1.doc

First submission 2024-10-17 03:49:02 Last sumbission 2024-10-17 05:39:01

File details

File type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: HP Inc., Template: Normal.dotm, Last Saved By: user, Revision Number: 5, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Create Time/Date: Wed Sep 18 22:21:00 2024, Last Saved Time/Date: Wed Sep 18 22:23:00 2024, Number of Pages: 1, Number of Words: 0, Number of Characters: 3, Security: 0
Mime type: application/msword
File size: 67.53 KB (69151 bytes)
MD5: b066bbea5d6502655a1880d7987ae7c7
SHA1: 4b97e1115fca394fcbc5e512e8acccc109699100
SHA256: b2e9ef81af6c4686944e5c589d420fc9dffbf9af7afe3e1e913cece273626070

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 4

URL Host (FQDN/IP) Date Added
hXXp://googletranslate.zapto.org/1.doc VirusTotal Report googletranslate.zapto.org VirusTotal Report 2024-10-17 05:39:03
hXXp://162-19-214-220.eyeohost.net/1.doc VirusTotal Report 162-19-214-220.eyeohost.net VirusTotal Report 2024-10-17 04:19:03
hXXp://162.19.214.220.sslip.io/1.doc VirusTotal Report 162.19.214.220.sslip.io VirusTotal Report 2024-10-17 04:14:04
hXXp://162.19.214.220/1.doc VirusTotal Report 162.19.214.220 VirusTotal Report 2024-10-17 03:49:02

Strings analysis - File found

XML
drs/shapexml.xml
theme/theme/theme1.xml
drs/e2oDoc.xml
[Content_Types].xml
Text
\services.txt
data\boot.txt
ices.txt

Strings analysis - Possible URLs found 1

http://schemas.openxmlformats.org/drawingml/2006/main