Malicious
MS Office Document
MD5: d61b10e126e202cc1723c28016898b98
Size: 20.37 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | d61b10e126e202cc1723c28016898b98 |
| Sha1 | cfd68bb146fc2a054cd7733b0eee665c3f91f62b |
| Sha256 | a89c4e4576d8f180a915ddc1d1233aa1b0fb0853eddafad84c3b8c2af85849ff |
| Sha384 | e27e8a9759a4b43b12fec0b9df6ca2a0af2e08bdc494ecaef5c83a5bc287109e59e951b69cbe5f9ab36d0ea417d002fa |
| Sha512 | e96b7e22204d6e51fed2df2b03793829cc334c9ad12a818d5b4b6e4778e04bff0b3d49bb9c14817734d181f3ec04c4b48e1b503aa7357cbec7c7bfb81eaa0d73 |
| SSDeep | 393216:2/ceNLS3gl9Qv87upe4GCAKUdOCu3et1bGHaDsxiY:2Dpq06tA7dhIeYEY |
| TLSH | 852733A62C262E83CA5526BB23531742AF310CB33B1187116D79F92D1CBD1FA4B5D39B |
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 14
STICH kept: 6secondary ignored: 8
bin
5img
3Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
6 / 6
Path
ole:doc>bin>scr:ps1~T1027~T1059.001
Shape
ole:doc>bin>scr:ps1
malicious
3 nodes
Path
ole:doc>bin>scr:vbs~T1059.005
Shape
ole:doc>bin>scr:vbs
technique3 nodes
Deobfuscated PowerShell
UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential