Suspicious
Suspect

PDF @0x00000000

MS Office Document
MD5: 8eb0f2b79f67a0391957d4fa93ebc755
Size: 1.22 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8eb0f2b79f67a0391957d4fa93ebc755
Sha1 4de27e172060b5af7b80ed192bdeb0190520b01a
Sha256 2dae1df14d0cc6ea8e670e0b327101d0fe5c475dc06a376e99a6df426bddf418
Sha384 16651fec6b73fa11c53cd4ef4eb148c5362c7199744c9359c6baaac4b66a53eeb5fecbec37a3d2eaa03e34bc892955c7
Sha512 8c83fbdf3cc07baa6c2fece5672dc13b5f2b291f7dc236c5d1913e1032288c49f903f3fbb5c24be5bd8338a9317f286abe0e4671d23772f3d72e6af7833f21ae
SSDeep 24576:c6S0UkKcOdfc3lUBXK5t1QRT/64rmVz/G7inkPTYv3IhvO:c6pUTPdU3l0K5tmB6n70YQO
TLSH E9452222FE41CE26D92157351BEBB0C2DB1AFC636E69094F3381B36569321B4CBB2D45
8eb0f2b79f67a0391957d4fa93ebc755
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0001FDF8
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 8 0
#Stream obj 2 0
#Stream obj 3 0
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 345 0
#Stream obj 347 0
#Stream obj 351 0
#Stream obj 346 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 24 0
#Stream obj 28 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 36 0
#Stream obj 38 0
#Stream obj 42 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 355 0
#Stream obj 50 0
#Stream obj 54 0
#Stream obj 356 0
#Stream obj 63 0
#Stream obj 358 0
printerSettings
printerSettings1.bin
docProps
core.xml
app.xml
CompObj
MBD0001FDF9
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD0001FDFA
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 5img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Version
1.7
Author
Thabo Katane
CreationDate
D:20240209092531+02'00'
Creator
Microsoft® Word for Microsoft 365
ModifiedDate
D:20240209092531+02'00'
Producer
Microsoft® Word for Microsoft 365
/Author
Thabo Katane
/Creator
Microsoft® Word for Microsoft 365
/CreationDate
D:20240209092531+02'00'
/ModDate
D:20240209092531+02'00'
/Producer
Microsoft® Word for Microsoft 365
Version
1.4
CreationDate
D:20260812131346Z
ModifiedDate
D:20260812131346Z
Producer
iText 2.1.7 by 1T3XT
/ModDate
D:20260812131346Z
/CreationDate
D:20260812131346Z
/Producer
iText 2.1.7 by 1T3XT
URI URI
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
8eb0f2b79f67a0391957d4fa93ebc755
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0001FDF8
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 8 0
#Stream obj 2 0
#Stream obj 3 0
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 345 0
#Stream obj 347 0
#Stream obj 351 0
#Stream obj 346 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 24 0
#Stream obj 28 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 36 0
#Stream obj 38 0
#Stream obj 42 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 355 0
#Stream obj 50 0
#Stream obj 54 0
#Stream obj 356 0
#Stream obj 63 0
#Stream obj 358 0
printerSettings
printerSettings1.bin
docProps
core.xml
app.xml
CompObj
MBD0001FDF9
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD0001FDFA
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
No malware configuration was found at this point.
URI URI
https:huhuhuhuhuhuhuhuhuhuhu
8eb0f2b79f67a0391957d4fa93ebc755 › Root Entry › MBD0001FDF8 › Package › xl › embeddings › oleObject2.bin › Root Entry › CONTENTS
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙