Malicious
Malicious

5c7a42ba06acab5297e510ea2b6971a0

Share on LinkedIn
Print
MS Office Document
MD5: 5c7a42ba06acab5297e510ea2b6971a0
Size: 455.68 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5c7a42ba06acab5297e510ea2b6971a0
Sha1 19208133a21266653a33a0740b33072a10539c43
Sha256 598d4275943265e6d53955ebc55d7fe2cb5d2633d4c3cbd31fc5ec31245c1075
Sha384 7b09cc0f2ef956e2823f450899f65cfddaa92021b67d79d02513caf3d2774572e0c62c9a81ca269de95d4cbd3dd93843
Sha512 43237544b06c318a10dd2827b42476cae830ace3c43eeb77d7fe739c23302d67b226b55fbbabdbbaeb666fdf407fa27511b2146e60bd1353092911770566e417
SSDeep 6144:A+MWp/gRH8oCM/xV19jpULb6zWp5chJymus37JeMoYXq6gHRUm16/hVmMOzTKvgX:tp/6Hf32gWb/mjJeM1Xq6gHKRSMZgZ5
TLSH A9A4232430C0DC67D1BB89BD88E4C213B11AFC969FE72C07B24B335F4A376954A5B969
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD017A3EC6
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole10Native
#Stream obj 37 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 24 0
#Stream obj 26 0
#Stream obj 32 0
#Stream obj 34 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 48 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 54 0
#Stream obj 57 0
Structure
PDF @0x000000B6
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD017A3EC7
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>img
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>img
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20260909163730-03'00'
ModifiedDate
D:20260909163730-03'00'
Title
HBRAGA/BRP0000422768_1
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20260909163730-03'00'
/ModDate
D:20260909163730-03'00'
/Producer
Microsoft: Print To PDF
/Title
HBRAGA/BRP0000422768_1
An error has occurred. This application may no longer respond until reloaded. Reload 🗙