Malicious
Malicious

16b23c782d649c6653d117df3a2a31e0

Share on LinkedIn
Print
MS Office Document
MD5: 16b23c782d649c6653d117df3a2a31e0
Size: 577.02 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 16b23c782d649c6653d117df3a2a31e0
Sha1 dde18aa5b9d01fab84b0910bcbbfa568b8ce14e5
Sha256 3b408e5bd496ec69350d67ae11b7d9335692935d59ae098919fe2bf9b3ce22f5
Sha384 00fa3c86356717b80052dbf12b10c20aedbc5b8b18d80fe99b7dac79e0c5f0aaaac44a5b6d3801728915736fa63d6623
Sha512 f26c59ae20d75ab60d38faea2f30be963e5af57b82aeb8cc67f02c1b6a1137ad9e2932f166eb41c210824048ebf7acb36d88a119c7961d49ad4e41026c170b09
SSDeep 12288:5ucSzO8GkrV6pJVJZw9mLX41wMCbxfNMvMVEgFgeztpsfjW4zL1XlQHy:IcSqXAi/qkoOjbUMVEqV2LWQN
TLSH 3AC4230030CA9F6BE4AB4BB848E5A5D3140CFD5C7F44D91F32C4375DB87EA61826BA69
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD004C5363
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 22 0
#Stream obj 5 0
#Stream obj 32 0
#Stream obj 34 0
oleObject1.bin
Root Entry
Ole10Native
Text (Preview)
PDF @0x000000E0
#Stream obj 22 0
#Stream obj 13 0
#Stream obj 12 0
#Stream obj 21 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 5 0
Structure
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD004C5364
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf>pdf:stream>bin
malicious 7 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 HttP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
CreationDate
D:20260910092803-02'00
Producer
ReportBuilder
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
An error has occurred. This application may no longer respond until reloaded. Reload 🗙