Suspect
MS Office Document
MD5: b501f679d574c3f09a05172fb7c9a2af
Size: 24.25 MB
application/vnd.ms-office
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b501f679d574c3f09a05172fb7c9a2af |
| Sha1 | 1e333068b17a2fe4bd087428d9bb0bda0a08cba9 |
| Sha256 | 89b0e70fe9e1e4e08e2437b144f06fd242e86cec1846388e1faf38892a769eec |
| Sha384 | ef9a4f26c3e179bb92bc0f619e1cda3acab3c86c2fed5ea30b921a7e5c3991a39ad7ecfe594d04d455a3b325d60b1a5a |
| Sha512 | 406226ef7e04919084f722d1f058fea82788dfc590c63a1b912dca0170a486910f6acd319296c13f27475eab4f67e366ac9037c44eb44a1b853319c0aea06674 |
| SSDeep | 393216:76ohU+8bjJ8kQu9ySZ8EN6ohU+8bjJ8T6ohU+8bjJ8M6ohU+8bjJ8Y6ohU+8bjJO:uoh0bjN9ySZzkoh0bjPoh0bjQoh0bjKG |
| TLSH | 063733211BFDD855EAB30B75FA7782B44637BC526911A05F13A13A0D1A32F829E93373 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 11
STICH kept: 2secondary ignored: 9
bin
8img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>pe:dll>pe:dll
Shape
ole:doc>pe:dll>pe:dll
3 nodes
Path
ole:doc>pe:dll
Shape
ole:doc>pe:dll
2 nodes
PE Layout
UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential