Malicious
Malicious

7a6e1e578342864c1bb07c83b4e677e3

Share on LinkedIn
Print
LNK File
MD5: 7a6e1e578342864c1bb07c83b4e677e3
Size: 333.84 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7a6e1e578342864c1bb07c83b4e677e3
Sha1 29c19cf3900d1b8e03a83b57e604ff79d8f43e3b
Sha256 297292d46d4f11fc801f5d6d01251735698a8419aa3196db7b3aa7bb8ea85cad
Sha384 b8472552dd9ec1e3bbbda48e5c68a3cd827f74a463cfcd5d9e6a493770e616e944bc9d811df9e9d5ae6fa44ff6e7349b
Sha512 01fc70679bb99c93dc3c574b8572607aba1c7815dd9872ead1b72baddee5be415a5051d22c494709803e5982dc87a8f44ff22eed6d1af30f9db7ae5f02eb321b
SSDeep 6144:B3ORfxkzQfSWD/MUwWR2nOvN9rkkrnpfGMLQYSvwTFxZPNs94SE:ByfxksfSWDEsR2apOMLl29k
TLSH 1964F020484C7CDED26197F14B1F7D1E760D72B6F6C486953BACCB8643A0A2BA45362F
7a6e1e578342864c1bb07c83b4e677e3
Malicious
PDF @0x0000079C
#Stream obj 443 0
#Stream obj 442 0
#Stream obj 451 0
#Stream obj 450 0
#Stream obj 447 0
#Stream obj 446 0
#Stream obj 4 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 456 0
#Stream obj 455 0
#Stream obj 39 0
#Stream obj 48 0
#Stream obj 460 0
#Stream obj 50 0
#Stream obj 461 0
#Stream obj 61 0
#Stream obj 463 0
Structure
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk>scr:ps1~T1027~T1059.001~T1105
Shape lnk>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
URL #7 https:huhuhuhuhuhuhuhuhuhuhu
URL #8 https:huhuhuhuhuhuhuhuhuhuhu
URL #9 https:huhuhuhuhuhuhuhuhuhuhu
URL #10 https:huhuhuhuhuhuhuhuhuhuhu
URL #11 https:huhuhuhuhuhuhuhuhuhuhu
URL #12 https:huhuhuhuhuhuhuhuhuhuhu
URL #13 https:huhuhuhuhuhuhuhuhuhuhu
URL #14 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Un-named
CreationDate
D:20260730100908-07'00'
Creator
Microsoft® Word 2019
ModifiedDate
D:20260730100908-07'00'
Producer
Microsoft® Word 2019
/Author
Un-named
/Creator
Microsoft® Word 2019
/CreationDate
D:20260730100908-07'00'
/ModDate
D:20260730100908-07'00'
/Producer
Microsoft® Word 2019
Deobfuscated PowerShell UNKNWOWNmalicious
"" $uhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙