Malicious
Malicious

905e88594dbc44c47737ead834b4b513

MS Office Document
MD5: 905e88594dbc44c47737ead834b4b513
Size: 32.77 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 905e88594dbc44c47737ead834b4b513
Sha1 cd5bef05f9c2b057c1212cd5761b3f3c520740fa
Sha256 26fdb0624a5cfd6e4103db61880caacce2b4e4d9459f63f608283d2925688aa8
Sha384 c47ed7c1ddbe20fa0ecbad3027ba0be3d926ca15504e0e4bac146ab6e5d8a5f85c8022e862b421ef9d79b21c3809efa0
Sha512 7f6bbba0e1f696c136f8d1cd4e3f78ee6bfad699a1b78627f9d7e3db8a1c080e16479e3cfc36ef2eb4d06cdec68d2d5b3191f3eab309f0732f1f963acc2f3c3c
SSDeep 384:BezOZ48glidD3QO2yCey3M5aoXoLHo1x5Pey3M5sC0x:v47lidVueWMbeWMmCU
TLSH 03E2A41776049231C5861331896FE7E48B76AC48DF671427369BB39C2F73AD061B7AE0
Pwshscript
Pythscript
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕳䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.001
Shape ole:doc>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
featurhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Pwshscript
Pythscript
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕳䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
featurhuhuhuhuhuhuhuhuhuhuhu
905e88594dbc44c47737ead834b4b513 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙