Malicious
Malicious

cb9e33fa2f0426c89933af0ab6829d40

Share on LinkedIn
Print
MS Office Document
MD5: cb9e33fa2f0426c89933af0ab6829d40
Size: 667.65 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cb9e33fa2f0426c89933af0ab6829d40
Sha1 0d07f670e5b2bd63090d9fdd5a3b6b81013f5f81
Sha256 acae59daae55ace98a8be92598521c4ab4c87147e43162f53c48440f2df6783c
Sha384 9d4cfb4fdc027623cc15281823c2272750efb8de9852afbf23ffdd7aa4f9127a9bed92259549fa7f98ec401d392a4c8d
Sha512 5357832b4fb40a79dc5b600764d6a0cd34107a07dadf7dc3014c6eb453e8a88a54e9ba6804b4edf49b55eb76d03e842a437a14a16f272029135a54e302ffff6a
SSDeep 12288:QvhhJdOtOsGbNNN2bBpvUEufRYvQlX0S5ihucv7SrLPISnFQilih1Eq/A2G:QvhItjGKr3QXiscv7OtFJUnA2G
TLSH 8DE41244F4D0AE27C6FD24B139D094C2467BBC19CA16ED4B2D413BFC3A32AB7585A1AD
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD000116E2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
styles.xml
theme
theme1.xml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
media
image2.emf
image1.emf
embeddings
oleObject2.bin
Root Entry
Ole
CompObj
CONTENTS
Text (Preview)
#Stream obj 20 0
#Stream obj 8 0
#Stream obj 10 0
#Stream obj 16 0
#Stream obj 18 0
Structure
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 3 0
#Stream obj 21 0
#Stream obj 17 0
#Stream obj 32 0
#Stream obj 18 0
#Stream obj 39 0
#Stream obj 40 0
#Stream obj 50 0
#Stream obj 41 0
#Stream obj 26 0
#Stream obj 48 0
#Stream obj 45 0
#Stream obj 10 0
#Stream obj 19 0
#Stream obj 9 0
printerSettings
printerSettings1.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD000116E3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf:stream>bin
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf:stream>bin
malicious 6 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>bin
Shape ole:doc>oox:xlsx>oox:media>bin
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.3
CreationDate
D:20260501062429-07'00'
ModifiedDate
D:20260501062430-07'00'
Producer
http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M
Version
1.7
CreationDate
D:20261003110002+02'00'
ModifiedDate
D:20261003110002+02'00'
Title
Remote Desktop Redirected Printer Doc
Producer
Microsoft: Print To PDF
/CreationDate
D:20261003110002+02'00'
/ModDate
D:20261003110002+02'00'
/Producer
Microsoft: Print To PDF
/Title
Remote Desktop Redirected Printer Doc
/Producer
http://bfo.com/products/report?version=bforeport-ns-1.2.10-r47746M
/CreationDate
D:20260501062429-07'00'
/ModDate
D:20260501062430-07'00'
An error has occurred. This application may no longer respond until reloaded. Reload 🗙