Malicious
PDF @0x00000000
MS Office Document
MD5: 87eb0a1a6b07479bc1065576d10ccf53
Size: 920.58 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 87eb0a1a6b07479bc1065576d10ccf53 |
| Sha1 | acf1f46a59a8c675eafb52051956322aaecdb763 |
| Sha256 | 32f7eefee64db549de9a1299ae677db39d34df0736d6bd3f1b69dcd1a67284a9 |
| Sha384 | a077980e0198a8ef7d7835403e5e295735e0622fccf0e472f095644bf6d90d3c2db5827f4e7880195f70f5ae24d8bc56 |
| Sha512 | 0a6bf0b7ab3638a659d89266caf454af4fde2e187d6bf136bb7a1817d0054056bc8d44461f77ac0452c22cb424a11ea690f7a9c97630ecc8d2e5268871dc094e |
| SSDeep | 12288:DrKPdVpw2F1J+RT/II8fp4rm4y+ev5B95S1UiXFZYeC/FF1anBTNex4Ae5rcMoTb:/Kdt1QRT/64rmFu1UiVNC/z1yPkUrwr |
| TLSH | 6A151211EF848937CDD297380B9372C5E60DFC679E6B4B0A57487369783B6F4A861C0A |
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 2secondary ignored: 10
bin
5img
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape
ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #4 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.7 |
| CreationDate | D:20260731145050-04'00 |
| Creator | Mozilla Firefox 153.0.1 |
| Producer | cairo 1.18.4 (https://cairographics.org) |
| /Producer | cairo 1.18.4 (https://cairographics.org) |
| /Creator | Mozilla Firefox 153.0.1 |
| /CreationDate | D:20260731145050-04'00 |
| Version | 1.6 |
| Producer | Oracle BI Publisher 12.2.1.4.0 |
| /Producer | Oracle BI Publisher 12.2.1.4.0 |
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #4 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
87eb0a1a6b07479bc1065576d10ccf53 › Root Entry › MBD003D5392 › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.