# Page Not Found

The URL `files/dLtgQbmJfU7aEWzkjedG` does not exist. This page may have been moved, renamed, or deleted.

## Suggested Pages

You may be looking for one of the following:
- [From IRS Files to XWorm: Dissecting a Multi‑Stage LNK‑Based Malware Chain](https://xto9ot.gitbook.io/malware-analysis/from-irs-files-to-xworm-dissecting-a-multi-stage-lnk-based-malware-chain.md)
- [Technical Analysis of a Multi‑Stage Batch Loader Delivering QuasarRAT](https://xto9ot.gitbook.io/malware-analysis/technical-analysis-of-a-multi-stage-batch-loader-delivering-quasarrat.md)
- [Analysis Archive](https://xto9ot.gitbook.io/malware-analysis/analysis-archive.md)
- [Investigation of Turkish-Sourced EagleRAT and AsyncRAT Malware Activity](https://xto9ot.gitbook.io/malware-analysis/investigation-of-turkish-sourced-eaglerat-and-asyncrat-malware-activity.md)
- [SilverFox APT Campaign Targeting Chinese-Speaking Users via Trojanized WPS Office Installer](https://xto9ot.gitbook.io/malware-analysis/silverfox-apt-campaign-targeting-chinese-speaking-users-via-trojanized-wps-office-installer.md)

## How to find the correct page

If the exact page cannot be found, you can still retrieve the information using the documentation query interface.

### Option 1 — Ask a question (recommended)

Perform an HTTP GET request on the documentation index with the `ask` parameter:

```
GET https://xto9ot.gitbook.io/malware-analysis/from-irs-files-to-xworm-dissecting-a-multi-stage-lnk-based-malware-chain.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

### Option 2 — Browse the documentation index

Full index: https://xto9ot.gitbook.io/malware-analysis/sitemap.md

Use this to discover valid page paths or navigate the documentation structure.

### Option 3 — Retrieve the full documentation corpus

Full export: https://xto9ot.gitbook.io/malware-analysis/llms-full.txt

Use this to access all content at once and perform your own parsing or retrieval. It will be more expensive.

## Tips for requesting documentation

Prefer `.md` URLs for structured content, append `.md` to URLs (e.g., `/malware-analysis/from-irs-files-to-xworm-dissecting-a-multi-stage-lnk-based-malware-chain.md`).

You may also use `Accept: text/markdown` header for content negotiation.
