Malicious
Malicious

9eed3f533794df731877f42a9381424a

MS Word Document
MD5: 9eed3f533794df731877f42a9381424a
Size: 15.91 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9eed3f533794df731877f42a9381424a
Sha1 019f9cc2f6b2298a50490d5824350d9df65c6713
Sha256 004c6032084c0660cdcce4e0d1a24a00a00ee000e03df69a27ee844ab1ba6e22
Sha384 31558e03a80cc9c467957358867bef938f983260d62c9402b2dc1f208a90884faf557c818b7888ea81f5fe00805996f8
Sha512 644ed6a2047a767106567d648869441e014f867e869970e673cabc76a12a9172bf1f7c988b7c209faf2d50db4030babe4917b74c51edce6d52dcbf7bf8ee0ddd
SSDeep 384:INOlwt8f1wsyoWJjyA6KgzKc20RBkhviIhmgKI/5dBb5vUAHw0:yOiefGLGAPgn2eyhviSKI/rBNvUAH5
TLSH CD62AF3AB9E5E82AC11338FD20114657F06B549AEF759C935B0A9ADD45B09CC0323ACF
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
9eed3f533794df731877f42a9381424a › word › _rels › settings.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙