Malicious
MS Office Document
MD5: ac108558ae3c869e43266664e70d20a3
Size: 20.36 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | ac108558ae3c869e43266664e70d20a3 |
| Sha1 | 68d5a2459a4a19af4e0e7f60daeb8c662f14a912 |
| Sha256 | ae89a8bbb5dc1d716edbc2d8a9bff87906ecfbb4c74f63f3aadf58b935189b54 |
| Sha384 | dfe8741e8deda70be34d1a31004d41228ae014701879f903bd6ba80a9f5f0a8eb2bd060df92023f0e6b65a388bad59b6 |
| Sha512 | fd1b7fd4d7d0c585e35b9f510f8f1c905fd8aca73208ea5bcccd2711c52e92abe1fb41f9bdbbb04c4077389ae09bcfdbd6af70ed0d6ac895c9f13c4c09674006 |
| SSDeep | 393216:kncN/pyn3S3glJQv87upm4GCAKUd2Cu3et11GCaTSLiY:kU2p+06NA7dpIetOY |
| TLSH | C92733A668262E83CA6026BB23531702BF310DB33B1187512D79F92D1CBD1FA5B5D35B |
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 14
STICH kept: 6secondary ignored: 8
bin
5img
3Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
6 / 6
Path
ole:doc>bin>scr:ps1~T1027~T1059.001
Shape
ole:doc>bin>scr:ps1
malicious
3 nodes
Path
ole:doc>bin>scr:vbs~T1059.005
Shape
ole:doc>bin>scr:vbs
technique3 nodes
Deobfuscated PowerShell
UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential