Malicious
Malicious

PDF @0x00000000

Share on LinkedIn
Print
MS Office Document
MD5: 67130b4f6871f2b39778d402d0fe20f4
Size: 1.23 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 67130b4f6871f2b39778d402d0fe20f4
Sha1 5879abeb5f2627dbe91a295bd63aa2d273e29cc2
Sha256 13b3fbb9fed1b90b4083593a380397a6253ff60b0af8f2cfa71abf84279ccca7
Sha384 9ecde5d8b64696d306f0bbf67fad4ddd97a7e52efe71ab0c3c15f9ab9e450c8632cf2c1beeb880b226f07b4561923bba
Sha512 f5400e7cedc0eba5a6b8ba387406b36f62437c7664182ee5aafbea23240f8e5cc7ce42b0eba6fb0666293278e976d4b6517851e88fdb2a48bfc513aaebf1b48a
SSDeep 24576:bK5t1QRT/64rmRrizKRj3g/5qYjTTwWXIuwRYA2C/DGSkT3mSIJWh7Nlj1E:bK5tmB6vri+9s9ZwqA2esT3owhfj1
TLSH F4452210FE848D29C94293350BE3B1D6D529BC277E214A0F23597379B977B70E762E0A
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00269F53
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD00269F54
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
Text (Preview)
#Stream obj 1 0
#Stream obj 1 0-preview.png
#Stream obj 2 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00269F55
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 13 STICH kept: 2secondary ignored: 11
bin 5img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260802163606-08'00'
Creator
HP Scan
ModifiedDate
D:20260802163606-08'00'
Producer
HP Scan Extended Application
/Creator
HP Scan
/CreationDate
D:20260802163606-08'00'
/ModDate
D:20260802163606-08'00'
/Producer
HP Scan Extended Application
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙