Malicious
Malicious

cbcb58ffe45c202c11bcf2070496aed6

Share on LinkedIn
Print
ZIP Archive
MD5: cbcb58ffe45c202c11bcf2070496aed6
Size: 3.53 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cbcb58ffe45c202c11bcf2070496aed6
Sha1 b47d1618177b6bc219b8734cd02f9cf7be7aff43
Sha256 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd
Sha384 7452ae03fadbcdc4293a2bc20448a02537d71701595f2dc9e8095eed2018996b8eaab401bfc24d1182dcdb3f85bc2102
Sha512 97115e8faf2a0554d899f05931d29a99a500ff849d0f3fbf5ab5d36387b8938288e25804b8ef0b031a18ae04fd23e52959737f7b94a369e2fa55922861ef506d
SSDeep 98304:SyrPvG3UNpYqQLpXhHHeanDebmPL+okjWa1lu/:SyrPO3UDsdXp+z8+FWyE
TLSH 9DF53329C35BA51C444ED111B88E299A937D8D177E1E17314E43336CFE378AE3E8E2A5
Overlay_5a23ee85.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 2secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:vbe>scr:vbs~T1027~T1059~T1059.005~T1105>scr:bat>scr:ps1~T1059.001
Shape arc:zip>scr:vbe>scr:vbs>scr:bat>scr:ps1
malicious 5 nodes
Path arc:zip>scr:vbe>scr:vbs~T1027~T1059~T1059.005~T1105>scr:bat>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:vbe>scr:vbs>scr:bat>scr:ps1
malicious 5 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
cmd /chuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(Writehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙