Suspicious
Suspect

21edc8839da40e71e2003013db5ceef6

Share on LinkedIn
Print
MS Office Document
MD5: 21edc8839da40e71e2003013db5ceef6
Size: 814.08 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 21edc8839da40e71e2003013db5ceef6
Sha1 4e9e132fe20804d89d300087fa565a7b3302557a
Sha256 e71e1bcc0bd45ce8fa03241971c1847b1b19b223b20b167e11f35df520e1d403
Sha384 3561bdd66de0758c3233d894402341133ccc0f801f8756d928e049051a9be5a3a1c855800dc4de541a8a9b83b73ceeb8
Sha512 0c2cd3ae5954d85fe192603046aec71e6f77b95aede81243518537c181cb8b719074746c978709007cadfedf29b4b6ead00433842325a519fcc91a1b453cf9e4
SSDeep 12288:DxgRAPXRC5Ih55TEYU+79QG0tGT3N0WDsE/o4iNJoQ3xurptkvBoVMyqCCt4gKV:1gRA/EyAludP4EgNNJTAp4BoVfX/g
TLSH B0052309F9D5BE57D263A2B09CD5838C5118FC432E0BEA2B6DA1335D543A0BCB6C752B
21edc8839da40e71e2003013db5ceef6
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00405712
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet2.xml.rels
sheet1.xml.rels
sheet3.xml.rels
sheet5.xml.rels
sheet4.xml.rels
sheet2.xml
sheet3.xml
sheet5.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
vmlDrawing2.vml.rels
drawing4.xml
drawing1.xml
drawing2.xml
vmlDrawing1.vml
vmlDrawing2.vml
drawing3.xml
media
image4.emf
image3.emf
image1.png
image1.png-preview.png
image2.emf
embeddings
oleObject3.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 21 0
#Stream obj 24 0
#Stream obj 27 0
#Stream obj 29 0
#Stream obj 28 0
#Stream obj 37 0
#Stream obj 51 0
#Stream obj 65 0
#Stream obj 79 0
#Stream obj 93 0
#Stream obj 107 0
#Stream obj 121 0
#Stream obj 135 0
#Stream obj 150 0
#Stream obj 164 0
oleObject1.bin
Root Entry
CompObj
CONTENTS
oleObject2.bin
Root Entry
CONTENTS
#Stream obj 6 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 26 0
#Stream obj 26 0-preview.png
#Stream obj 40 0
#Stream obj 27 0
#Stream obj 41 0
#Stream obj 28 0
#Stream obj 42 0
#Stream obj 29 0
#Stream obj 44 0
#Stream obj 31 0
#Stream obj 45 0
#Stream obj 32 0
#Stream obj 47 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 20 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 37 0
#Stream obj 37 0-preview.png
#Stream obj 38 0
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings1.bin
printerSettings2.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00405713
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.4
Author
City of Johannesburg
CreationDate
D:20260622150000+02'00'
Subject
Account Number : 556736545
Title
Tax Invoice
Version
1.7
Author
Absa Retail
CreationDate
D:20260622120032Z
Creator
DocFusion
ModifiedDate
D:20260622120032Z
Producer
DocFusion
/Creator
DocFusion
/ModDate
D:20260622120032Z
/CreationDate
D:20260622120032Z
/Producer
DocFusion
/Author
Absa Retail
URI URI
mailtohuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙