Malicious
MS Word Document
MD5: a87ff06ba769975cfd4706c3761f0b9a
Size: 643.83 KB
application/msword
General
Structural Analysis
Config.1
Yara Rules11
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | a87ff06ba769975cfd4706c3761f0b9a
|
| Sha1 | e74034edfaa4b7fd6562cdbd67007988bce7e772
|
| Sha256 | 62a3447e62daf4522af0db92546a50a163f5ee55c195d65a5732b1c34a2d982f
|
| Sha384 | 328578557984e6e15f0fffee6a93f5a2c753f08b4e953a2795f8824d3617addbefd6861af5c439152d59a8385c4d872c
|
| Sha512 | a5cf4fec9a0a92cfad223f7d519117dada36d23ad5fe548c35338577623ea98f79930cf35da81a56fbe9c3c6c85f9621084180fd4b0b89b2cb9fa7f9cfa43b6d
|
| SSDeep | 12288:6MYjruj30EDXv1JPee8u9G/mtcShn+7dVxNR+9sVc//y5EIj3Ii:6MYjrg30QDH8u9VzhYLRCC5Eo
|
| TLSH | 36D423E62F6C44996ED421AF5AD238FAF4118E219E37CFC92142B774F539808096F787
|
File Structure
a87ff06ba769975cfd4706c3761f0b9a
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
Page #1
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu
|
| Path | settihuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Informations
|
Name | Value |
|---|---|
| CONTENTS | 1.3 |
| CONTENTS | TallyPrime |
| CONTENTS | D:20250913102429 |
| CONTENTS | TallyPrime |
| CONTENTS | Order Voucher Display |
| CONTENTS | D:20250913102429 |
| CONTENTS | TallyPrime |
| CONTENTS | Order Voucher Display |
| CONTENTS | TallyPrime |
Artefacts
|
Name | Value |
|---|---|
| Remote Template - Highly Suspicious | https:huhuhuhuhuhuhuhuhuhuhu
|
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
a87ff06ba769975cfd4706c3761f0b9a (643.83 KB)
File Structure
a87ff06ba769975cfd4706c3761f0b9a
Malicious
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
Page #1
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
Characteristics
Malware Configuration - Remote Template
|
Config. Field0 | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu
|
| Path | settihuhuhuhuhuhuhu
|
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu
|
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu
|
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Artefacts
|
Name | Value | Location |
|---|---|---|
| Remote Template - Highly Suspicious | https:huhuhuhuhuhuhuhuhuhuhu
Malicious |
a87ff06ba769975cfd4706c3761f0b9a > word > _rels > settings.xml.rels |
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.