Malicious
Malicious

3564c091d20d62618b4ea0e1783bb744

Share on LinkedIn
Print
MS Office Document
MD5: 3564c091d20d62618b4ea0e1783bb744
Size: 1.06 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3564c091d20d62618b4ea0e1783bb744
Sha1 b746ed7337ec708f339c643d65521f9f9a81d5f0
Sha256 76ccc559edd679c1de7f433a1441af1b0301270b37ac79ee8baae34f1322e11f
Sha384 530dc502a0d415554350e58fe5146e618bb017afecea3e4c61f59273c45e8dbf73907ad792268b3c21e6b1d0ec33acb6
Sha512 8e26bfbd60c0713f5365716ac1499bcbf5af75b0841eb728eec43149830b1fcd030f71d260da4beeb62fc371fd7e3720a03c46090e380cab6f321316a63c22e3
SSDeep 24576:6dj8nnb6YmG7U7scIKBY73rCNVkCZbN+fbwfEpGDYSvyE8:1nnjmv7FWWXkp8MpGkNE8
TLSH 2435231AFBCACE33D192113405C6D6C5452DBE85BB7D46C33691F38B5AB9AE42BA301C
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D52BB
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 411 0
#Stream obj 413 0
#Stream obj 415 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 417 0
#Stream obj 17 0
#Stream obj 16 0
#Stream obj 418 0
#Stream obj 28 0
#Stream obj 420 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 12 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 32 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 35 0
#Stream obj 36 0
#Stream obj 39 0
#Stream obj 37 0
#Stream obj 38 0
#Stream obj 2 0
#Stream obj 5 0
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 51 0
#Stream obj 29 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 42 0
#Stream obj 3 0
#Stream obj 4 0
#Stream obj 6 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 15 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD002D52BC
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 htTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Version
1.6
Author
LAB3
Author
marketing
CreationDate
D:20230518161654-05'00'
Creator
Microsoft® Word 2016
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260908155520+05'30'
ModifiedDate
D:20230914115104-05'00'
Producer
Microsoft® Word 2016
Title
Microsoft Word - Warranty_TWR
Producer
Acrobat Distiller 23.0 (Windows)
/Author
LAB3
/Creator
Microsoft® Word 2016
/CreationDate
D:20260908155520+05'30'
/ModDate
D:20260908155520+05'30'
/Producer
Microsoft® Word 2016
/Author
marketing
/CreationDate
D:20230518161654-05'00'
/Creator
PScript5.dll Version 5.2.2
/ModDate
D:20230914115104-05'00'
/Producer
Acrobat Distiller 23.0 (Windows)
/Title
Microsoft Word - Warranty_TWR
An error has occurred. This application may no longer respond until reloaded. Reload 🗙