Malicious
MS Office Document
MD5: 8f85542d9c8a70c1ec891fb0ba7e8d7e
Size: 2.8 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 8f85542d9c8a70c1ec891fb0ba7e8d7e |
| Sha1 | 6c0f8b8b8ea8d94500a61c4883bca4728ee6eb55 |
| Sha256 | e16618583b9255c3c03feeaa9da1e7c3ef2291764421c0851ecae398c90a5f17 |
| Sha384 | ce24a61ce72b53bdc57532ce116cf9f24a96d02b4e24453c5ec3967ca2931caa07407b87870fbad7eacc18cbe20f0492 |
| Sha512 | 59454f1800dd49f542a4622f8ef3227836e5d787cd7a613175202c40492d780be83c984eb7c99a835ed5aeffb5d845317d22daa0b4c879bcf84c277307d57bc3 |
| SSDeep | 49152:zm8Y8hUpqLOSGRLvpLA6Kwp9MftgkaATVqVZ9Rw4YP/BD/vTkPduTRUhfwEdeW:dYTpqLNoZA5qLPdXeW |
| TLSH | 4FD56C0177C3C03AD97E89702AA5EB7A007B7FA61BB484DB57E41D6A39714C202B1F67 |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 10
STICH kept: 4secondary ignored: 6
bin
5img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
ole:doc>scr:ps1~T1027~T1059.001~T1105
Shape
ole:doc>scr:ps1
malicious
2 nodes
Path
ole:doc>pe:dll~T1059.007>pe:rsrc>bin
Shape
ole:doc>pe:dll>pe:rsrc>bin
technique4 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential