Malicious
Malicious

788922438dfbd620e0317545e2542c43

MS Office Document
MD5: 788922438dfbd620e0317545e2542c43
Size: 8.77 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 788922438dfbd620e0317545e2542c43
Sha1 c28279a4836fd30c48408bff7a8b824d88488635
Sha256 492f3ab6828bef36c19d5b34cf47c76587f7455960c44ea54b472b4371851bbf
Sha384 e456ab4e1eb6212b934ea9f0f789a2f151e14127f1fedbe9ec98603163c4eab45bb079f2e5c8f4996d0ebc30db6e75b6
Sha512 0d2cab5ca9ab3499aa77b8502331a865b4a3e2b0c884a2eebc4da0da60bab0e2f58c273fd089abb8d100d66d7299fef11de1fe57b99fb762ebff1063cc2143b4
SSDeep 196608:oWZPr/HhX/bujFdQftE4DNAKc1ns5ixOoWETjExC7/9m/BQ:LPr/hyI/DNUs5iLWdC7/9T
TLSH F096331AB7D00CA9E8B79275D9A78125EFB5BC083320C95F0368720A5F3BBA0757B715
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Atera.Agent.Installer.Msi.Ca.Properties.Resources.resources
icon
icon-preview.png
[Authenticode]_83e5e138.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
WixToolset.Dtf.WindowsInstaller.Errors.resources
CustomAction.config
Root Entry
Malicious
䡀䌏䈯
䄦㡥䆾䅤
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛㵪䆲䗤䕲
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀䓊㼳䄨䆵䠫
䡀㼿䕷䑬㭪䗤䠤
Malicious
[PowerShell Command]
Malicious
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䈜䙵䆬㬨䑲䕷䏲
䡀䈜䙵䆬㲨䖱䄷䏯
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
[Authenticode]_f9ab9279.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
Overlay_dd69ae97.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
DigitalSignature
SummaryInformation
MsiDigitalSignatureEx
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
bin 3img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.001~T1105
Shape ole:doc>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Atera.Agent.Installer.Msi.Ca.Properties.Resources.resources
icon
icon-preview.png
[Authenticode]_83e5e138.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
WixToolset.Dtf.WindowsInstaller.Errors.resources
CustomAction.config
Root Entry
Malicious
䡀䌏䈯
䄦㡥䆾䅤
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛㵪䆲䗤䕲
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀䓊㼳䄨䆵䠫
䡀㼿䕷䑬㭪䗤䠤
Malicious
[PowerShell Command]
Malicious
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䘌䗶䐲䆊䌷䑲
䡀䈜䙵䆬㬨䑲䕷䏲
䡀䈜䙵䆬㲨䖱䄷䏯
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
[Authenticode]_f9ab9279.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
Overlay_dd69ae97.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
DigitalSignature
SummaryInformation
MsiDigitalSignatureEx
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
788922438dfbd620e0317545e2542c43 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙