Malicious
MS Word Document
MD5: b9ca0e1f5889369142d67dd8b127b8ae
Size: 15.92 KB
application/msword
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | b9ca0e1f5889369142d67dd8b127b8ae |
| Sha1 | 38264ea76da40235bbfdc670097e16a86dd8d26c |
| Sha256 | d7dda7ae4b6eac5a9ecebbe2ae156ddd3c2fc71dffa7ffa8db66c8f47f7a2e98 |
| Sha384 | 2a722327e71f5ec721cb9ee9617cf5fe820b6205831bdc127d577ca08365f9be6e701831b279e1a17ab37fdd7560f3c4 |
| Sha512 | 202a09f4affd0da951cf4423b387214975171d43788d49993215a0b66110d671967a1c329d0b4f3a250e48bb9e56b95b317f5115422ddf1d926394eceba037f9 |
| SSDeep | 384:LNflwBKK45JNkqCxoxM6kKtF8sP4wSfZQUCrLweXM4xljl:RfiBpAymW6kK4RwGsH84/R |
| TLSH | 6562AF2A67E66D2DC31FC27C84865656F408518F8B0965DB374C4BCCA672E841722BC9 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 5
STICH kept: 1secondary ignored: 4
oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
oox:docx>oox:rel:ext~T1221
Shape
oox:docx>oox:rel:ext
technique2 nodes
| Config. Field | Value |
|---|---|
| Target | https:huhuhuhuhuhuhuhuhuhuhu |
| Path | settihuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential