Malicious
Malicious

9792da30038b26f7203179ec154c3f81

MS Office Document
MD5: 9792da30038b26f7203179ec154c3f81
Size: 619.52 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 9792da30038b26f7203179ec154c3f81
Sha1 16b32feb820ae9e9d9da256bf3d7a713fcf3baab
Sha256 93e1a2507a6739baf7ecea52b403e6e70ea3eb170377b8ca6db40f4dc3ff9886
Sha384 df35a584f6cfcba2c83a3b4fdc2f4885ea54e582342ab3ef0d099a470689a9f2c6fd607a793d5557514e3c09236ab115
Sha512 5a72d72b9135d187add84d96c404b2fabe0d6eacf48311cbf64cb718f9c342d00e4773c3ba4da2ae3798ae2fdab7504fb06dfaacea48ed1a44b544db672d9456
SSDeep 12288:6w00000000000S02tGboHzW7FelLnzpnoDJXf/8Ocef3GQyN8aS9VjBU:6xoTWm1oh38es8P
TLSH 78D42209B6D8DE97EBC39B7A87C2D056D97DED69CA4EC02B744C335D193332244A2329
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD016EBB01
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 5 0
#Stream obj 5 0-preview.png
#Stream obj 279 0
#Stream obj 282 0
#Stream obj 283 0
#Stream obj 286 0
#Stream obj 287 0
#Stream obj 290 0
#Stream obj 291 0
#Stream obj 294 0
#Stream obj 10 0
oleObject1.bin
Root Entry
Ole10Native
Text (Preview)
#Stream obj 13 0
#Stream obj 12 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 5 0
Structure
PDF @0x000000E0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD016EBB02
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>img
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>img
malicious 6 nodes
Config. Field Value
URL distante (OLE moniker) #1 HtTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
Version
1.4
CreationDate
D:20260910044932+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
ModifiedDate
D:20260910044932+00'00'
Title
SLES CALIBRATION PRIVATE LIMITED
Producer
Skia/PDF m152
/Title
SLES CALIBRATION PRIVATE LIMITED
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
/Producer
Skia/PDF m152
/CreationDate
D:20260910044932+00'00'
/ModDate
D:20260910044932+00'00'
Version
1.3
Author
dipak
CreationDate
D:20260905130956+05'30'
Creator
PScript5.dll Version 5.2.2
ModifiedDate
D:20260905130956+05'30'
Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
Producer
GPL Ghostscript 9.06
/Producer
GPL Ghostscript 9.06
/CreationDate
D:20260905130956+05'30'
/ModDate
D:20260905130956+05'30'
/Title
Crystal Reports ActiveX Designer - PI_BILLC1.RPT
/Creator
PScript5.dll Version 5.2.2
/Author
dipak
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD016EBB01
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 6 0
#Stream obj 5 0
#Stream obj 5 0-preview.png
#Stream obj 279 0
#Stream obj 282 0
#Stream obj 283 0
#Stream obj 286 0
#Stream obj 287 0
#Stream obj 290 0
#Stream obj 291 0
#Stream obj 294 0
#Stream obj 10 0
oleObject1.bin
Root Entry
Ole10Native
Text (Preview)
#Stream obj 13 0
#Stream obj 12 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 5 0
Structure
PDF @0x000000E0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD016EBB02
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 HtTp:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙