Malicious
Malicious

5c7a42ba06acab5297e510ea2b6971a0

MS Office Document
MD5: 5c7a42ba06acab5297e510ea2b6971a0
Size: 455.68 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5c7a42ba06acab5297e510ea2b6971a0
Sha1 19208133a21266653a33a0740b33072a10539c43
Sha256 598d4275943265e6d53955ebc55d7fe2cb5d2633d4c3cbd31fc5ec31245c1075
Sha384 7b09cc0f2ef956e2823f450899f65cfddaa92021b67d79d02513caf3d2774572e0c62c9a81ca269de95d4cbd3dd93843
Sha512 43237544b06c318a10dd2827b42476cae830ace3c43eeb77d7fe739c23302d67b226b55fbbabdbbaeb666fdf407fa27511b2146e60bd1353092911770566e417
SSDeep 6144:A+MWp/gRH8oCM/xV19jpULb6zWp5chJymus37JeMoYXq6gHRUm16/hVmMOzTKvgX:tp/6Hf32gWb/mjJeM1Xq6gHKRSMZgZ5
TLSH A9A4232430C0DC67D1BB89BD88E4C213B11AFC969FE72C07B24B335F4A376954A5B969
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017A3EC6
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017A3EC7
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>img
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>img
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017A3EC6
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017A3EC7
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙