Malicious
Malicious

fcabb61f54ee5e848321acdac6c9039d

MS Office Document
MD5: fcabb61f54ee5e848321acdac6c9039d
Size: 13.96 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fcabb61f54ee5e848321acdac6c9039d
Sha1 68a4e27353b4ac06f4ceb3dcb663ca38e5306c59
Sha256 cc17cb6086f10aada5b199a46361996927466128be504943c9fbe2752fe2d558
Sha384 a8c173be2795e8399d14f6d0657a9bc8c274bf903952e27c1d0db71d16c19224892fae836f65632c2518c606148852b6
Sha512 0b8d5f4e312d172a9cda3664994995c30994c992d414f57ecd30afeaba1c34b5151b165b5900438a39b97f2db4cbcf6d86d9d5f4ca61ab622bcd3e028dc84c95
SSDeep 393216:UCT0sLaxGZQ90ajj8ZqQrdgNTMMVKwlGlAX:bjmtjj8Z7rdn6X
TLSH 75E633507094CE37D46312738C68E6B9AD2E3D604EB6A6FFE7985B0F5E1C0E05362C69
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
lib
native
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ookii.Dialogs.Wpf.ProgressDialog.resources
Ookii.Dialogs.Wpf.Properties.Resources.resources
Ookii.Dialogs.XPThemes.manifest
Ookii.Dialogs.Wpf.CredentialDialog.bmp
Ookii.Dialogs.Wpf.ProgressDialog.bmp
Ookii.Dialogs.Wpf.TaskDialog.bmp
Ookii.Dialogs.Wpf.VistaFolderBrowserDialog.bmp
Ookii.Dialogs.Wpf.VistaOpenFileDialog.bmp
Ookii.Dialogs.Wpf.VistaSaveFileDialog.bmp
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Overlay_05970a00.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.CLR_UEF
.rdata
.data
_RDATA
.rsrc
.reloc
Resources
RT_RCDATA
ID:0000
[Authenticode]_ac3573f5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
TacticalLauncher.deps.json
.Net Resources
TacticalLauncher.g.resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
TacticalLauncher.dll.config
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
TacticalLauncher.runtimeconfig.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
package
services
metadata
core-properties
6310c3fabf874260bfc548c12d7a1a1d.psmdcp
setup.ico
splashimage.gif
splashimage.gif-preview.png
TacticalLauncher.nuspec
[Content_Types].xml
_rels
.rels
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Repaired @0x00068CCF]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 14 STICH kept: 3secondary ignored: 11
bin 8img 2xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>ole:doc
Shape pe:exe>ole:doc
malicious 2 nodes
Path pe:exe>oox:doc>pe:dll>arc:7zsfx
Shape pe:exe>oox:doc>pe:dll>arc:7zsfx
4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_ffec790a.bin (13528944 bytes)
Info
PDB Path: C:\Source\New folder\Clowd.Squirrel\build\Release\Win32\Setup.pdb
lib
native
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ookii.Dialogs.Wpf.ProgressDialog.resources
Ookii.Dialogs.Wpf.Properties.Resources.resources
Ookii.Dialogs.XPThemes.manifest
Ookii.Dialogs.Wpf.CredentialDialog.bmp
Ookii.Dialogs.Wpf.ProgressDialog.bmp
Ookii.Dialogs.Wpf.TaskDialog.bmp
Ookii.Dialogs.Wpf.VistaFolderBrowserDialog.bmp
Ookii.Dialogs.Wpf.VistaOpenFileDialog.bmp
Ookii.Dialogs.Wpf.VistaSaveFileDialog.bmp
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
Overlay_05970a00.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.CLR_UEF
.rdata
.data
_RDATA
.rsrc
.reloc
Resources
RT_RCDATA
ID:0000
[Authenticode]_ac3573f5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
TacticalLauncher.deps.json
.Net Resources
TacticalLauncher.g.resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
TacticalLauncher.dll.config
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
TacticalLauncher.runtimeconfig.json
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
package
services
metadata
core-properties
6310c3fabf874260bfc548c12d7a1a1d.psmdcp
setup.ico
splashimage.gif
splashimage.gif-preview.png
TacticalLauncher.nuspec
[Content_Types].xml
_rels
.rels
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[Repaired @0x00068CCF]
Malicious
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙