Malicious
Malicious

MS Word Document
MD5: a87ff06ba769975cfd4706c3761f0b9a
Size: 643.83 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a87ff06ba769975cfd4706c3761f0b9a
Sha1 e74034edfaa4b7fd6562cdbd67007988bce7e772
Sha256 62a3447e62daf4522af0db92546a50a163f5ee55c195d65a5732b1c34a2d982f
Sha384 328578557984e6e15f0fffee6a93f5a2c753f08b4e953a2795f8824d3617addbefd6861af5c439152d59a8385c4d872c
Sha512 a5cf4fec9a0a92cfad223f7d519117dada36d23ad5fe548c35338577623ea98f79930cf35da81a56fbe9c3c6c85f9621084180fd4b0b89b2cb9fa7f9cfa43b6d
SSDeep 12288:6MYjruj30EDXv1JPee8u9G/mtcShn+7dVxNR+9sVc//y5EIj3Ii:6MYjrg30QDH8u9VzhYLRCC5Eo
TLSH 36D423E62F6C44996ED421AF5AD238FAF4118E219E37CFC92142B774F539808096F787
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet3.xml
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
docProps
core.xml
app.xml
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
docProps
core.xml
app.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
CONTENTS
1.3
CONTENTS
TallyPrime
CONTENTS
D:20250913102429
CONTENTS
TallyPrime
CONTENTS
Order Voucher Display
CONTENTS
D:20250913102429
CONTENTS
TallyPrime
CONTENTS
Order Voucher Display
CONTENTS
TallyPrime
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet3.xml
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
docProps
core.xml
app.xml
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
docProps
core.xml
app.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
a87ff06ba769975cfd4706c3761f0b9a › word › _rels › settings.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙