Malicious
Malicious

f01cae8ecedbd43ca5c3eaeccc78f8ae

MS Word Document
MD5: f01cae8ecedbd43ca5c3eaeccc78f8ae
Size: 15.91 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f01cae8ecedbd43ca5c3eaeccc78f8ae
Sha1 7d7f975a223c08caf5c1992228788e09fae20a09
Sha256 83a7fb922c389a70ad36bfbe6cb08506914f54fa8bd92baced4c6d1fda6e0427
Sha384 499073008f7fac0716087e0123c574cc5ca8a4581dd3ff0ec70e0c6c4be01844bd1d908c656eab18b0a720c03b687230
Sha512 a71116d34e9647c1ae0a54005200bba035cb08315767cf5b7546daced229e2945ad9583fff5f7309bcdbea8add9e3aef7c6675d86706f5f0ac29cb3e600a2f29
SSDeep 192:5NhlwYx5NFzFJNmG23xIHLMk44WWOvr/PA5zPB7AGeRajLMO8pWNdwCqM+2KKryu:5Nhlw+jJNmhmHyn7QB7UYARgdwChB1rJ
TLSH F162B02EE5A56C1DCB0331F950442311FA8AD4CA9E2BD1C92E189EDCC391DA4477BECB
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
f01cae8ecedbd43ca5c3eaeccc78f8ae › word › _rels › settings.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙