Malicious
Malicious

b9ca0e1f5889369142d67dd8b127b8ae

MS Word Document
MD5: b9ca0e1f5889369142d67dd8b127b8ae
Size: 15.92 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b9ca0e1f5889369142d67dd8b127b8ae
Sha1 38264ea76da40235bbfdc670097e16a86dd8d26c
Sha256 d7dda7ae4b6eac5a9ecebbe2ae156ddd3c2fc71dffa7ffa8db66c8f47f7a2e98
Sha384 2a722327e71f5ec721cb9ee9617cf5fe820b6205831bdc127d577ca08365f9be6e701831b279e1a17ab37fdd7560f3c4
Sha512 202a09f4affd0da951cf4423b387214975171d43788d49993215a0b66110d671967a1c329d0b4f3a250e48bb9e56b95b317f5115422ddf1d926394eceba037f9
SSDeep 384:LNflwBKK45JNkqCxoxM6kKtF8sP4wSfZQUCrLweXM4xljl:RfiBpAymW6kK4RwGsH84/R
TLSH 6562AF2A67E66D2DC31FC27C84865656F408518F8B0965DB374C4BCCA672E841722BC9
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
b9ca0e1f5889369142d67dd8b127b8ae › word › _rels › settings.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙