Malicious
788922438dfbd620e0317545e2542c43
MS Office Document
MD5: 788922438dfbd620e0317545e2542c43
Size: 8.77 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 788922438dfbd620e0317545e2542c43 |
| Sha1 | c28279a4836fd30c48408bff7a8b824d88488635 |
| Sha256 | 492f3ab6828bef36c19d5b34cf47c76587f7455960c44ea54b472b4371851bbf |
| Sha384 | e456ab4e1eb6212b934ea9f0f789a2f151e14127f1fedbe9ec98603163c4eab45bb079f2e5c8f4996d0ebc30db6e75b6 |
| Sha512 | 0d2cab5ca9ab3499aa77b8502331a865b4a3e2b0c884a2eebc4da0da60bab0e2f58c273fd089abb8d100d66d7299fef11de1fe57b99fb762ebff1063cc2143b4 |
| SSDeep | 196608:oWZPr/HhX/bujFdQftE4DNAKc1ns5ixOoWETjExC7/9m/BQ:LPr/hyI/DNUs5iLWdC7/9T |
| TLSH | F096331AB7D00CA9E8B79275D9A78125EFB5BC083320C95F0368720A5F3BBA0757B715 |
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 5
STICH kept: 1secondary ignored: 4
bin
3img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>scr:ps1~T1027~T1059.001~T1105
Shape
ole:doc>scr:ps1
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
788922438dfbd620e0317545e2542c43 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.