Suspect
8915011c77d0e5e8b0e05ee3c610d33b
MS Office Document
MD5: 8915011c77d0e5e8b0e05ee3c610d33b
Size: 993.79 KB
application/vnd.ms-office
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 8915011c77d0e5e8b0e05ee3c610d33b |
| Sha1 | 160db26d8bcd4aae07f61b67afde30b40b6a1870 |
| Sha256 | 987f6aaa246560441794de42e7126656818bf43d5aa0f45ca0ea82f285ce9317 |
| Sha384 | 1ac1ba8c32ca7a871ccdb7ba80387d52779eac06e0784d0ee69d4d2135d46f0e6ed57bf151b824e7671d4b8fb5326198 |
| Sha512 | c8af18332d3b4f300610bdf607c27f45d416b49000ca9b06abf20ef39ef1363dbdd2f07b9c79bd4b05c070b7d8a2dac49ac5c5bbb73d137bc2286ef8bfc3a62c |
| SSDeep | 24576:Ux3EWkuImjpuK6EAVTCnZuLPgz5OWOZwGLLEuuSn5:U1kOuK67GnZyPReS5 |
| TLSH | DE252205F019D267C5EE21355AC3E592413A7C86981CFE1B7B80BBFD2F321F0A67265A |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 11
STICH kept: 1secondary ignored: 10
bin
4img
2oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.7 |
| Author | Hyme Braga(JCNA) |
| CreationDate | D:20250128101513-03'00' |
| ModifiedDate | D:20250128101513-03'00' |
| Title | Comunicado Pedido de Compras.pdf |
| Producer | Microsoft: Print To PDF |
| /Author | Hyme Braga(JCNA) |
| /CreationDate | D:20250128101513-03'00' |
| /ModDate | D:20250128101513-03'00' |
| /Producer | Microsoft: Print To PDF |
| /Title | Comunicado Pedido de Compras.pdf |
| Version | 1.3 |
| Author | BASIS |
| CreationDate | D:20260910130015 |
| Creator | Form ZZM_PURCHORD_BR PT |
| Producer | SAP NetWeaver 740 |
| /Author | BASIS |
| /CreationDate | D:20260910130015 |
| /Creator | Form ZZM_PURCHORD_BR PT |
| /Producer | SAP NetWeaver 740 |
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.