Malicious
Malicious

c17db3d1b467c1103bb9528df44c7884

Share on LinkedIn
Print
MS Office Document
MD5: c17db3d1b467c1103bb9528df44c7884
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c17db3d1b467c1103bb9528df44c7884
Sha1 834d309e4abbd8912518ab6a6ba61dd53dfdd52b
Sha256 450b9cc8a3b5b9e1a92f6050de8fd610d2866a25e28701861ebb3ccb7e4b17cf
Sha384 c2c04bd8908f65171b04a75acd6c3c9b5bb071648c7a914a65d75cdd6a57392d0a77a330db19529462b789af7d5893df
Sha512 aefc3a5f315bc6f962158201990bafd6bfbaa6060baff25c338a893a22e2caca66d76cecec70f8d1240cab3e204aee4fc2383aacd9d522124c3959714d795fdb
SSDeep 768:/Kk3hOdsylKlgryzc4bNhZFGzE+cL2knAJD/TfoJV2yax:Sk3hOdsylKlgryzc4bNhZFGzE+cL2kn0
TLSH 02D23DA2B3D6D80AD94507394CE7C6E66726FC226F63834B3289F31E1F71AC08953657
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path ole:doc~T1027~T1059.005~T1105>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1027~T1059.005~T1105>ole:vba~T1027~T1059.005~T1105
Shape ole:doc>ole:vba
technique2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
Doc91huhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
Doc91huhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙