Malicious
456d0c9cd9b225ed8faa807f7dbd8558
MS Office Document
MD5: 456d0c9cd9b225ed8faa807f7dbd8558
Size: 65.54 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 456d0c9cd9b225ed8faa807f7dbd8558 |
| Sha1 | 19d47a97bd5b2fd32bd80fd87124518bec241d2e |
| Sha256 | d222455bf7f6fb149222a13d3b728178726896b8664743a5a7aca6da336263d1 |
| Sha384 | f60ab9785dc6b02f9a76bfe4fdd999f962b707b419dbfc5346f577a64705a16b937c85b11a8617fa5c6bbb415fd4d614 |
| Sha512 | bf4948a8da40913e59480e788bfad071c485ccca3a7c15b06c33e9abcffef418f6561d41a555103e262f50bfb66d3477595a8243ca2c86055512ffa6428ebbdd |
| SSDeep | 768:HuZTbl+MomHmBwCuXbgRpRCG+fYGAScLYid4OMZ:kTD6wVgRyG+fYVMUTG |
| TLSH | A453C7237A445333C5421372961FA3E49F798C5C4BF74212356AB29C1EB1EB462FB8E6 |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 3
STICH kept: 2secondary ignored: 1
bin
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>scr:ps1~T1027~T1059.005~T1105>scr:vbs~T1059.005
Shape
ole:doc>scr:ps1>scr:vbs
malicious
3 nodes
Path
ole:doc>scr:ps1~T1027~T1059.005~T1105>scr:bat
Shape
ole:doc>scr:ps1>scr:bat
technique3 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
456d0c9cd9b225ed8faa807f7dbd8558 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
456d0c9cd9b225ed8faa807f7dbd8558 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.