Suspicious
Suspect

39fb359fff1d4ea12cfbc8000e715bfb

Share on LinkedIn
Print
MS Office Document
MD5: 39fb359fff1d4ea12cfbc8000e715bfb
Size: 1.07 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 39fb359fff1d4ea12cfbc8000e715bfb
Sha1 94596089c9193846567cc2271c0451243f53c526
Sha256 0043a61af8d9b9045e2c420c91c7a452f591420bbf4d28ec2c3a66c67bdb3a50
Sha384 19d865f11ea25c43aa6df85b845ce6243593d2b2a17c8b03191c7a8d1972fadd325677b6dcb287f257bc3a419acbc202
Sha512 9fd543815e89361939937513801e02202bafe734e1eaab6dc67e4211c85ef63e480a0a179774e5c6f55777defb39238e544adac318db3be7882acb0aab4a42ca
SSDeep 24576:/pzOZ5ezyKvUtzBSRG8XH86wMhhx9jwL4HyTZahDAKY99k:hzo5ez6GzoMhh/wL7MDFYL
TLSH AA352326BEA4EF87D07A427B0CE5C09443A87CA17F05A91B2796FB6C30B067171E654E
39fb359fff1d4ea12cfbc8000e715bfb
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00EE0754
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 87 0
#Stream obj 88 0
#Stream obj 89 0
#Stream obj 90 0
#Stream obj 91 0
#Stream obj 92 0
#Stream obj 93 0
#Stream obj 94 0
#Stream obj 72 0
#Stream obj 84 0
#Stream obj 71 0
#Stream obj 83 0
#Stream obj 82 0
#Stream obj 80 0
#Stream obj 77 0
#Stream obj 78 0
#Stream obj 76 0
#Stream obj 74 0
#Stream obj 101 0
#Stream obj 100 0
#Stream obj 73 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 31 0
#Stream obj 29 0
#Stream obj 53 0
#Stream obj 26 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 49 0
#Stream obj 47 0
#Stream obj 45 0
#Stream obj 44 0
#Stream obj 43 0
#Stream obj 41 0
#Stream obj 61 0
#Stream obj 62 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 66 0
#Stream obj 10 0
#Stream obj 2 0
#Stream obj 3 0
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 11 0
#Stream obj 67 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 42 0
#Stream obj 56 0
Structure
sharedStrings.xml
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD00EE0755
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL #2 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20130508153712+02'00'
Creator
Adobe InDesign CS6 (Macintosh)
ModifiedDate
D:20221229185615+05'30'
Producer
Adobe PDF Library 10.0.1
/CreationDate
D:20130508153712+02'00'
/Creator
Adobe InDesign CS6 (Macintosh)
/ModDate
D:20221229185615+05'30'
/Producer
Adobe PDF Library 10.0.1
An error has occurred. This application may no longer respond until reloaded. Reload 🗙