Malicious
2f1c96eba3a856288c370ddcdbe0aad8
MS Office Document
MD5: 2f1c96eba3a856288c370ddcdbe0aad8
Size: 798.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 2f1c96eba3a856288c370ddcdbe0aad8 |
| Sha1 | 14429db6efc656d2fef5b541aa06d31353bd2a59 |
| Sha256 | 88ce5e04d4fb0174d659e2d945f9077718ad643bbf32bffee16b2236364a4df4 |
| Sha384 | 499b9b4fc11fedf434b6e455b9d4ac7052cccd033b9755f4a008fe0db1f512b8163259d152abd2f80e7a5685a8c549fb |
| Sha512 | 30aa64cea51ac45768ddaa793a4694fe78096a5799ed2f59352eda7f6068070e7002392652119edb3c62a3f1cd745e101cdf930feb0d3a8b07e91cd0461f8afc |
| SSDeep | 24576:RrizeJ86MZMC4I1rOmCXh9Ugfwv673RlT:RriqJ8LQYCvUg4v6tl |
| TLSH | 7C052300FECADE1BC847C5388BD99DDBA999BD341F03D9873352B39E157952021E3A26 |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 11
STICH kept: 2secondary ignored: 9
bin
4img
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape
ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.7 |
| CreationDate | D:20260802163606-08'00' |
| Creator | HP Scan |
| ModifiedDate | D:20260802163606-08'00' |
| Producer | HP Scan Extended Application |
| /Creator | HP Scan |
| /CreationDate | D:20260802163606-08'00' |
| /ModDate | D:20260802163606-08'00' |
| /Producer | HP Scan Extended Application |
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
2f1c96eba3a856288c370ddcdbe0aad8 › Root Entry › MBD00D8B77E › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.