Malicious
Malicious

PDF @0x00000000

MS Office Document
MD5: c7025f4b92aeabdffe3524b98a38935b
Size: 920.58 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c7025f4b92aeabdffe3524b98a38935b
Sha1 a4af807f8d4a056b89f1b865f6ac6366d4be3e73
Sha256 ff2ca63ce0afe23545e57623af69aa39055f089501cfa524217588b2b7c06292
Sha384 b19fa8d1abc33222fc032cd1514586f8224c56cc90ba090a39ac4b7bd5e6c7a5e814d72e800b4c5cffd8f919ca67ba32
Sha512 a0e6a0f2bc53aeb055b1cffe8d3894c92589dcf83c197bc8c3026ca8794a6d3ad2ad11887cb79b2da447828ff4681cd9f16871780c9e36e05bdbc5f440fb23c5
SSDeep 24576:JKNt1QRT/64rmfu1UiVN4jtE9BmLf27XmEqq:JKNtmB6Bu19v4xE9By27Nq
TLSH BA151212FE808937CD5257380F53A2D1E21DBC6B9E6A9B0B1785337E783B6E4D952C06
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00370451
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD00370452
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00370453
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 12 STICH kept: 2secondary ignored: 10
bin 5img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260731145050-04'00
Creator
Mozilla Firefox 153.0.1
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 153.0.1
/CreationDate
D:20260731145050-04'00
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00370451
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD00370452
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD00370453
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
c7025f4b92aeabdffe3524b98a38935b › Root Entry › MBD00370452 › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙