Suspicious
Suspect

6497fadf53f16529a9833256bfef4e5a

Share on LinkedIn
Print
MS Office Document
MD5: 6497fadf53f16529a9833256bfef4e5a
Size: 813.57 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 6497fadf53f16529a9833256bfef4e5a
Sha1 b0164153e0d3c576c7944794705a0f82f70b695b
Sha256 7df9619f4ebfbfae75755efb99f044815ecfb17a8077fe90b300da86fc9e49e7
Sha384 77e78f69bbe994f315b81de79420f24e0b5876cee5ef73b42b1e6e167e9dd6066c0735e5aa843c03dec59a8a665826fa
Sha512 8b2a269649009640f8de96416542438639ba65abd293d18a668b9db23d419ff27b74e9b319cca6f589ef3673440f7ffe6d5a7b92c6629c4c784db10869dbf867
SSDeep 12288:TAPXRC5Ih55TEYnU+qQjScrYA53J3U7HaPYq0VpAL0t03OPT+WX4RZL:TA/EyHSccAlJ+HaSVO0yXWX4
TLSH 81052311F9E5AC2FC12364745DDE8484514CECC28E8FF65BBB51BB0F18316B5A9C4A3A
6497fadf53f16529a9833256bfef4e5a
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD004F7157
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet2.xml.rels
sheet1.xml.rels
sheet3.xml.rels
sheet5.xml.rels
sheet4.xml.rels
sheet2.xml
sheet3.xml
sheet5.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
vmlDrawing2.vml.rels
drawing4.xml
drawing1.xml
drawing2.xml
vmlDrawing1.vml
vmlDrawing2.vml
drawing3.xml
media
image4.emf
image3.emf
image1.png
image1.png-preview.png
image2.emf
embeddings
oleObject3.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 21 0
#Stream obj 24 0
#Stream obj 27 0
#Stream obj 29 0
#Stream obj 28 0
#Stream obj 37 0
#Stream obj 51 0
#Stream obj 65 0
#Stream obj 79 0
#Stream obj 93 0
#Stream obj 107 0
#Stream obj 121 0
#Stream obj 135 0
#Stream obj 150 0
#Stream obj 164 0
oleObject1.bin
Root Entry
CompObj
CONTENTS
oleObject2.bin
Root Entry
CONTENTS
#Stream obj 6 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 26 0
#Stream obj 26 0-preview.png
#Stream obj 40 0
#Stream obj 27 0
#Stream obj 41 0
#Stream obj 28 0
#Stream obj 42 0
#Stream obj 29 0
#Stream obj 44 0
#Stream obj 31 0
#Stream obj 45 0
#Stream obj 32 0
#Stream obj 47 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 20 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 37 0
#Stream obj 37 0-preview.png
#Stream obj 38 0
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings1.bin
printerSettings2.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD004F7158
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.4
Author
City of Johannesburg
CreationDate
D:20260622150000+02'00'
Subject
Account Number : 556736545
Title
Tax Invoice
Version
1.7
Author
Absa Retail
CreationDate
D:20260622120032Z
Creator
DocFusion
ModifiedDate
D:20260622120032Z
Producer
DocFusion
/Creator
DocFusion
/ModDate
D:20260622120032Z
/CreationDate
D:20260622120032Z
/Producer
DocFusion
/Author
Absa Retail
URI URI
mailtohuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙