Suspicious
Suspect

41520b3039069a351b264d5da54fe659

Share on LinkedIn
Print
MS Office Document
MD5: 41520b3039069a351b264d5da54fe659
Size: 666.11 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 41520b3039069a351b264d5da54fe659
Sha1 2fc4dbce1e2f560cbc018236dbb7bb7e8ec3b77c
Sha256 a7c9f9121f9c0804ac28f2327b53361ba25bbd10556b0a3e6446e6a9b752fdf1
Sha384 47a4e7438732360e8b42bdd7f048998b8e9bcdaf33f662e1d863daca919244bf3e6643e5861c521c00981254db7c7225
Sha512 4ec82e7bd9356b752c307af0c6ce183202a3e5ffd588048d70a2774f028a7a01920b5044573ae3951c7394e3eeab8d3a1105606ff7223e56f8461b6cf4625c10
SSDeep 12288:pHUaf6xAosjelwm2w00000000000S02tGboHc9qCr94aSa9eOrUwghaRB4:t/CTKm2xoc/elhgRK
TLSH F5E4230AF784DF9BE6C7193542C7B0D9902DACA69784C22F3B54B77E2A332B1D062549
41520b3039069a351b264d5da54fe659
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00DA8A9B
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
media
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.png
image4.png-preview.png
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
theme
theme1.xml
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 5 0
#Stream obj 5 0-preview.png
#Stream obj 279 0
#Stream obj 282 0
#Stream obj 283 0
#Stream obj 286 0
#Stream obj 287 0
#Stream obj 290 0
#Stream obj 291 0
#Stream obj 294 0
#Stream obj 10 0
Structure
sharedStrings.xml
styles.xml
printerSettings
printerSettings2.bin
printerSettings4.bin
customXml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
item3.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
core.xml
app.xml
custom.xml
CompObj
MBD00DA8A9C
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.4
CreationDate
D:20260910044932+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
ModifiedDate
D:20260910044932+00'00'
Title
SLES CALIBRATION PRIVATE LIMITED
Producer
Skia/PDF m152
/Title
SLES CALIBRATION PRIVATE LIMITED
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
/Producer
Skia/PDF m152
/CreationDate
D:20260910044932+00'00'
/ModDate
D:20260910044932+00'00'
An error has occurred. This application may no longer respond until reloaded. Reload 🗙