Suspicious
Suspect

PDF @0x00000000

MS Office Document
MD5: db9ff235eae552276b12622ae9105f1c
Size: 1.04 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 db9ff235eae552276b12622ae9105f1c
Sha1 f0e45e139ddddfb654f645c935e8e84f7812ae2b
Sha256 08d96f4f4e6bd0e23f5374936d2afe823cb5f3d7e6a1b064308038becfdcf25d
Sha384 15e358c9838cdd115c58767cd2b531ed56e53c8878b05a33aea58c9e33612b1c6668060e65551bdbce78fdf2f52c87cb
Sha512 cb01d6fbc94ae6b5d8887b7f9e90438eea069ed6c87db0c5acb8b02bdb5a3f2b8ba5140d00c6a174f279ec14578621e61b620c72a529dfad42b647251326264b
SSDeep 24576:kfMMUKNioqK7t1QRT/64rmBVJjkaQt7ffZ+sfBkqS:0eKN2K7tmB6j7jkaYM
TLSH C525F112EF415976C94243310BA772C1E21CEC7BAE2A4D0E2749733A6D776E4E973D0A
db9ff235eae552276b12622ae9105f1c
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D6FD3
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00277360
Ole
CompObj
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
MBD002D6FD4
Workbook
SummaryInformation
MBD00233248
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD002D6FD5
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Version
1.7
CreationDate
D:20260731145050-04'00
Creator
Mozilla Firefox 153.0.1
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 153.0.1
/CreationDate
D:20260731145050-04'00
db9ff235eae552276b12622ae9105f1c
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D6FD3
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00277360
Ole
CompObj
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
MBD002D6FD4
Workbook
SummaryInformation
MBD00233248
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD002D6FD5
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙