Malicious
Malicious

9eed3f533794df731877f42a9381424a

Share on LinkedIn
Print
MS Word Document
MD5: 9eed3f533794df731877f42a9381424a
Size: 15.91 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9eed3f533794df731877f42a9381424a
Sha1 019f9cc2f6b2298a50490d5824350d9df65c6713
Sha256 004c6032084c0660cdcce4e0d1a24a00a00ee000e03df69a27ee844ab1ba6e22
Sha384 31558e03a80cc9c467957358867bef938f983260d62c9402b2dc1f208a90884faf557c818b7888ea81f5fe00805996f8
Sha512 644ed6a2047a767106567d648869441e014f867e869970e673cabc76a12a9172bf1f7c988b7c209faf2d50db4030babe4917b74c51edce6d52dcbf7bf8ee0ddd
SSDeep 384:INOlwt8f1wsyoWJjyA6KgzKc20RBkhviIhmgKI/5dBb5vUAHw0:yOiefGLGAPgn2eyhviSKI/rBNvUAH5
TLSH CD62AF3AB9E5E82AC11338FD20114657F06B549AEF759C935B0A9ADD45B09CC0323ACF
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙