Malicious
Malicious

3564c091d20d62618b4ea0e1783bb744

MS Office Document
MD5: 3564c091d20d62618b4ea0e1783bb744
Size: 1.06 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3564c091d20d62618b4ea0e1783bb744
Sha1 b746ed7337ec708f339c643d65521f9f9a81d5f0
Sha256 76ccc559edd679c1de7f433a1441af1b0301270b37ac79ee8baae34f1322e11f
Sha384 530dc502a0d415554350e58fe5146e618bb017afecea3e4c61f59273c45e8dbf73907ad792268b3c21e6b1d0ec33acb6
Sha512 8e26bfbd60c0713f5365716ac1499bcbf5af75b0841eb728eec43149830b1fcd030f71d260da4beeb62fc371fd7e3720a03c46090e380cab6f321316a63c22e3
SSDeep 24576:6dj8nnb6YmG7U7scIKBY73rCNVkCZbN+fbwfEpGDYSvyE8:1nnjmv7FWWXkp8MpGkNE8
TLSH 2435231AFBCACE33D192113405C6D6C5452DBE85BB7D46C33691F38B5AB9AE42BA301C
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D52BB
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD002D52BC
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Version
1.6
Author
LAB3
Author
marketing
CreationDate
D:20230518161654-05'00'
Creator
Microsoft® Word 2016
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260908155520+05'30'
ModifiedDate
D:20230914115104-05'00'
Producer
Microsoft® Word 2016
Title
Microsoft Word - Warranty_TWR
Producer
Acrobat Distiller 23.0 (Windows)
/Author
LAB3
/Creator
Microsoft® Word 2016
/CreationDate
D:20260908155520+05'30'
/ModDate
D:20260908155520+05'30'
/Producer
Microsoft® Word 2016
/Author
marketing
/CreationDate
D:20230518161654-05'00'
/Creator
PScript5.dll Version 5.2.2
/ModDate
D:20230914115104-05'00'
/Producer
Acrobat Distiller 23.0 (Windows)
/Title
Microsoft Word - Warranty_TWR
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D52BB
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD002D52BC
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙