Suspicious
Suspect

8915011c77d0e5e8b0e05ee3c610d33b

MS Office Document
MD5: 8915011c77d0e5e8b0e05ee3c610d33b
Size: 993.79 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8915011c77d0e5e8b0e05ee3c610d33b
Sha1 160db26d8bcd4aae07f61b67afde30b40b6a1870
Sha256 987f6aaa246560441794de42e7126656818bf43d5aa0f45ca0ea82f285ce9317
Sha384 1ac1ba8c32ca7a871ccdb7ba80387d52779eac06e0784d0ee69d4d2135d46f0e6ed57bf151b824e7671d4b8fb5326198
Sha512 c8af18332d3b4f300610bdf607c27f45d416b49000ca9b06abf20ef39ef1363dbdd2f07b9c79bd4b05c070b7d8a2dac49ac5c5bbb73d137bc2286ef8bfc3a62c
SSDeep 24576:Ux3EWkuImjpuK6EAVTCnZuLPgz5OWOZwGLLEuuSn5:U1kOuK67GnZyPReS5
TLSH DE252205F019D267C5EE21355AC3E592413A7C86981CFE1B7B80BBFD2F321F0A67265A
8915011c77d0e5e8b0e05ee3c610d33b
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00241251
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
media
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 7 0
#Stream obj 10 0
#Stream obj 16 0
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 8 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 4 0
#Stream obj 4 0-preview.png
#Stream obj 5 0
#Stream obj 5 0-preview.png
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings4.bin
printerSettings2.bin
customXml
item3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD00241252
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20250128101513-03'00'
ModifiedDate
D:20250128101513-03'00'
Title
Comunicado Pedido de Compras.pdf
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20250128101513-03'00'
/ModDate
D:20250128101513-03'00'
/Producer
Microsoft: Print To PDF
/Title
Comunicado Pedido de Compras.pdf
Version
1.3
Author
BASIS
CreationDate
D:20260910130015
Creator
Form ZZM_PURCHORD_BR PT
Producer
SAP NetWeaver 740
/Author
BASIS
/CreationDate
D:20260910130015
/Creator
Form ZZM_PURCHORD_BR PT
/Producer
SAP NetWeaver 740
8915011c77d0e5e8b0e05ee3c610d33b
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00241251
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
media
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 7 0
#Stream obj 10 0
#Stream obj 16 0
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 8 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 4 0
#Stream obj 4 0-preview.png
#Stream obj 5 0
#Stream obj 5 0-preview.png
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings4.bin
printerSettings2.bin
customXml
item3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD00241252
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙