Malicious
cb9e33fa2f0426c89933af0ab6829d40
MS Office Document
MD5: cb9e33fa2f0426c89933af0ab6829d40
Size: 667.65 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | cb9e33fa2f0426c89933af0ab6829d40 |
| Sha1 | 0d07f670e5b2bd63090d9fdd5a3b6b81013f5f81 |
| Sha256 | acae59daae55ace98a8be92598521c4ab4c87147e43162f53c48440f2df6783c |
| Sha384 | 9d4cfb4fdc027623cc15281823c2272750efb8de9852afbf23ffdd7aa4f9127a9bed92259549fa7f98ec401d392a4c8d |
| Sha512 | 5357832b4fb40a79dc5b600764d6a0cd34107a07dadf7dc3014c6eb453e8a88a54e9ba6804b4edf49b55eb76d03e842a437a14a16f272029135a54e302ffff6a |
| SSDeep | 12288:QvhhJdOtOsGbNNN2bBpvUEufRYvQlX0S5ihucv7SrLPISnFQilih1Eq/A2G:QvhItjGKr3QXiscv7OtFJUnA2G |
| TLSH | 8DE41244F4D0AE27C6FD24B139D094C2467BBC19CA16ED4B2D413BFC3A32AB7585A1AD |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
9 / 9
Path
ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape
ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious
6 nodes
Path
ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape
ole:doc>oox:xlsx>oox:media>bin
malicious
4 nodes
| Config. Field | Value |
|---|---|
| URL distante (OLE moniker) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.3 |
| CreationDate | D:20260501062429-07'00' |
| ModifiedDate | D:20260501062430-07'00' |
| Producer | http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M |
| Version | 1.7 |
| CreationDate | D:20261003110002+02'00' |
| ModifiedDate | D:20261003110002+02'00' |
| Title | Remote Desktop Redirected Printer Doc |
| Producer | Microsoft: Print To PDF |
| /CreationDate | D:20261003110002+02'00' |
| /ModDate | D:20261003110002+02'00' |
| /Producer | Microsoft: Print To PDF |
| /Title | Remote Desktop Redirected Printer Doc |
| /Producer | http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M |
| /CreationDate | D:20260501062429-07'00' |
| /ModDate | D:20260501062430-07'00' |
| Config. Field | Value |
|---|---|
| URL distante (OLE moniker) #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.