Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d555e46e36e34da5779145fa8ae8bed9
Sha1 5b03dd1ece961e28febcfcb582ca58edd39da526
Sha256 625f912f4bdb5df0f2584f6b162c8602e5bb756b4853b94a12b9b9dadc25b915
Sha384 05371eeb7437903648bf18d300840e2cbce1b46fbdf016112e17488769d1ea388288a142f69b48e9ffdf8efd0b4ac557
Sha512 13dd0f79ca431da0e832d5b81f89c8335957ca5c10e72f5d5575566a1ca474233d211a8db857e3c762a899053e0f965b6e5dfe6732e9bbd8107a6c9101d4903a
SSDeep 1536:Q0SfF2p88+94VV8FFOvwhnpmAhi/ldSjXvU:QFfF2n+94oFovw9DhLbU
TLSH 4B63BF21AFEA0E48FD53CE3125F871EB483F714249E0A8590C6B4D5A4091CADE977F97
PDF @0x0000173A
#Stream obj 26 0
#Stream obj 27 0
#Stream obj 28 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 15 0
#Stream obj 19 0
#Stream obj 23 0
#Stream obj 37 0
#Stream obj 6 0
Structure
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Lnk Summary]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk~T1059.001~T1059.003~T1202~T1204.002>pdf>pdf:stream>bin
Shape lnk>pdf>pdf:stream>bin
malicious 4 nodes
Path lnk~T1059.001~T1059.003~T1202~T1204.002>lnk:cmd~T1059.001>scr:ps1~T1027~T1059.001
Shape lnk>lnk:cmd>scr:ps1
malicious 3 nodes
Name Value
Version
1.4
Author
(주)한글과컴퓨터
CreationDate
D:20260520124556+09'00'
Creator
한컴오피스 한글 2018
ModifiedDate
D:20260520124556+09'00'
Producer
Hancom PDF 1.3.0.515
/Producer
Hancom PDF 1.3.0.515
/CreationDate
D:20260520124556+09'00'
/ModDate
D:20260520124556+09'00'
/PDFVersion
1.4
PDF @0x0000173A
#Stream obj 26 0
#Stream obj 27 0
#Stream obj 28 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 15 0
#Stream obj 19 0
#Stream obj 23 0
#Stream obj 37 0
#Stream obj 6 0
Structure
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
[Lnk Summary]
Malicious
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙