Malicious
Malicious

PDF @0x00000000

MS Office Document
MD5: dadb0456537c460844da74dc5609a753
Size: 920.58 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dadb0456537c460844da74dc5609a753
Sha1 535f77b77f9ec4ffb8da65fe76872baa83c7764c
Sha256 35dfd49d00dbd9fdec834dcc8627738562e5a58717b72525cd21bb729cee4980
Sha384 8777905a4d118164a1675ec371f9fd1c141c33e4b8848892846250cd01b9979750c0953a969739cd274bf6bcd478560a
Sha512 be85a7b70a36e5d4f3662e814eb2493da1387e209d17ae2e98034837dbca3ea68d5089c04303234d4abaa7774b69cae83966bc517f856f2b87042476d0a125b4
SSDeep 24576:hKpt1QRT/64rmNu1UiVN6BPiWjb8MSsS:hKptmB6Lu19voPiw8fsS
TLSH 24151212FE804837C992973C0F5366D1E61DEC6B9E2A4E0A578533797C3B6F4E9A2C05
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0037A896
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD0037A897
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD0037A898
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 12 STICH kept: 2secondary ignored: 10
bin 5img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:rel:ext~T1221
Shape ole:doc>oox:xlsx>oox:rel:ext
technique3 nodes
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.7
CreationDate
D:20260731145050-04'00
Creator
Mozilla Firefox 153.0.1
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 153.0.1
/CreationDate
D:20260731145050-04'00
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD0037A896
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00233248
Ole
CompObj
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
MBD0037A897
Malicious
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
media
image1.emf
sharedStrings.xml
embeddings
oleObject1.bin
Root Entry
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
Structure
printerSettings
printerSettings1.bin
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
docProps
core.xml
app.xml
CompObj
MBD0037A898
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
dadb0456537c460844da74dc5609a753 › Root Entry › MBD0037A897 › Package › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙