Suspicious
Suspect

b348f7ae41623fed7a3c9f46809ffe4d

Share on LinkedIn
Print
MS Office Document
MD5: b348f7ae41623fed7a3c9f46809ffe4d
Size: 814.08 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b348f7ae41623fed7a3c9f46809ffe4d
Sha1 dd03f24715e6961873204c735517724b1578ca17
Sha256 fcd959770e20be2a9d6ff33c27678f52e67940ac9f6d24fde9276e13fc8832b8
Sha384 2e8031eb64d3f3575c108ee530358e414ac95b8029d52f10b0df0498ae0d0a86f6a5c006feba24976590d6dbf6f9050c
Sha512 bd3cf37f7916efe8b29f4e9a20a94c5ae1e586f74593ec61823c197fc07ed4fde627cfb07c17ed96fcf7c516992fa3d23238962584b168b3f36e394c070bac42
SSDeep 12288:CxgRAPXRC5Ih55TEY3K+79QG0t0v/5T3N0WDsHTZGjXxwdpjvYdUIM3Hg5Q3IdSR:8gRA/EyXul0dP4HTMj+dpgUIGHg0IKR
TLSH A9052389F9E1FE1AC133957428C1C2D4D22EEDD1AE49E65F6A22B71D483127CA7C142B
b348f7ae41623fed7a3c9f46809ffe4d
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD003FA493
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet2.xml.rels
sheet1.xml.rels
sheet3.xml.rels
sheet5.xml.rels
sheet4.xml.rels
sheet2.xml
sheet3.xml
sheet5.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
vmlDrawing2.vml.rels
drawing4.xml
drawing1.xml
drawing2.xml
vmlDrawing1.vml
vmlDrawing2.vml
drawing3.xml
media
image4.emf
image3.emf
image1.png
image1.png-preview.png
image2.emf
embeddings
oleObject3.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 6 0
#Stream obj 7 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 21 0
#Stream obj 24 0
#Stream obj 27 0
#Stream obj 29 0
#Stream obj 28 0
#Stream obj 37 0
#Stream obj 51 0
#Stream obj 65 0
#Stream obj 79 0
#Stream obj 93 0
#Stream obj 107 0
#Stream obj 121 0
#Stream obj 135 0
#Stream obj 150 0
#Stream obj 164 0
oleObject1.bin
Root Entry
CompObj
CONTENTS
oleObject2.bin
Root Entry
CONTENTS
#Stream obj 6 0
#Stream obj 10 0
#Stream obj 11 0
#Stream obj 12 0
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 26 0
#Stream obj 26 0-preview.png
#Stream obj 40 0
#Stream obj 27 0
#Stream obj 41 0
#Stream obj 28 0
#Stream obj 42 0
#Stream obj 29 0
#Stream obj 44 0
#Stream obj 31 0
#Stream obj 45 0
#Stream obj 32 0
#Stream obj 47 0
#Stream obj 33 0
#Stream obj 34 0
#Stream obj 20 0
#Stream obj 21 0
#Stream obj 22 0
#Stream obj 23 0
#Stream obj 24 0
#Stream obj 36 0
#Stream obj 36 0-preview.png
#Stream obj 37 0
#Stream obj 37 0-preview.png
#Stream obj 38 0
Structure
sharedStrings.xml
styles.xml
theme
theme1.xml
printerSettings
printerSettings1.bin
printerSettings2.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD003FA494
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 11 STICH kept: 1secondary ignored: 10
bin 4img 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Name Value
Version
1.4
Author
City of Johannesburg
CreationDate
D:20260622150000+02'00'
Subject
Account Number : 556736545
Title
Tax Invoice
Version
1.7
Author
Absa Retail
CreationDate
D:20260622120032Z
Creator
DocFusion
ModifiedDate
D:20260622120032Z
Producer
DocFusion
/Creator
DocFusion
/ModDate
D:20260622120032Z
/CreationDate
D:20260622120032Z
/Producer
DocFusion
/Author
Absa Retail
URI URI
mailtohuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙