Malicious
Malicious

bfabd10cc55cdda854a763ff8bba0f72

Share on LinkedIn
Print
ZIP Archive
MD5: bfabd10cc55cdda854a763ff8bba0f72
Size: 7.6 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bfabd10cc55cdda854a763ff8bba0f72
Sha1 aa3589322313f36ff2f401bcb6171d5b4adb8c27
Sha256 fcb25bcd035d93e2791be4990119bc3980ffc16209faec1cb557208168dc7f72
Sha384 f0a3d3a91572438de0164377ae036b7902d56f6a5cf9f6f9fe2adba74db5c1a7b7783adccf0abc6bc48c416a17f5124d
Sha512 1df860df5f2eb6be86e9673162917c28c0d93b3af4ffe8a6a39327dc01d71e3b84a2c5977854316675b4b73df3a37f89e1d1b7f395bcfbf4568c9323012af455
SSDeep 196608:rVZRR8bkqiT0nYzeM5PEsqz8UPS/j1paY7nDPkS8lQut5u:RZROiJyMLi8Ua/hpl7DPkK0u
TLSH 0A7633FEEF347E4DA73BD6F7F1701589888267097C6754A144E842A2ACAB94017C38DE
App
Malicious
AppInfo
appicon.ico
appicon_128.png
appicon_128.png-preview.png
appicon_16.png
appicon_16.png-preview.png
appicon_32.png
appicon_32.png-preview.png
appicon_75.png
appicon_75.png-preview.png
appicon111.ico
appinfo.ini
Launcher
CapCut_Installer.95-40-8-09.ini
license.txt
splash.jpg
splash.jpg-preview.png
splashz.jpg
splashz.jpg.exif
splashz.jpg-preview.png
beta15658
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Authenticode]_9be44668.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
RT_STRING
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
RT_MESSAGETABLE
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Authenticode]_d9454d73.p7b
INSTALLATION FAIL README.txt
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 6 STICH kept: 1secondary ignored: 5
bin 3img 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI MSI huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Payload URI EXE huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙