Suspicious
Suspect

41520b3039069a351b264d5da54fe659

MS Office Document
MD5: 41520b3039069a351b264d5da54fe659
Size: 666.11 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41520b3039069a351b264d5da54fe659
Sha1 2fc4dbce1e2f560cbc018236dbb7bb7e8ec3b77c
Sha256 a7c9f9121f9c0804ac28f2327b53361ba25bbd10556b0a3e6446e6a9b752fdf1
Sha384 47a4e7438732360e8b42bdd7f048998b8e9bcdaf33f662e1d863daca919244bf3e6643e5861c521c00981254db7c7225
Sha512 4ec82e7bd9356b752c307af0c6ce183202a3e5ffd588048d70a2774f028a7a01920b5044573ae3951c7394e3eeab8d3a1105606ff7223e56f8461b6cf4625c10
SSDeep 12288:pHUaf6xAosjelwm2w00000000000S02tGboHc9qCr94aSa9eOrUwghaRB4:t/CTKm2xoc/elhgRK
TLSH F5E4230AF784DF9BE6C7193542C7B0D9902DACA69784C22F3B54B77E2A332B1D062549
41520b3039069a351b264d5da54fe659
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00DA8A9B
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
media
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.png
image4.png-preview.png
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
theme
theme1.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 5 0
#Stream obj 5 0-preview.png
#Stream obj 279 0
#Stream obj 282 0
#Stream obj 283 0
#Stream obj 286 0
#Stream obj 287 0
#Stream obj 290 0
#Stream obj 291 0
#Stream obj 294 0
#Stream obj 10 0
Structure
sharedStrings.xml
styles.xml
printerSettings
printerSettings2.bin
printerSettings4.bin
customXml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
item3.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
core.xml
app.xml
custom.xml
CompObj
MBD00DA8A9C
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.4
CreationDate
D:20260910044932+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
ModifiedDate
D:20260910044932+00'00'
Title
SLES CALIBRATION PRIVATE LIMITED
Producer
Skia/PDF m152
/Title
SLES CALIBRATION PRIVATE LIMITED
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
/Producer
Skia/PDF m152
/CreationDate
D:20260910044932+00'00'
/ModDate
D:20260910044932+00'00'
41520b3039069a351b264d5da54fe659
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00DA8A9B
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
media
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.png
image4.png-preview.png
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
theme
theme1.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 5 0
#Stream obj 5 0-preview.png
#Stream obj 279 0
#Stream obj 282 0
#Stream obj 283 0
#Stream obj 286 0
#Stream obj 287 0
#Stream obj 290 0
#Stream obj 291 0
#Stream obj 294 0
#Stream obj 10 0
Structure
sharedStrings.xml
styles.xml
printerSettings
printerSettings2.bin
printerSettings4.bin
customXml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
item3.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
core.xml
app.xml
custom.xml
CompObj
MBD00DA8A9C
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙