Malicious
Malicious

Share on LinkedIn
Print
MS Word Document
MD5: a87ff06ba769975cfd4706c3761f0b9a
Size: 643.83 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a87ff06ba769975cfd4706c3761f0b9a
Sha1 e74034edfaa4b7fd6562cdbd67007988bce7e772
Sha256 62a3447e62daf4522af0db92546a50a163f5ee55c195d65a5732b1c34a2d982f
Sha384 328578557984e6e15f0fffee6a93f5a2c753f08b4e953a2795f8824d3617addbefd6861af5c439152d59a8385c4d872c
Sha512 a5cf4fec9a0a92cfad223f7d519117dada36d23ad5fe548c35338577623ea98f79930cf35da81a56fbe9c3c6c85f9621084180fd4b0b89b2cb9fa7f9cfa43b6d
SSDeep 12288:6MYjruj30EDXv1JPee8u9G/mtcShn+7dVxNR+9sVc//y5EIj3Ii:6MYjrg30QDH8u9VzhYLRCC5Eo
TLSH 36D423E62F6C44996ED421AF5AD238FAF4118E219E37CFC92142B774F539808096F787
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet3.xml
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
docProps
core.xml
app.xml
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
docProps
core.xml
app.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
CONTENTS
1.3
CONTENTS
TallyPrime
CONTENTS
D:20250913102429
CONTENTS
TallyPrime
CONTENTS
Order Voucher Display
CONTENTS
D:20250913102429
CONTENTS
TallyPrime
CONTENTS
Order Voucher Display
CONTENTS
TallyPrime
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙