Malicious
Malicious

7aa5f78836c596192702e164fbf304fd

Share on LinkedIn
Print
ZIP Archive
MD5: 7aa5f78836c596192702e164fbf304fd
Size: 530.76 KB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7aa5f78836c596192702e164fbf304fd
Sha1 bddc74cc893a7ab646cb027af60493d34ab1b388
Sha256 1ec7d1c20c93f562405cb4833d12e06357b66865eb13eaf8e43aeb4e71ebe718
Sha384 df5db7a6176bcc82858288db6183c139463ee91e09c723d564adaffc784445e1d8628c8b552f7ca89323880ff645934a
Sha512 b885523ccebbd590711223c7bf8c38dfe47203fe870055da0adbf7b0e5b5413bb4857b9d9302a92a89a996ea1a10484a17b0e8009faf9d1ba15e513b276b8974
SSDeep 12288:IgOY4+YbZVOdiK9otbwj4XZ6dJObbtRzBPdDdYENULDVbZ:IgDwZo4K+tbwQ6m7t5dZULDT
TLSH 65B423EE884BE96EC1626075C3AA8EE558E65FF937E7E71B7C08742834144111FFA903
Выписка ЕГРЮ от 11.04.24.pdf
#Stream obj 19 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 26 0
#Stream obj 27 0
#Stream obj 30 0
#Stream obj 7 0
#Stream obj 9 0
#Stream obj 31 0
#Stream obj 34 0
#Stream obj 12 0
#Stream obj 14 0
#Stream obj 16 0
Карточка Фров Трейд.doc
Root Entry
Data
1Table
CompObj
WordDocument
SummaryInformation
DocumentSummaryInformation
Свидетельство о постановке на налоговый учет.pdf
Text (Preview)
#Stream obj 4 0
#Stream obj 4 0-preview.png
#Stream obj 5 0
#Stream obj 7 0
#Stream obj 7 0-preview.png
#Stream obj 8 0
Structure
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 2img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>lnk~T1059.001~T1059.003~T1202~T1204.002~T1218>lnk:cmd>scr:ps1~T1027~T1059.001~T1105
Shape arc:zip>lnk>lnk:cmd>scr:ps1
malicious 4 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
ModifiedDate
D:20240620070451Z
Producer
iLovePDF
Version
1.4
CreationDate
D:20240412090934+00'00'
Creator
Chromium
ModifiedDate
D:20240412090934+00'00'
Producer
Skia/PDF m76
/Producer
iLovePDF
/ModDate
D:20240620070451Z
/Creator
Chromium
/Producer
Skia/PDF m76
/CreationDate
D:20240412090934+00'00'
/ModDate
D:20240412090934+00'00'
LNK: Command Execution UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Servihuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙