Malicious
9eed3f533794df731877f42a9381424a
MS Word Document
MD5: 9eed3f533794df731877f42a9381424a
Size: 15.91 KB
application/msword
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 9eed3f533794df731877f42a9381424a |
| Sha1 | 019f9cc2f6b2298a50490d5824350d9df65c6713 |
| Sha256 | 004c6032084c0660cdcce4e0d1a24a00a00ee000e03df69a27ee844ab1ba6e22 |
| Sha384 | 31558e03a80cc9c467957358867bef938f983260d62c9402b2dc1f208a90884faf557c818b7888ea81f5fe00805996f8 |
| Sha512 | 644ed6a2047a767106567d648869441e014f867e869970e673cabc76a12a9172bf1f7c988b7c209faf2d50db4030babe4917b74c51edce6d52dcbf7bf8ee0ddd |
| SSDeep | 384:INOlwt8f1wsyoWJjyA6KgzKc20RBkhviIhmgKI/5dBb5vUAHw0:yOiefGLGAPgn2eyhviSKI/rBNvUAH5 |
| TLSH | CD62AF3AB9E5E82AC11338FD20114657F06B549AEF759C935B0A9ADD45B09CC0323ACF |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 5
STICH kept: 1secondary ignored: 4
oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
oox:docx>oox:rel:ext~T1221
Shape
oox:docx>oox:rel:ext
technique2 nodes
| Config. Field | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu |
| Path | settihuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu |
| Path | settihuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
9eed3f533794df731877f42a9381424a › word › _rels › settings.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.