Malicious
Malicious

0946d568385cefcad9fcc458af350f4e

Share on LinkedIn
Print
MS Office Document
MD5: 0946d568385cefcad9fcc458af350f4e
Size: 1.06 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0946d568385cefcad9fcc458af350f4e
Sha1 4b153a15971d9111fde5f5de5eadce65009e5857
Sha256 c1fa1986e9f47abe8c9d2280802409cf4c04d9f482424880c09dcb02472acf9c
Sha384 0367df31c9fefaeb23cce1dbacb7f4c6cd406389a08e62f8867802cf7fce205a694ee69db9210756895b86d7acb876f9
Sha512 a3cc6181f897bf9d3765a7379b96550e8484700d6393e1ed6e51a993f304777863e02cd752a58094531fd96bc063130421fe785c3e6cb12c99824376acb92e5c
SSDeep 24576:Ldj8nnb6YmyH6nIKn213kqg3HGXnZzpQKnhqPbeNwftu:GnnjmOoYTSHGZGKrNwftu
TLSH DB352374FAD84F2BC591473000C7D2CA516ABF89F26C674336843B89BA799B8B773119
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00976FA0
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00976FA1
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
Author
marketing
CreationDate
D:20230518161654-05'00'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20230914115104-05'00'
Title
Microsoft Word - Warranty_TWR
Producer
Acrobat Distiller 23.0 (Windows)
Version
1.7
Author
LAB3
CreationDate
D:20260908155520+05'30'
Creator
Microsoft® Word 2016
ModifiedDate
D:20260908155520+05'30'
Producer
Microsoft® Word 2016
/Author
LAB3
/Creator
Microsoft® Word 2016
/CreationDate
D:20260908155520+05'30'
/ModDate
D:20260908155520+05'30'
/Producer
Microsoft® Word 2016
/Author
marketing
/CreationDate
D:20230518161654-05'00'
/Creator
PScript5.dll Version 5.2.2
/ModDate
D:20230914115104-05'00'
/Producer
Acrobat Distiller 23.0 (Windows)
/Title
Microsoft Word - Warranty_TWR
An error has occurred. This application may no longer respond until reloaded. Reload 🗙