Suspicious
Suspect

c66ea2495dde3c04e8e1aa5e9a6b8391

Share on LinkedIn
Print
MS Office Document
MD5: c66ea2495dde3c04e8e1aa5e9a6b8391
Size: 1.18 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c66ea2495dde3c04e8e1aa5e9a6b8391
Sha1 9866b046da40c5881ab076f6a5705744650fbd0f
Sha256 73eb38a53b7c32603f6bd22b67c8fcfd19ef5f6a05f7dd1a648082a8cc5eaac4
Sha384 68df336df1e4b449a219c40e42e91194910db99c1a6145c9862d250712ce90956a1d199e0373ba395622bdf641ada189
Sha512 18b41b3f13f7a3c6829baa744156bcf36c50d44f54eaae562655e3d1ace8e59f1a98e7f32a9f6478d9eb92d62e70c96711a7ea2b4a362413618f1422286d4f10
SSDeep 24576:fWp/4edodG1sxxcR8tApcJ19EGVEnuXowldgHc9t8oQFiKOiM2/3:fWplwg8thsuYwc4Qne2/3
TLSH 9C452303DA072B3FD1231632C487D4965E1AAE1BBA199FA74B00B309767A7F167E740D
c66ea2495dde3c04e8e1aa5e9a6b8391
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002CBF5C
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet2.xml
sheet1.xml
theme
theme1.xml
sharedStrings.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 4 0
#Stream obj 20 0
#Stream obj 22 0
#Stream obj 25 0
#Stream obj 27 0
#Stream obj 30 0
#Stream obj 32 0
#Stream obj 35 0
#Stream obj 37 0
#Stream obj 40 0
#Stream obj 42 0
#Stream obj 45 0
#Stream obj 47 0
#Stream obj 51 0
#Stream obj 53 0
#Stream obj 56 0
#Stream obj 58 0
#Stream obj 61 0
#Stream obj 63 0
#Stream obj 66 0
#Stream obj 68 0
#Stream obj 17 0
#Stream obj 19 0
#Stream obj 76 0
printerSettings
printerSettings1.bin
customXml
item3.xml
_rels
item3.xml.rels
item2.xml.rels
item1.xml.rels
item1.xml
itemProps1.xml
item2.xml
itemProps3.xml
itemProps2.xml
docProps
core.xml
app.xml
custom.xml
CompObj
MBD002CBF5D
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 4 0
#Stream obj 12 0
#Stream obj 20 0
oleObject2.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD002CBF5E
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
URL #5 https:huhuhuhuhuhuhuhuhuhuhu
URL #6 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20260627193553+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
ModifiedDate
D:20260702085124-06'00'
Title
Transferencias Internacionales
Producer
Skia/PDF m149
/Title
Transferencias Internacionales
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
/Producer
Skia/PDF m149
/CreationDate
D:20260627193553+00'00'
/ModDate
D:20260702085124-06'00'
Version
1.7
CreationDate
D:20260715174319-04'00'
Creator
SQR for PeopleSoft/8.61.19/Intel/Red Hat Linux/Oracle/Mar 30 2026
Title
/psoft/tmp/PFIN/0000025437_DOT01.PDF
Producer
PDFlib 10.0.1p3-i (Linux-x64)
/Title
/psoft/tmp/PFIN/0000025437_DOT01.PDF
/Creator
SQR for PeopleSoft/8.61.19/Intel/Red Hat Linux/Oracle/Mar 30 2026
/CreationDate
D:20260715174319-04'00'
/Producer
PDFlib 10.0.1p3-i (Linux-x64)
Version
1.7
CreationDate
D:20260719140244+06'00
Creator
Mozilla Firefox 152.0.6
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 152.0.6
/CreationDate
D:20260719140244+06'00
An error has occurred. This application may no longer respond until reloaded. Reload 🗙