Malicious
Malicious

16b23c782d649c6653d117df3a2a31e0

MS Office Document
MD5: 16b23c782d649c6653d117df3a2a31e0
Size: 577.02 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 16b23c782d649c6653d117df3a2a31e0
Sha1 dde18aa5b9d01fab84b0910bcbbfa568b8ce14e5
Sha256 3b408e5bd496ec69350d67ae11b7d9335692935d59ae098919fe2bf9b3ce22f5
Sha384 00fa3c86356717b80052dbf12b10c20aedbc5b8b18d80fe99b7dac79e0c5f0aaaac44a5b6d3801728915736fa63d6623
Sha512 f26c59ae20d75ab60d38faea2f30be963e5af57b82aeb8cc67f02c1b6a1137ad9e2932f166eb41c210824048ebf7acb36d88a119c7961d49ad4e41026c170b09
SSDeep 12288:5ucSzO8GkrV6pJVJZw9mLX41wMCbxfNMvMVEgFgeztpsfjW4zL1XlQHy:IcSqXAi/qkoOjbUMVEqV2LWQN
TLSH 3AC4230030CA9F6BE4AB4BB848E5A5D3140CFD5C7F44D91F32C4375DB87EA61826BA69
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD004C5363
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 22 0
#Stream obj 5 0
#Stream obj 32 0
#Stream obj 34 0
oleObject1.bin
Root Entry
Ole10Native
Text (Preview)
PDF @0x000000E0
#Stream obj 22 0
#Stream obj 13 0
#Stream obj 12 0
#Stream obj 21 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 5 0
Structure
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD004C5364
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf>pdf:stream>bin
malicious 7 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 HttP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
CreationDate
D:20260910092803-02'00
Producer
ReportBuilder
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD004C5363
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 22 0
#Stream obj 5 0
#Stream obj 32 0
#Stream obj 34 0
oleObject1.bin
Root Entry
Ole10Native
Text (Preview)
PDF @0x000000E0
#Stream obj 22 0
#Stream obj 13 0
#Stream obj 12 0
#Stream obj 21 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 5 0
Structure
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD004C5364
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 HttP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙