Malicious
Malicious

f01cae8ecedbd43ca5c3eaeccc78f8ae

Share on LinkedIn
Print
MS Word Document
MD5: f01cae8ecedbd43ca5c3eaeccc78f8ae
Size: 15.91 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f01cae8ecedbd43ca5c3eaeccc78f8ae
Sha1 7d7f975a223c08caf5c1992228788e09fae20a09
Sha256 83a7fb922c389a70ad36bfbe6cb08506914f54fa8bd92baced4c6d1fda6e0427
Sha384 499073008f7fac0716087e0123c574cc5ca8a4581dd3ff0ec70e0c6c4be01844bd1d908c656eab18b0a720c03b687230
Sha512 a71116d34e9647c1ae0a54005200bba035cb08315767cf5b7546daced229e2945ad9583fff5f7309bcdbea8add9e3aef7c6675d86706f5f0ac29cb3e600a2f29
SSDeep 192:5NhlwYx5NFzFJNmG23xIHLMk44WWOvr/PA5zPB7AGeRajLMO8pWNdwCqM+2KKryu:5Nhlw+jJNmhmHyn7QB7UYARgdwChB1rJ
TLSH F162B02EE5A56C1DCB0331F950442311FA8AD4CA9E2BD1C92E189EDCC391DA4477BECB
[Content_Types].xml
_rels
.rels
docProps
app.xml
core.xml
custom.xml
word
Malicious
document.xml
_rels
Malicious
document.xml.rels
webSettings.xml
settings.xml
styles.xml
theme
theme111.xml
fontTable.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:docx>oox:rel:ext~T1221
Shape oox:docx>oox:rel:ext
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path settihuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙