Malicious
Malicious

456d0c9cd9b225ed8faa807f7dbd8558

MS Office Document
MD5: 456d0c9cd9b225ed8faa807f7dbd8558
Size: 65.54 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 456d0c9cd9b225ed8faa807f7dbd8558
Sha1 19d47a97bd5b2fd32bd80fd87124518bec241d2e
Sha256 d222455bf7f6fb149222a13d3b728178726896b8664743a5a7aca6da336263d1
Sha384 f60ab9785dc6b02f9a76bfe4fdd999f962b707b419dbfc5346f577a64705a16b937c85b11a8617fa5c6bbb415fd4d614
Sha512 bf4948a8da40913e59480e788bfad071c485ccca3a7c15b06c33e9abcffef418f6561d41a555103e262f50bfb66d3477595a8243ca2c86055512ffa6428ebbdd
SSDeep 768:HuZTbl+MomHmBwCuXbgRpRCG+fYGAScLYid4OMZ:kTD6wVgRyG+fYVMUTG
TLSH A453C7237A445333C5421372961FA3E49F798C5C4BF74212356AB29C1EB1EB462FB8E6
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 2secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.005~T1105>scr:vbs~T1059.005
Shape ole:doc>scr:ps1>scr:vbs
malicious 3 nodes
Path ole:doc>scr:ps1~T1027~T1059.005~T1105>scr:bat
Shape ole:doc>scr:ps1>scr:bat
technique3 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
456d0c9cd9b225ed8faa807f7dbd8558 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
456d0c9cd9b225ed8faa807f7dbd8558 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙