Suspicious
Suspect

PDF @0x00000000

Share on LinkedIn
Print
MS Office Document
MD5: 8eb0f2b79f67a0391957d4fa93ebc755
Size: 1.22 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8eb0f2b79f67a0391957d4fa93ebc755
Sha1 4de27e172060b5af7b80ed192bdeb0190520b01a
Sha256 2dae1df14d0cc6ea8e670e0b327101d0fe5c475dc06a376e99a6df426bddf418
Sha384 16651fec6b73fa11c53cd4ef4eb148c5362c7199744c9359c6baaac4b66a53eeb5fecbec37a3d2eaa03e34bc892955c7
Sha512 8c83fbdf3cc07baa6c2fece5672dc13b5f2b291f7dc236c5d1913e1032288c49f903f3fbb5c24be5bd8338a9317f286abe0e4671d23772f3d72e6af7833f21ae
SSDeep 24576:c6S0UkKcOdfc3lUBXK5t1QRT/64rmVz/G7inkPTYv3IhvO:c6pUTPdU3l0K5tmB6n70YQO
TLSH E9452222FE41CE26D92157351BEBB0C2DB1AFC636E69094F3381B36569321B4CBB2D45
8eb0f2b79f67a0391957d4fa93ebc755
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0001FDF8
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 8 0
#Stream obj 2 0
#Stream obj 3 0
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 345 0
#Stream obj 347 0
#Stream obj 351 0
#Stream obj 346 0
#Stream obj 12 0
#Stream obj 11 0
#Stream obj 4 0
#Stream obj 24 0
#Stream obj 28 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 36 0
#Stream obj 38 0
#Stream obj 42 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 355 0
#Stream obj 50 0
#Stream obj 54 0
#Stream obj 356 0
#Stream obj 63 0
#Stream obj 358 0
printerSettings
printerSettings1.bin
docProps
core.xml
app.xml
CompObj
MBD0001FDF9
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD0001FDFA
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 5img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Version
1.7
Author
Thabo Katane
CreationDate
D:20240209092531+02'00'
Creator
Microsoft® Word for Microsoft 365
ModifiedDate
D:20240209092531+02'00'
Producer
Microsoft® Word for Microsoft 365
/Author
Thabo Katane
/Creator
Microsoft® Word for Microsoft 365
/CreationDate
D:20240209092531+02'00'
/ModDate
D:20240209092531+02'00'
/Producer
Microsoft® Word for Microsoft 365
Version
1.4
CreationDate
D:20260812131346Z
ModifiedDate
D:20260812131346Z
Producer
iText 2.1.7 by 1T3XT
/ModDate
D:20260812131346Z
/CreationDate
D:20260812131346Z
/Producer
iText 2.1.7 by 1T3XT
URI URI
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙