Malicious
Malicious

b9ca0e1f5889369142d67dd8b127b8ae

Share on LinkedIn
Print
MS Word Document
MD5: b9ca0e1f5889369142d67dd8b127b8ae
Size: 15.92 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b9ca0e1f5889369142d67dd8b127b8ae
Sha1 38264ea76da40235bbfdc670097e16a86dd8d26c
Sha256 d7dda7ae4b6eac5a9ecebbe2ae156ddd3c2fc71dffa7ffa8db66c8f47f7a2e98
Sha384 2a722327e71f5ec721cb9ee9617cf5fe820b6205831bdc127d577ca08365f9be6e701831b279e1a17ab37fdd7560f3c4
Sha512 202a09f4affd0da951cf4423b387214975171d43788d49993215a0b66110d671967a1c329d0b4f3a250e48bb9e56b95b317f5115422ddf1d926394eceba037f9
SSDeep 384:LNflwBKK45JNkqCxoxM6kKtF8sP4wSfZQUCrLweXM4xljl:RfiBpAymW6kK4RwGsH84/R
TLSH 6562AF2A67E66D2DC31FC27C84865656F408518F8B0965DB374C4BCCA672E841722BC9
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙