Malicious
Malicious

469a8f715bb5830353332e9859f770ec

Share on LinkedIn
Print
MS Office Document
MD5: 469a8f715bb5830353332e9859f770ec
Size: 455.68 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 469a8f715bb5830353332e9859f770ec
Sha1 3ad4cabd68d62b4c586b2ae2564904a771bc799f
Sha256 800376b9807c86fa1e3320432f40339f31209093ab16efc90ef9e02ed218df11
Sha384 7558b031bb72bb6c8f2b856ef3261edaab0f38386cdd3185b6ec8ba3377e11846c335df5a11d4838429ffc62145b2d42
Sha512 20f84b0d45196a519f07a67180a4d5644f0be15c0e1948b12a4c76c27527c40cc7930c94d85e04dab519b19709ad7596105854962e5abc94bf81e7a9c1340c81
SSDeep 6144:IXq0SWp/gRH8oCM/xV19jpULb6zWp5chJymus37JeMoYXq6gHRUm16/hVmMOzTKr:yp/6Hf32gWb/mjJeM1Xq6gHKRSMZg6i
TLSH 21A4232430C0DD67D1AB49FCC8E0C253711BFC859FA62D1BB28A335F0A767845E5B9A9
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017C67C2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017C67C3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>img
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>img
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
An error has occurred. This application may no longer respond until reloaded. Reload 🗙