Malicious
Malicious

fa87911771a52e3c1ffb1c39da59540c

LNK File
MD5: fa87911771a52e3c1ffb1c39da59540c
Size: 333.81 KB
application/x-ms-shortcut
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fa87911771a52e3c1ffb1c39da59540c
Sha1 a8fbf9c78c1c1a3f34bf18bc6c2aedfa842fe15c
Sha256 d398f11c236a59e44a9dff6f99af3aacefcb4a4bdf77bb7cf790cd0b13b0439a
Sha384 ca2e523e27076220c6a3e1cd997e1b93e2834a804b29ca2136c0a82742d452a0fa84315ad39f308225bd481055fb84c1
Sha512 b826fd9891b63060ca7f03a7d383ff745e7b3980c9af443dcf30104d4a36dcaf7750719eb79975612963795d86353435d873a6a0d11cd0267452e0671b4802d3
SSDeep 6144:R3ORfxkzQfSWD/MUwWR2nOvN9rkkrnpfGMLQYSvwTFxZPNs94SE:RyfxksfSWDEsR2apOMLl29k
TLSH D464F020484C7CDEC26197F14B1F7D1E760D72B6F6C486953BACCB8643A0A2BA45362F
fa87911771a52e3c1ffb1c39da59540c
Malicious
PDF @0x00000782
#Stream obj 443 0
#Stream obj 442 0
#Stream obj 451 0
#Stream obj 450 0
#Stream obj 447 0
#Stream obj 446 0
#Stream obj 4 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 456 0
#Stream obj 455 0
#Stream obj 39 0
#Stream obj 48 0
#Stream obj 460 0
#Stream obj 50 0
#Stream obj 461 0
#Stream obj 61 0
#Stream obj 463 0
Structure
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 2 STICH kept: 1secondary ignored: 1
bin 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path lnk>scr:ps1~T1027~T1059.001~T1105
Shape lnk>scr:ps1
malicious 2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
URL #7 https:huhuhuhuhuhuhuhuhuhuhu
URL #8 https:huhuhuhuhuhuhuhuhuhuhu
URL #9 https:huhuhuhuhuhuhuhuhuhuhu
URL #10 https:huhuhuhuhuhuhuhuhuhuhu
URL #11 https:huhuhuhuhuhuhuhuhuhuhu
URL #12 https:huhuhuhuhuhuhuhuhuhuhu
URL #13 https:huhuhuhuhuhuhuhuhuhuhu
URL #14 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Un-named
CreationDate
D:20260730100908-07'00'
Creator
Microsoft® Word 2019
ModifiedDate
D:20260730100908-07'00'
Producer
Microsoft® Word 2019
/Author
Un-named
/Creator
Microsoft® Word 2019
/CreationDate
D:20260730100908-07'00'
/ModDate
D:20260730100908-07'00'
/Producer
Microsoft® Word 2019
Deobfuscated PowerShell UNKNWOWNmalicious
"" $uhuhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
fa87911771a52e3c1ffb1c39da59540c
Malicious
PDF @0x00000782
#Stream obj 443 0
#Stream obj 442 0
#Stream obj 451 0
#Stream obj 450 0
#Stream obj 447 0
#Stream obj 446 0
#Stream obj 4 0
#Stream obj 31 0
#Stream obj 33 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 456 0
#Stream obj 455 0
#Stream obj 39 0
#Stream obj 48 0
#Stream obj 460 0
#Stream obj 50 0
#Stream obj 461 0
#Stream obj 61 0
#Stream obj 463 0
Structure
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
URL #7 https:huhuhuhuhuhuhuhuhuhuhu
URL #8 https:huhuhuhuhuhuhuhuhuhuhu
URL #9 https:huhuhuhuhuhuhuhuhuhuhu
URL #10 https:huhuhuhuhuhuhuhuhuhuhu
URL #11 https:huhuhuhuhuhuhuhuhuhuhu
URL #12 https:huhuhuhuhuhuhuhuhuhuhu
URL #13 https:huhuhuhuhuhuhuhuhuhuhu
URL #14 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Deobfuscated PowerShell UNKNWOWNmalicious
"" $uhuhuhuhuhuhuhuhuhuhuhu
fa87911771a52e3c1ffb1c39da59540c › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #1 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
fa87911771a52e3c1ffb1c39da59540c › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
fa87911771a52e3c1ffb1c39da59540c › [Lnk Summary] › [PowerShell Command]
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
fa87911771a52e3c1ffb1c39da59540c › [Lnk Summary] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙