Suspicious
Suspect

8915011c77d0e5e8b0e05ee3c610d33b

Share on LinkedIn
Print
MS Office Document
MD5: 8915011c77d0e5e8b0e05ee3c610d33b
Size: 993.79 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8915011c77d0e5e8b0e05ee3c610d33b
Sha1 160db26d8bcd4aae07f61b67afde30b40b6a1870
Sha256 987f6aaa246560441794de42e7126656818bf43d5aa0f45ca0ea82f285ce9317
Sha384 1ac1ba8c32ca7a871ccdb7ba80387d52779eac06e0784d0ee69d4d2135d46f0e6ed57bf151b824e7671d4b8fb5326198
Sha512 c8af18332d3b4f300610bdf607c27f45d416b49000ca9b06abf20ef39ef1363dbdd2f07b9c79bd4b05c070b7d8a2dac49ac5c5bbb73d137bc2286ef8bfc3a62c
SSDeep 24576:Ux3EWkuImjpuK6EAVTCnZuLPgz5OWOZwGLLEuuSn5:U1kOuK67GnZyPReS5
TLSH DE252205F019D267C5EE21355AC3E592413A7C86981CFE1B7B80BBFD2F321F0A67265A
8915011c77d0e5e8b0e05ee3c610d33b
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00241251
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
media
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 7 0
#Stream obj 10 0
#Stream obj 16 0
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 8 0
#Stream obj 9 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 4 0
#Stream obj 4 0-preview.png
#Stream obj 5 0
#Stream obj 5 0-preview.png
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings4.bin
printerSettings2.bin
customXml
item3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD00241252
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
Author
Hyme Braga(JCNA)
CreationDate
D:20250128101513-03'00'
ModifiedDate
D:20250128101513-03'00'
Title
Comunicado Pedido de Compras.pdf
Producer
Microsoft: Print To PDF
/Author
Hyme Braga(JCNA)
/CreationDate
D:20250128101513-03'00'
/ModDate
D:20250128101513-03'00'
/Producer
Microsoft: Print To PDF
/Title
Comunicado Pedido de Compras.pdf
Version
1.3
Author
BASIS
CreationDate
D:20260910130015
Creator
Form ZZM_PURCHORD_BR PT
Producer
SAP NetWeaver 740
/Author
BASIS
/CreationDate
D:20260910130015
/Creator
Form ZZM_PURCHORD_BR PT
/Producer
SAP NetWeaver 740
An error has occurred. This application may no longer respond until reloaded. Reload 🗙