Malicious
Malicious

2f1c96eba3a856288c370ddcdbe0aad8

Share on LinkedIn
Print
MS Office Document
MD5: 2f1c96eba3a856288c370ddcdbe0aad8
Size: 798.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2f1c96eba3a856288c370ddcdbe0aad8
Sha1 14429db6efc656d2fef5b541aa06d31353bd2a59
Sha256 88ce5e04d4fb0174d659e2d945f9077718ad643bbf32bffee16b2236364a4df4
Sha384 499b9b4fc11fedf434b6e455b9d4ac7052cccd033b9755f4a008fe0db1f512b8163259d152abd2f80e7a5685a8c549fb
Sha512 30aa64cea51ac45768ddaa793a4694fe78096a5799ed2f59352eda7f6068070e7002392652119edb3c62a3f1cd745e101cdf930feb0d3a8b07e91cd0461f8afc
SSDeep 24576:RrizeJ86MZMC4I1rOmCXh9Ugfwv673RlT:RriqJ8LQYCvUg4v6tl
TLSH 7C052300FECADE1BC847C5388BD99DDBA999BD341F03D9873352B39E157952021E3A26
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00D8B77E
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
Text (Preview)
#Stream obj 1 0
#Stream obj 1 0-preview.png
#Stream obj 2 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00D8B77F
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 2secondary ignored: 9
bin 4img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260802163606-08'00'
Creator
HP Scan
ModifiedDate
D:20260802163606-08'00'
Producer
HP Scan Extended Application
/Creator
HP Scan
/CreationDate
D:20260802163606-08'00'
/ModDate
D:20260802163606-08'00'
/Producer
HP Scan Extended Application
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙