3af4ffe8a6a39327dc01d71e3b84a2c5977854316675b4b73df3a37f89e1d1b7f395bcfbf4568c9323012af455 |
| SSDeep | 196608:rVZRR8bkqiT0nYzeM5PEsqz8UPS/j1paY7nDPkS8lQut5u:RZROiJyMLi8Ua/hpl7DPkK0u |
| TLSH | 0A7633FEEF347E4DA73BD6F7F1701589888267097C6754A144E842A2ACAB94017C38DE |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 6
STICH kept: 1secondary ignored: 5
bin
3img
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape
arc:zip>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | MSI huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | EXE huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | MSI huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| Payload URI | EXE huhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
bfabd10cc55cdda854a763ff8bba0f72 › CapCut_Installer.95-40-8-09.exe
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bfabd10cc55cdda854a763ff8bba0f72 › App › beta15658 › Installer-95-40-8-09.dll › [PowerShell Command]
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
bfabd10cc55cdda854a763ff8bba0f72 › App › beta15658 › Installer-95-40-8-09.dll › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.