SUSPICIOUS — 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275.zip
SUSPICIOUS — 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (43/100), attributed to the STRATO family. 5 of 54 detection engines flagged it.
Identification
- SHA-256:
24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275 - SHA-1:
1f61c0a24cffaf0a65fb5c046a8f01cf5fa16ac3 - MD5:
b9845f3cb8bc89e3f3dcf660a1caf78d - ssdeep:
393216:ItdF8uTB/DO4vqc509j0g27KBVQwZAmGQEvhrko:GF8qK4ykk+7KI2HQvhN - TLSH:
T1626E33F98E1471914C18F640B92B812206E8546779B1D211645272F9E3F3F8AEBBC27E - Submitted as: 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275.zip
- File type: zip · Size: 13991507 bytes
- Verdict: suspicious (43/100) · Family: STRATO
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Trojan:Win32/Suschil!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008412
- Kaspersky (KVRT): Trojan.Win64.Agent.smgxbi
Why this verdict
The suspicious score of 43/100 is the fusion of 3 weighted signals:
- YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: concrt140.dll, glib-2.0-0.dll, iconv-2.dll, intl-8.dll, libgcc_s_seh-1.dll - static signal, weight 0.25, confidence 0.50
Archive contents (15 executables)
This zip carries 15 extracted members, each analyzed as its own sample (listing truncated):
- ProtobufLite.dll -
eaa699671e0a071456be13635ac0d8947e0ec3166148b615df30ecb25d6eaade - SDL3.dll -
132e7f953951944f7628861227ecaea8c37a5a484f004c2072b7f3a1c343fa73 - SMInfrastructure.dll -
c092b9e93712da5e78914a508f8349ec4af77fd92a0f50e6e6ebd5c4997cd6ba - SysInspector.exe -
548e2a1b4113c16d421df342e4beed5aaa393db29810936788bf2b7f720537a9 - SysInspectorLang.dll -
c8b409713b5301e576ccbee3287f37b5eda86a6cdd74d20d1d641c0a6de3476b - concrt140.dll -
8032b43bdd2f18ce7eb131e7cd542967081bea9490df08681bf805ce4f4d3aab - glib-2.0-0.dll -
cbdc399946efc0c477a93268f11c71cd770b0f49fe627647ba77e06acd0e0998 - iconv-2.dll -
1fafdbd0c0ec01102c2175659779dff747e92d178d9469c1ca998c5901892cc5 - intl-8.dll -
d75a6a69ca975fcc038dda954795a1127c6b2c854ed4631da17a121a76ec7710 - libgcc_s_seh-1.dll -
729214efc075b7d4a6fd6309d13f8c49574f3d30c60cf0fb6fc002d90a265866 - libiomp5md.dll -
d41a71c38f627a95748596820ab380135dcccc4ceecd6fe7d4e247d015bf55a4 - libircmd.dll -
80b5fc727ef6034d1c0be043b06c5654fa74660f632cadba28361982be1e6d70 - libmmd.dll -
3c6d84f0cd71062f65b42cf06da7bf08d9fbeb97abf132852f4dec47f0e1a585 - libstdc++-6.dll -
ffdee6daaa4afc1975a4ec0371161078a864c6c1f27186b93a673801cad99eba - libwinpthread-1.dll -
04737a97282e4068a06ebce60ef80d2f42b8dd33ed7f2cf09ee85d4167e6f9a1
Dynamic analysis
This zip is a container, so it was not detonated itself. Its extracted members were re-submitted and analyzed as their own samples, and the runtime behaviour lives on those reports.
Embedded domains
- 3k.me
- 1.be
- 0.br
- k.kr
- 1.su
- 1k.fi
- 2.ly
- 6.mx
File paths
- O:\:9
- Q:\Sh
- S:\Qo
- o:\8
- a:\Xl
- A:\&j
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report