Malicious
MS Word Document
MD5: 04e5950966f10f89f65e79f2b6255ef5
Size: 102.93 KB
application/msword
General
Structural Analysis
Config.2
Yara Rules13
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 04e5950966f10f89f65e79f2b6255ef5
|
| Sha1 | 06f653506cdaae117a9ac598470fa7c940f2966b
|
| Sha256 | 9b9a7e4ee0182c987b8c01c4041255f12a99bf8d163ed7955d0b2eab6adaccce
|
| Sha384 | 53bfd5978a0e2fdc7aafbe3b525f20c3864f4318b8f955aa4485a2e1b0eda4289dac67a82e6cdd7f098d6e0f56baf7f4
|
| Sha512 | 2cb03867304deec9b191346c07bf6c112111c8ff5a34a391a87b187ae8f905470320b9c5f6975b3cadaa6af221d44f98917d66f7c1a961c75319fb7b0c52bffa
|
| SSDeep | 1536:0JvFsZOOOOvUmTemkTEUF5oupFYRkgeq8isgKXBuhe7AP1/k/pQbUzydUS4Ohr8:0JvFsRzETEUF5KewN4Ro+Gr4OhY
|
| TLSH | 57A3F1C5AB854C02D2CC0175D60CDF697F766A0F0ADB698E3F7DA77E826280797B2109
|
File Structure
04e5950966f10f89f65e79f2b6255ef5
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
header2.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer2.xml
footer3.xml
header3.xml
endnotes.xml
header2.xml
media
image1.emf
image2.emf
embeddings
Malicious
Microsoft_Office_Excel_Worksheet1.xlsx
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
media
image2.emf
image1.emf
sharedStrings.xml
externalLinks
Malicious
_rels
Malicious
externalLink1.xml
printerSettings
printerSettings1.bin
Microsoft_Office_Excel_Worksheet2.xlsx
theme
theme1.xml
settings.xml
styles.xml
webSettings.xml
fontTable.xml
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu
|
| Path | settihuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu
|
| Path | externhuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Artefacts
|
Name | Value |
|---|---|
| Remote Template - Highly Suspicious | https:huhuhuhuhuhuhuhuhuhuhu
|
| Remote Template - Highly Suspicious | file:/huhuhuhuhuhuhuhuhuhuhu
|
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
04e5950966f10f89f65e79f2b6255ef5 (102.93 KB)
File Structure
04e5950966f10f89f65e79f2b6255ef5
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
header2.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer2.xml
footer3.xml
header3.xml
endnotes.xml
header2.xml
media
image1.emf
image2.emf
embeddings
Malicious
Microsoft_Office_Excel_Worksheet1.xlsx
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
media
image2.emf
image1.emf
sharedStrings.xml
externalLinks
Malicious
_rels
Malicious
externalLink1.xml
printerSettings
printerSettings1.bin
Microsoft_Office_Excel_Worksheet2.xlsx
theme
theme1.xml
settings.xml
styles.xml
webSettings.xml
fontTable.xml
Characteristics
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu
|
| Path | settihuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu
|
| Path | externhuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Artefacts
|
Name | Value | Location |
|---|---|---|
| Remote Template - Highly Suspicious | https:huhuhuhuhuhuhuhuhuhuhu
Malicious |
04e5950966f10f89f65e79f2b6255ef5 > word > _rels > settings.xml.rels |
| Remote Template - Highly Suspicious | file:/huhuhuhuhuhuhuhuhuhuhu
Malicious |
04e5950966f10f89f65e79f2b6255ef5 > word > embeddings > Microsoft_Office_Excel_Worksheet1.xlsx > xl > externalLinks > _rels > externalLink1.xml.rels |
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.