Malicious
Malicious

ecc825caa8479ed1ad7e83ad9c8ab5e6

MS Office Document
MD5: ecc825caa8479ed1ad7e83ad9c8ab5e6
Size: 30.72 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ecc825caa8479ed1ad7e83ad9c8ab5e6
Sha1 bfa95331a132162257994b4323f521d0167fb9db
Sha256 1948744d57d7a91b585031df5e3c3a5f911811ca0c010594b9b851f904a06ad4
Sha384 b5e33ca62c1d48994554f1d217a1d95118827efeb5772800e6d3c760a380b9fa448139c2edb672a5db79fc134f70752c
Sha512 8f9b28029c020da9d7e21b9b014630de20d04359775bea96752ce12bc66b9532b5e713c80566f16da77ff6a06849efbe82dc742a20478ea9fdffe35aa6938246
SSDeep 768:bpydEHnOhAevH4nCFShnL0IeWMbCSPzN/nq:gmHOhAWFFShnIIobO
TLSH 05D27D46F941C332CA815B325B5BD7F48F36AC55DF932003369AB34C2E729A02AB75E0
BCeLyIF1lktV
[PowerShell Command]
Malicious
wSxjzqPCP_Sz
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕙䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 2secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>scr:ps1~T1027~T1059.001
Shape ole:doc>scr:ps1
malicious 2 nodes
Path ole:doc>scr:ps1
Shape ole:doc>scr:ps1
2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
param(huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
BCeLyIF1lktV
[PowerShell Command]
Malicious
wSxjzqPCP_Sz
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䕙䓲䕨䜷
䕙䇲䆸䞷䄦䠥
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
param(huhuhuhuhuhuhuhuhuhuhu
ecc825caa8479ed1ad7e83ad9c8ab5e6 › DYLhN3FbIl02 › [Deobfuscated PS]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙