Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 28fddd561924e2e2eab44cb95d76c3c6
Sha1 201810d06f3cb22ea6826440f57eae537a5845f1
Sha256 4f67e0b3cfcf0297cd4cbc6449abf39962d2c40981bfd8f23a832b634e075a4a
Sha384 79a83b6a7d7559cf419335a6c472877165fe30354e7fc6cf57c3923d7555046ac39277c14c8e964dca63d376cd46402f
Sha512 73d3f52c98167690064c8137809bd285f15fcad6ac272ac4a04ca7fb73e82092af4632a3827d69e4b9da7f67d5d003358bc04bf841c8af14b8e3fc5cd396c342
SSDeep 12288:WMw/q3g8ojlPL8/IQSJXux3paQO16ydOc9Wo3Frr5d6XiO/nTf23WUAr4pIgtcYQ:Nud35NRJo3pa716jmxrPWzn4AUKUcd
TLSH 44F4231642BB84B9EDCB727E18307B21B4F74C4F3F818B6D925C2D6ADE81858261D723
asist_vbs_exe_down.gif
cow_pass.gif
index.php
macro.vbs
power_com.gif
power_com_wow.gif
power_dir.gif
power_exe.gif
power_exe_del.gif
power_key.gif
power_key_j.gif
power_kill.gif
The_Progress_and_Promise_of_the_Moon-Kim_Summit.doc
The_Progress_and_Promise_of_the_Moon-Kim_Summit.docm
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
media
image6.wmf
image3.wmf
image8.wmf
image4.wmf
image9.wmf
image2.wmf
image7.wmf
image10.wmf
image1.wmf
image11.png
image11.png-preview.png
image5.wmf
theme
theme1.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
__SRP_0
__SRP_1
__SRP_2
__SRP_3
_VBA_PROJECT
Malicious
vbaData.xml
settings.xml
fontTable.xml
stylesWithEffects.xml
activeX
activeX10.bin
Root Entry
CompObj
contents
_rels
activeX1.xml.rels
activeX10.xml.rels
activeX9.xml.rels
activeX8.xml.rels
activeX7.xml.rels
activeX6.xml.rels
activeX5.xml.rels
activeX4.xml.rels
activeX3.xml.rels
activeX2.xml.rels
activeX8.xml
activeX9.bin
Root Entry
contents
activeX3.bin
Root Entry
contents
activeX2.bin
Root Entry
contents
activeX1.bin
Root Entry
contents
activeX4.bin
Root Entry
contents
activeX8.bin
Root Entry
contents
activeX7.bin
Root Entry
contents
activeX6.bin
Root Entry
contents
activeX5.bin
styles.xml
webSettings.xml
docProps
core.xml
app.xml
upload.php
asist.gif
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 17 STICH kept: 9secondary ignored: 8
bin 3img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path arc:zip>scr:vbs~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:vbs>scr:bat>scr:ps1
malicious 4 nodes
Path arc:zip>oox:docm>ole:doc~T1059.005
Shape arc:zip>oox:docm>ole:doc
technique3 nodes
Command (COM trace) #1 UNKNWOWNmalicious
powershuhuhuhuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
powershuhuhuhuhuhuhu
Command (COM trace) #3 UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
(New-Ohuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
slehuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
slehuhuhuhu
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #2 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
renamehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
asist_vbs_exe_down.gif
cow_pass.gif
index.php
macro.vbs
power_com.gif
power_com_wow.gif
power_dir.gif
power_exe.gif
power_exe_del.gif
power_key.gif
power_key_j.gif
power_kill.gif
The_Progress_and_Promise_of_the_Moon-Kim_Summit.doc
The_Progress_and_Promise_of_the_Moon-Kim_Summit.docm
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
media
image6.wmf
image3.wmf
image8.wmf
image4.wmf
image9.wmf
image2.wmf
image7.wmf
image10.wmf
image1.wmf
image11.png
image11.png-preview.png
image5.wmf
theme
theme1.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
__SRP_0
__SRP_1
__SRP_2
__SRP_3
_VBA_PROJECT
Malicious
vbaData.xml
settings.xml
fontTable.xml
stylesWithEffects.xml
activeX
activeX10.bin
Root Entry
CompObj
contents
_rels
activeX1.xml.rels
activeX10.xml.rels
activeX9.xml.rels
activeX8.xml.rels
activeX7.xml.rels
activeX6.xml.rels
activeX5.xml.rels
activeX4.xml.rels
activeX3.xml.rels
activeX2.xml.rels
activeX8.xml
activeX9.bin
Root Entry
contents
activeX3.bin
Root Entry
contents
activeX2.bin
Root Entry
contents
activeX1.bin
Root Entry
contents
activeX4.bin
Root Entry
contents
activeX8.bin
Root Entry
contents
activeX7.bin
Root Entry
contents
activeX6.bin
Root Entry
contents
activeX5.bin
styles.xml
webSettings.xml
docProps
core.xml
app.xml
upload.php
asist.gif

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
NewMacros
Blacklist VBA
VBA Macro
No malware configuration was found at this point.
Command (COM trace) #1 UNKNWOWNmalicious
powershuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif
Command (COM trace) #2 UNKNWOWNmalicious
powershuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif
Command (COM trace) #3 UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › Mzfmj0.hta
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › Mzfmj.hta
Deobfuscated PowerShell UNKNWOWNmalicious
(New-Ohuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif › asist_vbs_getfiles.gif.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
slehuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif › asist_vbs_getfiles.gif.comtrace › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
slehuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_getfiles.gif › asist_vbs_getfiles.gif.comtrace › [Command #2] › [PowerShell Command]
Command (COM trace) #1 UNKNWOWNmalicious
cmd.exhuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_redirect_vbs.gif
Command (COM trace) #2 UNKNWOWNmalicious
"C:\Ushuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_redirect_vbs.gif
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_redirect_vbs.gif
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_redirect_vbs.gif
Deobfuscated PowerShell UNKNWOWNmalicious
renamehuhuhuhuhuhuhuhuhuhuhu
28fddd561924e2e2eab44cb95d76c3c6 › asist_vbs_redirect_vbs.gif › asist_vbs_redirect_vbs.gif.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙