Suspicious
Suspect

9330f27eaa3e457b2b1ec4cc34dfcfd5

Share on LinkedIn
Print
MS Office Document
MD5: 9330f27eaa3e457b2b1ec4cc34dfcfd5
Size: 889.34 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9330f27eaa3e457b2b1ec4cc34dfcfd5
Sha1 cf6701d46414e9ddb7e09df4bc0ad6a5b72b3a4a
Sha256 aaa252d9ddcd8c962f90bffe584c722fa38834e5b8051a4b7ac6ce043392cf4e
Sha384 5373b5651ac57186b1b104e0dd67ec5c58bc01e27d2f0dc66403403c234f74e7a9de9c1c0c56ec5efdd96275c9406273
Sha512 42bcec6b8157ea92cc80049bb9f1f8f708d5428965889aa8bd4225149ae11fbbc9611fbf236645541aad8c2c8ac61c924c6b2f12809d52cda9fa6e9d564a4d21
SSDeep 12288:o9YomKc2uOi9ckWP5Eg9oEh6+NWk2lU9gfS9nOlktp6vhY96lC64kd5MVz7sLPoB:UU19oqil9h9OlkGvy96lhd+VHs
TLSH 4115231ABC858E2BE1335E32C8DFD45B4E06BE071E20DCF71A90BB099A3D5E046DB519
9330f27eaa3e457b2b1ec4cc34dfcfd5
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0025A832
xl
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
theme
theme1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD0025A833
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD0025A834
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20220603065428-04'00'
Creator
Apache FOP Version 1.0
Producer
Apache FOP Version 1.0
/Creator
Apache FOP Version 1.0
/Producer
Apache FOP Version 1.0
/CreationDate
D:20220603065428-04'00'
Version
1.4
CreationDate
D:20260627193553+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
ModifiedDate
D:20260702085124-06'00'
Title
Transferencias Internacionales
Producer
Skia/PDF m149
/Title
Transferencias Internacionales
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
/Producer
Skia/PDF m149
/CreationDate
D:20260627193553+00'00'
/ModDate
D:20260702085124-06'00'
An error has occurred. This application may no longer respond until reloaded. Reload 🗙