Suspicious
Suspect

9330f27eaa3e457b2b1ec4cc34dfcfd5

MS Office Document
MD5: 9330f27eaa3e457b2b1ec4cc34dfcfd5
Size: 889.34 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9330f27eaa3e457b2b1ec4cc34dfcfd5
Sha1 cf6701d46414e9ddb7e09df4bc0ad6a5b72b3a4a
Sha256 aaa252d9ddcd8c962f90bffe584c722fa38834e5b8051a4b7ac6ce043392cf4e
Sha384 5373b5651ac57186b1b104e0dd67ec5c58bc01e27d2f0dc66403403c234f74e7a9de9c1c0c56ec5efdd96275c9406273
Sha512 42bcec6b8157ea92cc80049bb9f1f8f708d5428965889aa8bd4225149ae11fbbc9611fbf236645541aad8c2c8ac61c924c6b2f12809d52cda9fa6e9d564a4d21
SSDeep 12288:o9YomKc2uOi9ckWP5Eg9oEh6+NWk2lU9gfS9nOlktp6vhY96lC64kd5MVz7sLPoB:UU19oqil9h9OlkGvy96lhd+VHs
TLSH 4115231ABC858E2BE1335E32C8DFD45B4E06BE071E20DCF71A90BB099A3D5E046DB519
9330f27eaa3e457b2b1ec4cc34dfcfd5
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0025A832
xl
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD0025A833
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD0025A834
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20220603065428-04'00'
Creator
Apache FOP Version 1.0
Producer
Apache FOP Version 1.0
/Creator
Apache FOP Version 1.0
/Producer
Apache FOP Version 1.0
/CreationDate
D:20220603065428-04'00'
Version
1.4
CreationDate
D:20260627193553+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
ModifiedDate
D:20260702085124-06'00'
Title
Transferencias Internacionales
Producer
Skia/PDF m149
/Title
Transferencias Internacionales
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
/Producer
Skia/PDF m149
/CreationDate
D:20260627193553+00'00'
/ModDate
D:20260702085124-06'00'
9330f27eaa3e457b2b1ec4cc34dfcfd5
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0025A832
xl
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD0025A833
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD0025A834
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙