Malicious
Malicious

Share on LinkedIn
Print
MS Word Document
MD5: 04e5950966f10f89f65e79f2b6255ef5
Size: 102.93 KB
application/msword
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
04e5950966f10f89f65e79f2b6255ef5
Sha1
06f653506cdaae117a9ac598470fa7c940f2966b
Sha256
9b9a7e4ee0182c987b8c01c4041255f12a99bf8d163ed7955d0b2eab6adaccce
Sha384
53bfd5978a0e2fdc7aafbe3b525f20c3864f4318b8f955aa4485a2e1b0eda4289dac67a82e6cdd7f098d6e0f56baf7f4
Sha512
2cb03867304deec9b191346c07bf6c112111c8ff5a34a391a87b187ae8f905470320b9c5f6975b3cadaa6af221d44f98917d66f7c1a961c75319fb7b0c52bffa
SSDeep
1536:0JvFsZOOOOvUmTemkTEUF5oupFYRkgeq8isgKXBuhe7AP1/k/pQbUzydUS4Ohr8:0JvFsRzETEUF5KewN4Ro+Gr4OhY
TLSH
57A3F1C5AB854C02D2CC0175D60CDF697F766A0F0ADB698E3F7DA77E826280797B2109
File Structure
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
header2.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer2.xml
footer3.xml
header3.xml
endnotes.xml
header2.xml
media
image1.emf
image2.emf
embeddings
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
drawing1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image2.emf
image1.emf
sharedStrings.xml
externalLinks
Malicious
_rels
Malicious
externalLink1.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
Microsoft_Office_Excel_Worksheet2.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
theme
theme1.xml
settings.xml
styles.xml
webSettings.xml
fontTable.xml
docProps
app.xml
core.xml
Malware Configuration - Remote Template
Config. Field
Value
Target
https:huhuhuhuhuhuhuhuhuhuhu
Path
settihuhuhuhuhuhuhu
XPath
/Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML
<Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Malware Configuration - Remote Template
Config. Field
Value
Target
file:/huhuhuhuhuhuhuhuhuhuhu
Path
externhuhuhuhuhuhuhu
XPath
/Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML
<Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Artefacts
Name
Value
Remote Template - Highly Suspicious
https:huhuhuhuhuhuhuhuhuhuhu
Remote Template - Highly Suspicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
04e5950966f10f89f65e79f2b6255ef5 (102.93 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙