Malicious
Malicious

469a8f715bb5830353332e9859f770ec

MS Office Document
MD5: 469a8f715bb5830353332e9859f770ec
Size: 455.68 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 469a8f715bb5830353332e9859f770ec
Sha1 3ad4cabd68d62b4c586b2ae2564904a771bc799f
Sha256 800376b9807c86fa1e3320432f40339f31209093ab16efc90ef9e02ed218df11
Sha384 7558b031bb72bb6c8f2b856ef3261edaab0f38386cdd3185b6ec8ba3377e11846c335df5a11d4838429ffc62145b2d42
Sha512 20f84b0d45196a519f07a67180a4d5644f0be15c0e1948b12a4c76c27527c40cc7930c94d85e04dab519b19709ad7596105854962e5abc94bf81e7a9c1340c81
SSDeep 6144:IXq0SWp/gRH8oCM/xV19jpULb6zWp5chJymus37JeMoYXq6gHRUm16/hVmMOzTKr:yp/6Hf32gWb/mjJeM1Xq6gHKRSMZg6i
TLSH 21A4232430C0DD67D1AB49FCC8E0C253711BFC859FA62D1BB28A335F0A767845E5B9A9
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017C67C2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017C67C3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>img
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>img
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017C67C2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017C67C3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙