Malicious
Malicious

Share on LinkedIn
Print
MS Word Document
MD5: a87ff06ba769975cfd4706c3761f0b9a
Size: 643.83 KB
application/msword
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
a87ff06ba769975cfd4706c3761f0b9a
Sha1
e74034edfaa4b7fd6562cdbd67007988bce7e772
Sha256
62a3447e62daf4522af0db92546a50a163f5ee55c195d65a5732b1c34a2d982f
Sha384
328578557984e6e15f0fffee6a93f5a2c753f08b4e953a2795f8824d3617addbefd6861af5c439152d59a8385c4d872c
Sha512
a5cf4fec9a0a92cfad223f7d519117dada36d23ad5fe548c35338577623ea98f79930cf35da81a56fbe9c3c6c85f9621084180fd4b0b89b2cb9fa7f9cfa43b6d
SSDeep
12288:6MYjruj30EDXv1JPee8u9G/mtcShn+7dVxNR+9sVc//y5EIj3Ii:6MYjrg30QDH8u9VzhYLRCC5Eo
TLSH
36D423E62F6C44996ED421AF5AD238FAF4118E219E37CFC92142B774F539808096F787
File Structure
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
document.xml
media
image1.emf
embeddings
Microsoft_Office_Excel_Worksheet1.xlsx
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet3.xml
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream {17}
#Stream {18}
#Stream {6}
#Stream {8}
#Stream {10}
Structure
styles.xml
theme
theme1.xml
sharedStrings.xml
printerSettings
printerSettings4.bin
printerSettings3.bin
docProps
core.xml
app.xml
theme
theme1.xml
settings.xml
webSettings.xml
styles.xml
fontTable.xml
docProps
core.xml
app.xml
Malware Configuration - Remote Template
Config. Field
Value
Target
https:huhuhuhuhuhuhuhuhuhuhu
Path
settihuhuhuhuhuhuhu
XPath
/Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML
<Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Informations
Name
Value
CONTENTS

1.3

CONTENTS

TallyPrime

CONTENTS

D:20250913102429

CONTENTS

TallyPrime

CONTENTS

Order Voucher Display

CONTENTS

D:20250913102429

CONTENTS

TallyPrime

CONTENTS

Order Voucher Display

CONTENTS

TallyPrime

Artefacts
Name
Value
Remote Template - Highly Suspicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
a87ff06ba769975cfd4706c3761f0b9a (643.83 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙