Malicious
60e1cce704229549db1cbc4d064e256e
MS Office Document
MD5: 60e1cce704229549db1cbc4d064e256e
Size: 672.26 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 60e1cce704229549db1cbc4d064e256e |
| Sha1 | 8cee0d2cc504e25ca2f0f3d42346382df74d5beb |
| Sha256 | 49eb1f8c8f049d2ba0e82b4907f85a3c7a0f1ea6898576aac149642352c9ad77 |
| Sha384 | 8e877516608c1d7abf9e7f8bea34ad017337cf1e85633c071eb5bad70dcf8574325ceab6e575f17b305c765d17008d0b |
| Sha512 | be9ce4c6abda7e3cf74090d4f930c770a265654f50c6f9c9914127b0b0e8cb4333040159db218b5a0a3a98a3be5ae6432bf5ba54d72886ccfaaea8573f5eab43 |
| SSDeep | 12288:gKPdv5B95S1UpXFZYeOLrdBMsrblzkyvuLcsJyTH1eEih5EpLU9aw7UmrPZ:gKRu1UpVNOL3ME54TbEp49aw77B |
| TLSH | 39E40212FA848437CA525B380BD366C1D61DAC2B5E2A8E0F5B85377E7D377E4D812C1A |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 10
STICH kept: 2secondary ignored: 8
bin
4oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape
ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #4 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.7 |
| CreationDate | D:20260731145050-04'00 |
| Creator | Mozilla Firefox 153.0.1 |
| Producer | cairo 1.18.4 (https://cairographics.org) |
| /Producer | cairo 1.18.4 (https://cairographics.org) |
| /Creator | Mozilla Firefox 153.0.1 |
| /CreationDate | D:20260731145050-04'00 |
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #4 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
60e1cce704229549db1cbc4d064e256e › Root Entry › MBD002D6E44 › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.