Malicious
Malicious

592b04c38ff195bae20623ccada92224

Share on LinkedIn
Print
ZIP Archive
MD5: 592b04c38ff195bae20623ccada92224
Size: 1.22 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 592b04c38ff195bae20623ccada92224
Sha1 bc278d4f960053847d201f60592051565142a863
Sha256 7b1c1b85784b92f8d4e7a7f3e6edd8a3b90cd708c75c09f17e62241433c2f3f9
Sha384 1aa8ef4be6a39eb88c87ea9616ad17ea5c6284b917cfa16ee0df87e15865582106ec3244cd1e8c7457b300294595dabb
Sha512 29f6728400b15749da8402923e9c3d6c89e1279428dedf79e98ce6868121a2d37ec6c3e7d1534dea2efa1c1072d680f8891cbb17b35c6b55427b218c63cc0805
SSDeep 24576:Fvtj3jH7Ifkg/2IEqejW7bwO2Geng+rc97ZCTdkAeQvFKrueC51Rug:Fvtj7eH2hy7bvStm0T2pCbMg
TLSH 30452314C728906EC0B61AB2A0F1193DE4715EF9590FEB4DEFE7294A909B244377533A
Documents
Malicious
1.Operations Overview and Dashboard.pdf
#Stream obj 5 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 14 0
#Stream obj 15 0
#Stream obj 17 0
#Stream obj 33 0
Structure
2. Office Network and Local Statistics.pdf
#Stream obj 5 0
#Stream obj 14 0
#Stream obj 15 0
#Stream obj 17 0
#Stream obj 33 0
#Stream obj 32 0
3. Office statistics.pdf
#Stream obj 5 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 17 0
#Stream obj 33 0
#Stream obj 35 0
4. Analytics.pdf
#Stream obj 5 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 14 0
#Stream obj 15 0
#Stream obj 17 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 26 0
#Stream obj 27 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 32 0
#Stream obj 35 0
#Stream obj 34 0
5. Key findings.pdf
Text (Preview)
#Stream obj 5 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 14 0
#Stream obj 15 0
#Stream obj 17 0
6. Supplement Panel Architecture and Operating Logic.pdf
#Stream obj 5 0
#Stream obj 14 0
#Stream obj 15 0
#Stream obj 17 0
#Stream obj 33 0
#Stream obj 32 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 38 0
#Stream obj 41 0
#Stream obj 40 0
#Stream obj 43 0
#Stream obj 45 0
#Stream obj 44 0
#Stream obj 47 0
#Stream obj 46 0
#Stream obj 49 0
#Stream obj 51 0
#Stream obj 50 0
#Stream obj 53 0
#Stream obj 52 0
#Stream obj 55 0
#Stream obj 54 0
#Stream obj 57 0
#Stream obj 56 0
#Stream obj 59 0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001
Shape arc:zip>lnk>lnk:cmd>scr:ps1
malicious 4 nodes
Name Value
Version
1.4
Producer
pypdf
Version
1.4
Producer
pypdf
/Producer
pypdf
/Producer
pypdf
Version
1.4
Producer
pypdf
/Producer
pypdf
Version
1.4
Producer
pypdf
/Producer
pypdf
Version
1.4
Producer
pypdf
/Producer
pypdf
Version
1.4
Producer
pypdf
/Producer
pypdf
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
& ((Gehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙