Malicious
Malicious

7a6e1e578342864c1bb07c83b4e677e3

LNK File
MD5: 7a6e1e578342864c1bb07c83b4e677e3
Size: 333.84 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7a6e1e578342864c1bb07c83b4e677e3
Sha1 29c19cf3900d1b8e03a83b57e604ff79d8f43e3b
Sha256 297292d46d4f11fc801f5d6d01251735698a8419aa3196db7b3aa7bb8ea85cad
Sha384 b8472552dd9ec1e3bbbda48e5c68a3cd827f74a463cfcd5d9e6a493770e616e944bc9d811df9e9d5ae6fa44ff6e7349b
Sha512 01fc70679bb99c93dc3c574b8572607aba1c7815dd9872ead1b72baddee5be415a5051d22c494709803e5982dc87a8f44ff22eed6d1af30f9db7ae5f02eb321b
SSDeep 6144:B3ORfxkzQfSWD/MUwWR2nOvN9rkkrnpfGMLQYSvwTFxZPNs94SE:ByfxksfSWDEsR2apOMLl29k
TLSH 1964F020484C7CDED26197F14B1F7D1E760D72B6F6C486953BACCB8643A0A2BA45362F
7a6e1e578342864c1bb07c83b4e677e3
Malicious
PDF @0x0000079C
#Stream obj 443 0
#Stream obj 442 0
#Stream obj 451 0
#Stream obj 450 0
#Stream obj 447 0
#Stream obj 446 0
#Stream obj 4 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 456 0
#Stream obj 455 0
#Stream obj 39 0
#Stream obj 48 0
#Stream obj 460 0
#Stream obj 50 0
#Stream obj 461 0
#Stream obj 61 0
#Stream obj 463 0
Structure
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk>scr:ps1~T1027~T1059.001~T1105
Shape lnk>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
URL #7 https:huhuhuhuhuhuhuhuhuhuhu
URL #8 https:huhuhuhuhuhuhuhuhuhuhu
URL #9 https:huhuhuhuhuhuhuhuhuhuhu
URL #10 https:huhuhuhuhuhuhuhuhuhuhu
URL #11 https:huhuhuhuhuhuhuhuhuhuhu
URL #12 https:huhuhuhuhuhuhuhuhuhuhu
URL #13 https:huhuhuhuhuhuhuhuhuhuhu
URL #14 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Un-named
CreationDate
D:20260730100908-07'00'
Creator
Microsoft® Word 2019
ModifiedDate
D:20260730100908-07'00'
Producer
Microsoft® Word 2019
/Author
Un-named
/Creator
Microsoft® Word 2019
/CreationDate
D:20260730100908-07'00'
/ModDate
D:20260730100908-07'00'
/Producer
Microsoft® Word 2019
Deobfuscated PowerShell UNKNWOWNmalicious
"" $uhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
7a6e1e578342864c1bb07c83b4e677e3
Malicious
PDF @0x0000079C
#Stream obj 443 0
#Stream obj 442 0
#Stream obj 451 0
#Stream obj 450 0
#Stream obj 447 0
#Stream obj 446 0
#Stream obj 4 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 456 0
#Stream obj 455 0
#Stream obj 39 0
#Stream obj 48 0
#Stream obj 460 0
#Stream obj 50 0
#Stream obj 461 0
#Stream obj 61 0
#Stream obj 463 0
Structure
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
URL #7 https:huhuhuhuhuhuhuhuhuhuhu
URL #8 https:huhuhuhuhuhuhuhuhuhuhu
URL #9 https:huhuhuhuhuhuhuhuhuhuhu
URL #10 https:huhuhuhuhuhuhuhuhuhuhu
URL #11 https:huhuhuhuhuhuhuhuhuhuhu
URL #12 https:huhuhuhuhuhuhuhuhuhuhu
URL #13 https:huhuhuhuhuhuhuhuhuhuhu
URL #14 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
"" $uhuhuhuhuhuhuhuhuhuhuhu
7a6e1e578342864c1bb07c83b4e677e3 › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7a6e1e578342864c1bb07c83b4e677e3 › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7a6e1e578342864c1bb07c83b4e677e3 › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
7a6e1e578342864c1bb07c83b4e677e3 › [Lnk Summary] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙