Suspicious
Suspect

39fb359fff1d4ea12cfbc8000e715bfb

MS Office Document
MD5: 39fb359fff1d4ea12cfbc8000e715bfb
Size: 1.07 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 39fb359fff1d4ea12cfbc8000e715bfb
Sha1 94596089c9193846567cc2271c0451243f53c526
Sha256 0043a61af8d9b9045e2c420c91c7a452f591420bbf4d28ec2c3a66c67bdb3a50
Sha384 19d865f11ea25c43aa6df85b845ce6243593d2b2a17c8b03191c7a8d1972fadd325677b6dcb287f257bc3a419acbc202
Sha512 9fd543815e89361939937513801e02202bafe734e1eaab6dc67e4211c85ef63e480a0a179774e5c6f55777defb39238e544adac318db3be7882acb0aab4a42ca
SSDeep 24576:/pzOZ5ezyKvUtzBSRG8XH86wMhhx9jwL4HyTZahDAKY99k:hzo5ez6GzoMhh/wL7MDFYL
TLSH AA352326BEA4EF87D07A427B0CE5C09443A87CA17F05A91B2796FB6C30B067171E654E
39fb359fff1d4ea12cfbc8000e715bfb
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00EE0754
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 87 0
#Stream obj 88 0
#Stream obj 89 0
#Stream obj 90 0
#Stream obj 91 0
#Stream obj 92 0
#Stream obj 93 0
#Stream obj 94 0
#Stream obj 72 0
#Stream obj 84 0
#Stream obj 71 0
#Stream obj 83 0
#Stream obj 82 0
#Stream obj 80 0
#Stream obj 77 0
#Stream obj 78 0
#Stream obj 76 0
#Stream obj 74 0
#Stream obj 101 0
#Stream obj 100 0
#Stream obj 73 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 31 0
#Stream obj 29 0
#Stream obj 53 0
#Stream obj 26 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 49 0
#Stream obj 47 0
#Stream obj 45 0
#Stream obj 44 0
#Stream obj 43 0
#Stream obj 41 0
#Stream obj 61 0
#Stream obj 62 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 66 0
#Stream obj 10 0
#Stream obj 2 0
#Stream obj 3 0
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 11 0
#Stream obj 67 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 42 0
#Stream obj 56 0
Structure
sharedStrings.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00EE0755
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL #2 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20130508153712+02'00'
Creator
Adobe InDesign CS6 (Macintosh)
ModifiedDate
D:20221229185615+05'30'
Producer
Adobe PDF Library 10.0.1
/CreationDate
D:20130508153712+02'00'
/Creator
Adobe InDesign CS6 (Macintosh)
/ModDate
D:20221229185615+05'30'
/Producer
Adobe PDF Library 10.0.1
39fb359fff1d4ea12cfbc8000e715bfb
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00EE0754
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 87 0
#Stream obj 88 0
#Stream obj 89 0
#Stream obj 90 0
#Stream obj 91 0
#Stream obj 92 0
#Stream obj 93 0
#Stream obj 94 0
#Stream obj 72 0
#Stream obj 84 0
#Stream obj 71 0
#Stream obj 83 0
#Stream obj 82 0
#Stream obj 80 0
#Stream obj 77 0
#Stream obj 78 0
#Stream obj 76 0
#Stream obj 74 0
#Stream obj 101 0
#Stream obj 100 0
#Stream obj 73 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 31 0
#Stream obj 29 0
#Stream obj 53 0
#Stream obj 26 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 49 0
#Stream obj 47 0
#Stream obj 45 0
#Stream obj 44 0
#Stream obj 43 0
#Stream obj 41 0
#Stream obj 61 0
#Stream obj 62 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 66 0
#Stream obj 10 0
#Stream obj 2 0
#Stream obj 3 0
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 11 0
#Stream obj 67 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 42 0
#Stream obj 56 0
Structure
sharedStrings.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00EE0755
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL #2 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙