Malicious
c3c3fc553049fafd94dd87113842c346
ZIP Archive
MD5: c3c3fc553049fafd94dd87113842c346
Size: 24.71 MB
application/zip
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | c3c3fc553049fafd94dd87113842c346 |
| Sha1 | 8a4cde7491abeb1c3c4a22d5ebf88609f4584180 |
| Sha256 | ea63dec0ee955b1f7fab073023b18d87c6b783784e9a5d994434f1b91c5eb80e |
| Sha384 | 567a8eacfe62dd364010a0d3f18e16a695e8c64d9ee1dc73544e8bdf957e82b0b05e1e104e04abef465bcb6dc391fec7 |
| Sha512 | fbfafe72f3b1cc63454d29c1acd58335fd0c2b3e4cdab2a698f9ccb349d49602c292dbd59dd3c782895d379a500470cc44414905d596ca6a6a69d2d0314ec6dd |
| SSDeep | 393216:1z1iw2IvWlYLhVCdC7HsAW4NqIN7ihVA7VfBfLqqrOjVR71FZ2nsWlYLfVCdC7dS:51iMWiLGwrNfivALzqqrOr71FXWiL4Z |
| TLSH | E947330619E64FD1D95D893590EB2703321DEF0B5053A34E87B8D22B3EB36F89F18699 |
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
16 / 16
Path
arc:zip>pe:exe>pe:rsrc>pe:exe>pe:rsrc>bin
Shape
arc:zip>pe:exe>pe:rsrc>pe:exe>pe:rsrc>bin
malicious
6 nodes
Path
arc:zip>pe:exe>pe:rsrc>pe:dll>pe:rsrc>bin
Shape
arc:zip>pe:exe>pe:rsrc>pe:dll>pe:rsrc>bin
malicious
6 nodes
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.4 |
| Author | Flexense Ltd. |
| CreationDate | D:20260204125540+02'00' |
| Creator | PDFCreator Version 1.2.3 |
| Keywords | DiskPulse, Disk Change Monitor |
| ModifiedDate | D:20260204125540+02'00' |
| Subject | DiskPulse Disk Change Monitor |
| Title | DiskPulse Disk Change Monitor |
| Producer | GPL Ghostscript 9.04 |
| /Producer | GPL Ghostscript 9.04 |
| /CreationDate | D:20260204125540+02'00' |
| /ModDate | D:20260204125540+02'00' |
| /Title | DiskPulse Disk Change Monitor |
| /Creator | PDFCreator Version 1.2.3 |
| /Author | Flexense Ltd. |
| /Keywords | DiskPulse, Disk Change Monitor |
| /Subject | DiskPulse Disk Change Monitor |
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
c3c3fc553049fafd94dd87113842c346 › info › unins000.dat
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.