Malicious
Malicious

6729f33c27fba9320ff7d27baee5804f

Share on LinkedIn
Print
MS Office Document
MD5: 6729f33c27fba9320ff7d27baee5804f
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6729f33c27fba9320ff7d27baee5804f
Sha1 0bd754f7fb5dd002c9ff6b2f24f46907ba6f1d83
Sha256 f6abab0a0c4bfb923dfa750ab928ccdf8f4a147c6185c832afa7ec22236a6cee
Sha384 b5fcec57a63ea281b143c16ba9311a08473b2ea576b7ce33c6b1f094e79e39ec462d0e9db1593411e85efbfdf5ae3df5
Sha512 b75a842b1eff0d05ea4d6b9f0eaacf86c705344c31740b298a43c1e4fff6700faec108ff733c7614ed1b772392cfdd4678a1dde5f4f5b9c3e7ba4d91f29884df
SSDeep 768:OKk3hOdsylKlgryzc4bNhZFGzE+cL2knAJDLafoe5HG/c:pk3hOdsylKlgryzc4bNhZFGzE+cL2knL
TLSH 05D24FA2B2D6D80AD94503394CE7C6E66726FC225F63934B3289F31E1F71BC08A43657
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path ole:doc~T1027~T1059.005~T1105>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1027~T1059.005~T1105>ole:vba~T1059.005
Shape ole:doc>ole:vba
technique2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
DOCUMEhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
DOCUMEhuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙