Suspicious
Suspect

ee271237806f726412e7e53507650f3c

Share on LinkedIn
Print
MS Office Document
MD5: ee271237806f726412e7e53507650f3c
Size: 8.36 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ee271237806f726412e7e53507650f3c
Sha1 5581cf2ca70bba1ae5e2d7a21da0328464f2e8d4
Sha256 3a41acf04286e9fb1bdbcc2773c62cfba717bce93a892ecb738792cd014d4ddc
Sha384 d353fcd057063e24907616735fed5e491f56aaa5dd59936e13cc99e4c0ce20587ce83f22ef9360619a1b4bb36ec6e6cc
Sha512 1a7eb1f9ba6f20d6e64b31ea29edc43f5673879a8d6c51c7156393b7018976832f3ad12df06823f03784c1cff95cb7a00b2fd7be16a6c2346568191bef60f415
SSDeep 196608:E3KoUc4BPw8VAzd6Z5ls2DafDN70uL4U2liSJnvsOTN:GnWP2xSgZ70uFQfvsO
TLSH 14863348FEA14B05DCF582B8415A8723771E0CE1BB46D557CA2F727C1A7A2B98BD70E0
Root Entry
䡀䌏䈯
[Authenticode]_c52a3fc9.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0065
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
xIQBf5NCg
[Authenticode]_44610408.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.didat
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
AykEew50WTG
[Authenticode]_15b1e3b7.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
fothk
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
vChBovO3o
fsv2sG4PsbWDxQiUHJSv
xIQBf5NCg
AykEew50WTG
DEWTud3JSrCytqK
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 1secondary ignored: 7
bin 6img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>bin>pe:dll
Shape ole:doc>bin>pe:dll
3 nodes
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙