Suspicious
Suspect

a0fc1d4d47153bc202b0bf581267f53b

MS Office Document
MD5: a0fc1d4d47153bc202b0bf581267f53b
Size: 795.65 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 a0fc1d4d47153bc202b0bf581267f53b
Sha1 85a767adcc2bcbda4236148889271105a45a8aa4
Sha256 200ff75f2ffd6488ac25ac5cdb4552a1d2dc321f36a398e3d648e9531769b93e
Sha384 ebb79a41e4f1c7161e14dc501c235a2963eb9423da5978941b105081aebeaf9f9fc2f036be1926d7b54aa2ada21fbef3
Sha512 12b75d7f481782f26703385f2d902d6c966e109bfce7813eeaa381b01204a2115ac59a5ab0184d0ec91d0664aff882b53e33074f32fbd191aa6d3cdcd1d5c2d8
SSDeep 12288:2UyIOrEuY8GkUlDRsJ47/ps0GzldCtri711OS2xkVczSWMwmXVildfPNXm:yIO4uY+2DRY4YWi711OS6kV9ildfPNX
TLSH 97052311EBD0BBEBD1666470471E8659E88ECE3EEF92B0876314745E78733F26382458
a0fc1d4d47153bc202b0bf581267f53b
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002557E3
Ole
MBD00263149
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
media
image3.emf
image2.emf
image1.emf
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
embeddings
oleObject3.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 7 0
#Stream obj 6 0
#Stream obj 20 0
#Stream obj 19 0
#Stream obj 19 0-preview.png
#Stream obj 21 0
#Stream obj 47 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 4 0
#Stream obj 52 0
#Stream obj 34 0
#Stream obj 54 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 5 0
#Stream obj 19 0
#Stream obj 25 0
#Stream obj 31 0
#Stream obj 37 0
#Stream obj 44 0
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 4 0
#Stream obj 5 0
printerSettings
printerSettings1.bin
docProps
core.xml
app.xml
CompObj
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 10 STICH kept: 1secondary ignored: 9
bin 4img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260812045945-04'00'
ModifiedDate
D:20260812045945-04'00'
Producer
Artifex Ghostscript 10.01.2
Version
1.7
Author
TANG Yi Bing [KCL-GCC]
CreationDate
D:20231109115441+08'00'
Creator
Microsoft® PowerPoint® for Microsoft 365
ModifiedDate
D:20231109115441+08'00'
Title
PowerPoint Presentation
Producer
Microsoft® PowerPoint® for Microsoft 365
Version
1.4
CreationDate
D:20260518104728+02'00'
Creator
RICOH IM 2702
ModifiedDate
D:20260518104728+02'00'
Producer
RICOH IM 2702
/CreationDate
D:20260518104728+02'00'
/ModDate
D:20260518104728+02'00'
/Creator
RICOH IM 2702
/Producer
RICOH IM 2702
/Title
PowerPoint Presentation
/Author
TANG Yi Bing [KCL-GCC]
/CreationDate
D:20231109115441+08'00'
/ModDate
D:20231109115441+08'00'
/Producer
Microsoft® PowerPoint® for Microsoft 365
/Creator
Microsoft® PowerPoint® for Microsoft 365
/Producer
Artifex Ghostscript 10.01.2
/CreationDate
D:20260812045945-04'00'
/ModDate
D:20260812045945-04'00'
URI URI
mailtohuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
a0fc1d4d47153bc202b0bf581267f53b
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002557E3
Ole
MBD00263149
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
media
image3.emf
image2.emf
image1.emf
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
embeddings
oleObject3.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 7 0
#Stream obj 6 0
#Stream obj 20 0
#Stream obj 19 0
#Stream obj 19 0-preview.png
#Stream obj 21 0
#Stream obj 47 0
#Stream obj 46 0
#Stream obj 51 0
#Stream obj 4 0
#Stream obj 52 0
#Stream obj 34 0
#Stream obj 54 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 8 0
#Stream obj 43 0
#Stream obj 40 0
#Stream obj 41 0
#Stream obj 5 0
#Stream obj 19 0
#Stream obj 25 0
#Stream obj 31 0
#Stream obj 37 0
#Stream obj 44 0
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 4 0
#Stream obj 5 0
printerSettings
printerSettings1.bin
docProps
core.xml
app.xml
CompObj
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URI URI
mailtohuhuhuhuhuhuhuhuhuhuhu
a0fc1d4d47153bc202b0bf581267f53b › Root Entry › MBD00263149 › Package › xl › embeddings › oleObject3.bin › Root Entry › CONTENTS
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙