Malicious
PDF @0x00000000
MS Office Document
MD5: 783e2d6de57faedc511d3a76040dc912
Size: 1.23 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 783e2d6de57faedc511d3a76040dc912 |
| Sha1 | 1855f198439eadfb32c21d6dc44ecc29918d5f0b |
| Sha256 | 7e8b04a5331275ab6154539494b11185b30a3952f472b714ba6d2f95cd19c7de |
| Sha384 | 29327ca3f81a25efe0f0ca0592de0a731ad97a94e18790113feed4f3ebd670ac2cd1032da15e86c5cc442e9c0ff1bca9 |
| Sha512 | 017af015706b5c7d4ec4183db6867bcc3a922bebfafba940cdc84b1e5179df4e727a9dc31769a20afdada4ebf6040a5cccb830c43d00706a449a394502eacf4b |
| SSDeep | 24576:XKpt1QRT/64rm0rizKRj3g/5qYjTTwWXRtm10t5Q9BlVT8Cget:XKptmB6ari+9s9h4aQ338C |
| TLSH | 99451214FF418D3AC852923507E7B1E1C61ABC776E124E4F23457339A973AB0D672E1A |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 13
STICH kept: 2secondary ignored: 11
bin
5img
2oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape
ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.7 |
| CreationDate | D:20260802163606-08'00' |
| Creator | HP Scan |
| ModifiedDate | D:20260802163606-08'00' |
| Producer | HP Scan Extended Application |
| /Creator | HP Scan |
| /CreationDate | D:20260802163606-08'00' |
| /ModDate | D:20260802163606-08'00' |
| /Producer | HP Scan Extended Application |
| Version | 1.6 |
| Producer | Oracle BI Publisher 12.2.1.4.0 |
| /Producer | Oracle BI Publisher 12.2.1.4.0 |
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
783e2d6de57faedc511d3a76040dc912 › Root Entry › MBD0029F259 › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.