Malicious
Malicious

cb9e33fa2f0426c89933af0ab6829d40

MS Office Document
MD5: cb9e33fa2f0426c89933af0ab6829d40
Size: 667.65 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cb9e33fa2f0426c89933af0ab6829d40
Sha1 0d07f670e5b2bd63090d9fdd5a3b6b81013f5f81
Sha256 acae59daae55ace98a8be92598521c4ab4c87147e43162f53c48440f2df6783c
Sha384 9d4cfb4fdc027623cc15281823c2272750efb8de9852afbf23ffdd7aa4f9127a9bed92259549fa7f98ec401d392a4c8d
Sha512 5357832b4fb40a79dc5b600764d6a0cd34107a07dadf7dc3014c6eb453e8a88a54e9ba6804b4edf49b55eb76d03e842a437a14a16f272029135a54e302ffff6a
SSDeep 12288:QvhhJdOtOsGbNNN2bBpvUEufRYvQlX0S5ihucv7SrLPISnFQilih1Eq/A2G:QvhItjGKr3QXiscv7OtFJUnA2G
TLSH 8DE41244F4D0AE27C6FD24B139D094C2467BBC19CA16ED4B2D413BFC3A32AB7585A1AD
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD000116E2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 20 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 3 0
#Stream obj 21 0
#Stream obj 17 0
#Stream obj 32 0
#Stream obj 18 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 50 0
#Stream obj 41 0
#Stream obj 26 0
#Stream obj 48 0
#Stream obj 45 0
#Stream obj 10 0
#Stream obj 19 0
#Stream obj 9 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD000116E3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.3
CreationDate
D:20260501062429-07'00'
ModifiedDate
D:20260501062430-07'00'
Producer
http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M
Version
1.7
CreationDate
D:20261003110002+02'00'
ModifiedDate
D:20261003110002+02'00'
Title
Remote Desktop Redirected Printer Doc
Producer
Microsoft: Print To PDF
/CreationDate
D:20261003110002+02'00'
/ModDate
D:20261003110002+02'00'
/Producer
Microsoft: Print To PDF
/Title
Remote Desktop Redirected Printer Doc
/Producer
http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M
/CreationDate
D:20260501062429-07'00'
/ModDate
D:20260501062430-07'00'
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD000116E2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 20 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 3 0
#Stream obj 21 0
#Stream obj 17 0
#Stream obj 32 0
#Stream obj 18 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 50 0
#Stream obj 41 0
#Stream obj 26 0
#Stream obj 48 0
#Stream obj 45 0
#Stream obj 10 0
#Stream obj 19 0
#Stream obj 9 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD000116E3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙