Malicious
Malicious

e7d1cfcf6d7a98072877715a64a64519

MS Office Document
MD5: e7d1cfcf6d7a98072877715a64a64519
Size: 32.77 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e7d1cfcf6d7a98072877715a64a64519
Sha1 e0a5b36bce2945d78277cb1448b2ba7defd3ffe2
Sha256 56f48b9fe25820b590b4e322509941de7d253b1a471c3245b4a11ec78636cf2f
Sha384 ec8cc4eb0bece7102d1664760e7db5d5ce74d14933abfb2770e90722710a7c699e30e454570ec410875f5225f83821d1
Sha512 15ff4714c23a164e5b35a6ac0a3b326d4eab42bc076d9b46fde908ecdd85b3051a7fa912b084ba45616e85048230c0a1b507d940b828b472137cafa598caec8c
SSDeep 384:EItwZsdQqWeTAOJADey3M5loXoDcnHo1x5Pey3M5sC0x:k8RWGmeWMNeWMmCU
TLSH 73E2A71676049331C58607324A2FE7E48B76AC48DF570527769AF39C2F739D062B7AE0
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕳䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.001
Shape ole:doc>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
featurhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕳䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
featurhuhuhuhuhuhuhuhuhuhuhu
e7d1cfcf6d7a98072877715a64a64519 › Root Entry › 䡀㼿䕷䑬㭪䗤䠤 › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙