Malicious
Malicious

0946d568385cefcad9fcc458af350f4e

MS Office Document
MD5: 0946d568385cefcad9fcc458af350f4e
Size: 1.06 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0946d568385cefcad9fcc458af350f4e
Sha1 4b153a15971d9111fde5f5de5eadce65009e5857
Sha256 c1fa1986e9f47abe8c9d2280802409cf4c04d9f482424880c09dcb02472acf9c
Sha384 0367df31c9fefaeb23cce1dbacb7f4c6cd406389a08e62f8867802cf7fce205a694ee69db9210756895b86d7acb876f9
Sha512 a3cc6181f897bf9d3765a7379b96550e8484700d6393e1ed6e51a993f304777863e02cd752a58094531fd96bc063130421fe785c3e6cb12c99824376acb92e5c
SSDeep 24576:Ldj8nnb6YmyH6nIKn213kqg3HGXnZzpQKnhqPbeNwftu:GnnjmOoYTSHGZGKrNwftu
TLSH DB352374FAD84F2BC591473000C7D2CA516ABF89F26C674336843B89BA799B8B773119
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00976FA0
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00976FA1
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
Author
marketing
CreationDate
D:20230518161654-05'00'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20230914115104-05'00'
Title
Microsoft Word - Warranty_TWR
Producer
Acrobat Distiller 23.0 (Windows)
Version
1.7
Author
LAB3
CreationDate
D:20260908155520+05'30'
Creator
Microsoft® Word 2016
ModifiedDate
D:20260908155520+05'30'
Producer
Microsoft® Word 2016
/Author
LAB3
/Creator
Microsoft® Word 2016
/CreationDate
D:20260908155520+05'30'
/ModDate
D:20260908155520+05'30'
/Producer
Microsoft® Word 2016
/Author
marketing
/CreationDate
D:20230518161654-05'00'
/Creator
PScript5.dll Version 5.2.2
/ModDate
D:20230914115104-05'00'
/Producer
Acrobat Distiller 23.0 (Windows)
/Title
Microsoft Word - Warranty_TWR
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00976FA0
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00976FA1
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙