Malicious
Malicious
MS Office Document
MD5: 1e09854c33f885f5f1d42b5e539607c6
Size: 1.14 MB
application/vnd.ms-office
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
1e09854c33f885f5f1d42b5e539607c6
Sha1
bfefe0cb64c27189ec8b9e541c7cd35267271b0d
Sha256
1d97f8703f3e94dbb0e8f6a464a3dfbf31d6af073637f4cbd87127daed555391
Sha384
642367e5f3d0364fef7eba36f81361db1c3f8c5e3f8240d6c802e2d31a75bd15f2e8e15e1aab970f530ba32fcb69d0ab
Sha512
06c3812696fd6939894b8aff02a90b7052fc67fcaf5005b005c71816b0e282d5e343aecdba8a03aa6245ee9c6bd0020f7f7d13dd53d287d039348348f4595f01
SSDeep
12288:PAPXRC3A+79QG0WW7zqzjP1wRBME1LrwCJyzcdd1OJRR3c9B2xzfArBP3C+rRIYz:PA/EkAPErjtOJ3jzfyB/zeYiyKr
TLSH
6735124C7599E549C37547B2DFC2C0D2910EBC679E8A811B328E7B5F3F32DA1AA4314A
File Structure
[Repaired @0x00000E00]
Malicious
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0006D1EE
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet2.xml
sheet3.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet7.xml.rels
sheet6.xml.rels
sheet5.xml.rels
sheet4.xml.rels
sheet1.xml
sheet13.xml
sheet12.xml
sheet11.xml
sheet10.xml
sheet9.xml
sheet8.xml
sheet7.xml
sheet6.xml
sheet5.xml
sheet14.xml
sheet15.xml
sheet16.xml
media
image1.emf
drawings
vmlDrawing1.vml
_rels
vmlDrawing1.vml.rels
sharedStrings.xml
theme
theme1.xml
styles.xml
printerSettings
printerSettings4.bin
printerSettings2.bin
printerSettings3.bin
printerSettings1.bin
printerSettings5.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD0006D1EF
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001CD4CA
Ole
CompObj
CONTENTS
#Stream {UglyToad.PdfPig.Core.XrefLocation}
#Stream {UglyToad.PdfPig.Core.XrefLocation}.exif
#Stream {UglyToad.PdfPig.Core.XrefLocation}-preview.png
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
MBD0006D1F0
Ole
_VBA_PROJECT_CUR
PROJECT
VBA
dir
_VBA_PROJECT
Malware Configuration - Remote Template
Config. Field
Value
Target

file:///F:\Copy%20of%20Muiltple%20master%20July%202016%20(003).xlsx

Path

externalLink1.xml.rels

XPath

/Relationships/Relationship

Outer XML

<Relationship Id="rId1" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/externalLinkPath" Target="file:///F:\Copy%20of%20Muiltple%20master%20July%202016%20(003).xlsx" TargetMode="External" xmlns="http://schemas.openxmlformats.org/package/2006/relationships" />

Informations
Name
Value
CONTENTS

1.7

CONTENTS

Absa Retail

CONTENTS

D:20260622120032Z

CONTENTS

DocFusion

CONTENTS

D:20260622120032Z

CONTENTS

DocFusion

CONTENTS

DocFusion

CONTENTS

D:20260622120032Z

CONTENTS

D:20260622120032Z

CONTENTS

DocFusion

CONTENTS

Absa Retail

CONTENTS

1.7

CONTENTS

D:20250805070422+02'00'

CONTENTS

abas Version 2019r4n20p60

CONTENTS

D:20250819130104+08'00'

CONTENTS

iText 2.1.7 by 1T3XT

CONTENTS

D:20250805070422+02'00'

CONTENTS

abas Version 2019r4n20p60

CONTENTS

D:20250819130104+08'00'

CONTENTS

iText 2.1.7 by 1T3XT

Artefacts
Name
Value
Remote Template - Highly Suspicious

file:///F:\Copy%20of%20Muiltple%20master%20July%202016%20(003).xlsx

URI

mailto:privacy@absa.co.za

PDF @0x00000000 (1.14 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙