Malicious
Malicious

Share on LinkedIn
Print
MS Word Document
MD5: 04e5950966f10f89f65e79f2b6255ef5
Size: 102.93 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 04e5950966f10f89f65e79f2b6255ef5
Sha1 06f653506cdaae117a9ac598470fa7c940f2966b
Sha256 9b9a7e4ee0182c987b8c01c4041255f12a99bf8d163ed7955d0b2eab6adaccce
Sha384 53bfd5978a0e2fdc7aafbe3b525f20c3864f4318b8f955aa4485a2e1b0eda4289dac67a82e6cdd7f098d6e0f56baf7f4
Sha512 2cb03867304deec9b191346c07bf6c112111c8ff5a34a391a87b187ae8f905470320b9c5f6975b3cadaa6af221d44f98917d66f7c1a961c75319fb7b0c52bffa
SSDeep 1536:0JvFsZOOOOvUmTemkTEUF5oupFYRkgeq8isgKXBuhe7AP1/k/pQbUzydUS4Ohr8:0JvFsRzETEUF5KewN4Ro+Gr4OhY
TLSH 57A3F1C5AB854C02D2CC0175D60CDF697F766A0F0ADB698E3F7DA77E826280797B2109
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
header2.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer2.xml
footer3.xml
header3.xml
endnotes.xml
header2.xml
media
image1.emf
image2.emf
embeddings
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
drawing1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image2.emf
image1.emf
sharedStrings.xml
externalLinks
Malicious
_rels
Malicious
externalLink1.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
Microsoft_Office_Excel_Worksheet2.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
theme
theme1.xml
settings.xml
styles.xml
webSettings.xml
fontTable.xml
docProps
app.xml
core.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙