Malicious
Malicious

PDF @0x00000000

Share on LinkedIn
Print
MS Office Document
MD5: ccdb61148960b94f52b40592f03af119
Size: 921.09 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ccdb61148960b94f52b40592f03af119
Sha1 c90ceef8e350611afb26eddbe46061352ccd7646
Sha256 77d1ccd3b57dea0ff34ee568a1027cd8ea74f14f3580acbc0aba8587f96f7a6c
Sha384 6ae6c209cb5bf62a0ef6a49f479a024c595ef7af15eae7a7b5edbe8d7a99345fe6881e42b7092eea373bf7b7fd4a0799
Sha512 0856e7e23ec6dcde22efe689b223b4f02b33d23d4cb150f1e0c2bf6a25967c9862c17cecd39eb41a9ef2dc07f3411ea1a372f6ac48758d07e9da789c1c96ae40
SSDeep 24576:CKpt1QRT/64rm4u1UiVN37YWczoyf9KDYgWikRMHRU2/Z:CKptmB6au19v37YWczok2YgWEHGQ
TLSH 78151211FF805476C9825B390FA3A6D1D90CBC5B9E6A0F0A27897339783B7F4D962C16
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD003B86FE
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD003B86FF
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD003B8700
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 12 STICH kept: 2secondary ignored: 10
bin 5img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260731145050-04'00
Creator
Mozilla Firefox 153.0.1
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 153.0.1
/CreationDate
D:20260731145050-04'00
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙