Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5f20e45252e2843506ff0cde903fa363
Sha1 e988ca8afd243496d05d78d3843912bf60e7e6fd
Sha256 1ed821fcc96cd12b94a7d4ab486d718416164e0ef8b607821b02b34c38f02674
Sha384 1963b4106aa38c07c4e71fd0bf1a1cb49ee91c9393cbdba3d4ef5592909d80303a252f6415db2f3f9a44cf7e85ebb084
Sha512 c764c5aa16b0f72b124388a9e13a84c47ca3d9c0788722ce4e384edb10dc2c312fb20b539ab611a1b2fbd50bef25aa43109a93cbbe8b56d8a56c432b418f3905
SSDeep 196608:hYIN/WRt9fPdN5v/CiN+pNGrDYOxlu2qy8fmaKFOuXuLBZ4/u02LnXeOOmhhlI9s:h//QvfPdDSN7GrD6Rl2kZLr9EFemw/
TLSH 49D633C4B5709AEE37C6A7413FE529E9F2A001613DD581C3A690350AD63BADFCEDE016
FOUND.000
listPlanRatio
[Authenticode]_98ba5cdb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
temporaryIconHeight
finalInvoiceError.xml
exceptionObject
resourceOutput
listPlanRatio.pub
ISKH_7565_Naznachenie_doshnost.pdf
Text (Preview)
#Stream obj 4 0
#Stream obj 8 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 11 0
#Stream obj 11 0.exif
#Stream obj 11 0-preview.png
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 9 0
#Stream obj 15 0
Structure
settingResult
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
[Authenticode]_d068fa0a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
actionMethod
[Authenticode]_a5d98da1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.buildid
.data
.pdata
.rodata
.tls
.reloc
activePictureMethod
avgPrepareLength.xml
invoicePeriod
initialGuestOutput
localChatHandler
statusTime
[Authenticode]_681ef6a5.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 2secondary ignored: 7
bin 6img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>lnk~T1059.001~T1059.003~T1202~T1204.002>lnk:cmd
Shape arc:zip>lnk>lnk:cmd
malicious 3 nodes
Path arc:zip>arc:zip>pe:exe
Shape arc:zip>arc:zip>pe:exe
3 nodes
Name Value
Version
1.7
CreationDate
D:20260623123536-07'00'
Creator
Adobe Acrobat 22.1
ModifiedDate
D:20260623123555-07'00'
Producer
Adobe Acrobat 22.1 Image Conversion Plug-in
/CreationDate
D:20260623123536-07'00'
/Creator
Adobe Acrobat 22.1
/ModDate
D:20260623123555-07'00'
/Producer
Adobe Acrobat 22.1 Image Conversion Plug-in
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
FOUND.000
listPlanRatio
[Authenticode]_98ba5cdb.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
temporaryIconHeight
finalInvoiceError.xml
exceptionObject
resourceOutput
listPlanRatio.pub
ISKH_7565_Naznachenie_doshnost.pdf
Text (Preview)
#Stream obj 4 0
#Stream obj 8 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 11 0
#Stream obj 11 0.exif
#Stream obj 11 0-preview.png
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 9 0
#Stream obj 15 0
Structure
settingResult
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
[Authenticode]_d068fa0a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
actionMethod
[Authenticode]_a5d98da1.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.buildid
.data
.pdata
.rodata
.tls
.reloc
activePictureMethod
avgPrepareLength.xml
invoicePeriod
initialGuestOutput
localChatHandler
statusTime
[Authenticode]_681ef6a5.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
No malware configuration was found at this point.
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
5f20e45252e2843506ff0cde903fa363 › ISKH_7565_Naznachenie_doshnost.‍pdf‌.lnk
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙