Suspicious
Suspect

ecefb2198bdbfde5d1bb3ca5cf833d4a

ZIP Archive
MD5: ecefb2198bdbfde5d1bb3ca5cf833d4a
Size: 584.44 KB
application/zip

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ecefb2198bdbfde5d1bb3ca5cf833d4a
Sha1 e7b16dcb8bfc29339fa2271d8d176d10636a238e
Sha256 dc4cfcb31728514d762a981e4bccc82cdb3fe9eb4a299a2e69a274c1feaa8f0d
Sha384 afbcde6d295bb03cfef1fc2aae99e562808c27b8a3944ff79f6b0b2772f7f2902ce8df5239f393a60fe5d1e8c04ee002
Sha512 e560f725241ff77a1a8ab4104f2b183d5345ee7a654278554bef33fa933066522cbb2e5d01f819426b470d29fbd96e287c4de458a5f45d5417193fdf558ae223
SSDeep 12288:geElNtIBB2gX3U5FA7iOm6Jjghf4xSfUxZ2U18/dtQlSprSp16nQAH9N3ez8:geSIBBfHLm6Jj6ESfUxZ91kmY/9Hew
TLSH FEC423B7179AB4897503E3E4814C6D9489AF20D957C3436ECA1E2693F5BE247FB200DE
genlibbc.txt
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
LaunchApp.cmd
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>pe:exe
Shape arc:zip>pe:exe
2 nodes
genlibbc.txt
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
LaunchApp.cmd
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙