Malicious
Malicious

PDF @0x00000000

Share on LinkedIn
Print
MS Office Document
MD5: 783e2d6de57faedc511d3a76040dc912
Size: 1.23 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 783e2d6de57faedc511d3a76040dc912
Sha1 1855f198439eadfb32c21d6dc44ecc29918d5f0b
Sha256 7e8b04a5331275ab6154539494b11185b30a3952f472b714ba6d2f95cd19c7de
Sha384 29327ca3f81a25efe0f0ca0592de0a731ad97a94e18790113feed4f3ebd670ac2cd1032da15e86c5cc442e9c0ff1bca9
Sha512 017af015706b5c7d4ec4183db6867bcc3a922bebfafba940cdc84b1e5179df4e727a9dc31769a20afdada4ebf6040a5cccb830c43d00706a449a394502eacf4b
SSDeep 24576:XKpt1QRT/64rm0rizKRj3g/5qYjTTwWXRtm10t5Q9BlVT8Cget:XKptmB6ari+9s9h4aQ338C
TLSH 99451214FF418D3AC852923507E7B1E1C61ABC776E124E4F23457339A973AB0D672E1A
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0029F258
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD0029F259
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
Text (Preview)
#Stream obj 1 0
#Stream obj 1 0-preview.png
#Stream obj 2 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD0029F25A
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 13 STICH kept: 2secondary ignored: 11
bin 5img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260802163606-08'00'
Creator
HP Scan
ModifiedDate
D:20260802163606-08'00'
Producer
HP Scan Extended Application
/Creator
HP Scan
/CreationDate
D:20260802163606-08'00'
/ModDate
D:20260802163606-08'00'
/Producer
HP Scan Extended Application
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙