Malicious
Malicious

2f1c96eba3a856288c370ddcdbe0aad8

MS Office Document
MD5: 2f1c96eba3a856288c370ddcdbe0aad8
Size: 798.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2f1c96eba3a856288c370ddcdbe0aad8
Sha1 14429db6efc656d2fef5b541aa06d31353bd2a59
Sha256 88ce5e04d4fb0174d659e2d945f9077718ad643bbf32bffee16b2236364a4df4
Sha384 499b9b4fc11fedf434b6e455b9d4ac7052cccd033b9755f4a008fe0db1f512b8163259d152abd2f80e7a5685a8c549fb
Sha512 30aa64cea51ac45768ddaa793a4694fe78096a5799ed2f59352eda7f6068070e7002392652119edb3c62a3f1cd745e101cdf930feb0d3a8b07e91cd0461f8afc
SSDeep 24576:RrizeJ86MZMC4I1rOmCXh9Ugfwv673RlT:RriqJ8LQYCvUg4v6tl
TLSH 7C052300FECADE1BC847C5388BD99DDBA999BD341F03D9873352B39E157952021E3A26
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00D8B77E
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
Text (Preview)
#Stream obj 1 0
#Stream obj 1 0-preview.png
#Stream obj 2 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00D8B77F
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 2secondary ignored: 9
bin 4img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260802163606-08'00'
Creator
HP Scan
ModifiedDate
D:20260802163606-08'00'
Producer
HP Scan Extended Application
/Creator
HP Scan
/CreationDate
D:20260802163606-08'00'
/ModDate
D:20260802163606-08'00'
/Producer
HP Scan Extended Application
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00D8B77E
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
Text (Preview)
#Stream obj 1 0
#Stream obj 1 0-preview.png
#Stream obj 2 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00D8B77F
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
2f1c96eba3a856288c370ddcdbe0aad8 › Root Entry › MBD00D8B77E › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙