Malicious
Malicious

7556863f1628506a4a2c2f65d901b669

MS Office Document
MD5: 7556863f1628506a4a2c2f65d901b669
Size: 2.31 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7556863f1628506a4a2c2f65d901b669
Sha1 c981753024346ee408f949a60f416533d1a2e6ed
Sha256 d13f0a4ce47f11f16e95b36e6833b13406546644cb52bb96f2017b64de0c04c2
Sha384 318a21e9824098ef9e37aa53529123450ebf89c906ea21b27f470e7d36d73fda1934f6eac08c2d287131a11bddecc1db
Sha512 d5a19784bf1212cea0da27724c0a243618dafe6b63d13ace7c90c58d35131fd42fbe4a2e226280c4d95c73dc410b5b5a3c47045042c4b34da6395c10d4a93185
SSDeep 49152:BmwNjA/jmSsKftqJoQmuo/OBMmwNjA/jmSsKftqJoQmuo/OBIjbVw2:V43lP43lV
TLSH CFB5233BDA839D9BCD1E0174966B6095791F1E22BB147E6E370C7B6A68B703083F590C
7556863f1628506a4a2c2f65d901b669
Malicious
[Repaired @0x000F5E00]
Malicious
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001E5057
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
media
image7.png
image7.png-preview.png
image8.jpeg
image8.jpeg-preview.png
image9.emf
image6.png
image6.png-preview.png
image5.jpeg
image5.jpeg-preview.png
image4.png
image4.png-preview.png
image2.png
image2.png-preview.png
image3.png
image3.png-preview.png
image1.png
image1.png-preview.png
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing1.xml
vmlDrawing1.vml
embeddings
oleObject1.bin
Root Entry
CompObj
CONTENTS
#Stream {UglyToad.PdfPig.Core.XrefLocation}
#Stream {UglyToad.PdfPig.Core.XrefLocation}.exif
#Stream {UglyToad.PdfPig.Core.XrefLocation}-preview.png
Structure
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD001E5059
Ole
ole10natIve
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 www.cahuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
CONTENTS
1.7
CONTENTS
—
CONTENTS
D:20260418134318+05'30'
CONTENTS
D:20260418134318+05'30'
CONTENTS
281411 AHU Quote Ananya Cleanroom Technologies.xlsx
CONTENTS
Microsoft: Print To PDF
CONTENTS
—
CONTENTS
D:20260418134318+05'30'
CONTENTS
D:20260418134318+05'30'
CONTENTS
Microsoft: Print To PDF
CONTENTS
281411 AHU Quote Ananya Cleanroom Technologies.xlsx
7556863f1628506a4a2c2f65d901b669
Malicious
[Repaired @0x000F5E00]
Malicious
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001E5057
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
media
image7.png
image7.png-preview.png
image8.jpeg
image8.jpeg-preview.png
image9.emf
image6.png
image6.png-preview.png
image5.jpeg
image5.jpeg-preview.png
image4.png
image4.png-preview.png
image2.png
image2.png-preview.png
image3.png
image3.png-preview.png
image1.png
image1.png-preview.png
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing1.xml
vmlDrawing1.vml
embeddings
oleObject1.bin
Root Entry
CompObj
CONTENTS
#Stream {UglyToad.PdfPig.Core.XrefLocation}
#Stream {UglyToad.PdfPig.Core.XrefLocation}.exif
#Stream {UglyToad.PdfPig.Core.XrefLocation}-preview.png
Structure
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD001E5059
Ole
ole10natIve
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 www.cahuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙