Malicious
Malicious

714a55991a0dfca0fc87868fcd7d8e1f

MS Office Document
MD5: 714a55991a0dfca0fc87868fcd7d8e1f
Size: 65.54 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 714a55991a0dfca0fc87868fcd7d8e1f
Sha1 9585436f584ddec148d41da8c1e2ea77e01200ea
Sha256 cac69561dbd3ef68e15c80be25b754f8a19e3f0849ffaf99af64de4d8118e63c
Sha384 3976d7c4f3c44dbb0e592d0734586a7ad8c3f109fa2a200536a8b078320ef7339bdabc70b66adc8323c59b64ff1c2cca
Sha512 573c8d915f9d4aa7d4d5d8059fd085d58a4a6e5869025173870ffe10b1cca1f0183cdd89ac77cb7ca8404134bf28e9ad69fdfe41d7df686f8a865a97448db1d1
SSDeep 768:HuZTbl+MomHmBwCuXbgRpRCG+fYGAScLYix5ONZ:kTD6wVgRyG+fYVMsAj
TLSH DE53C7237A445333C1421372961FA3E49F798C5C4BF74252356AB29C1EB1EB462FB8E6
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䕙䓲䕨䜷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.005~T1105>scr:vbs~T1059.005
Shape ole:doc>scr:ps1>scr:vbs
malicious 3 nodes
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䕙䓲䕨䜷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
Config. Field Value
URL (COM trace) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
714a55991a0dfca0fc87868fcd7d8e1f › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
714a55991a0dfca0fc87868fcd7d8e1f › Root Entry › 䡀㼿䕷䑬㭪䗤䠤
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙