Suspect
MS Office Document
MD5: db9ff235eae552276b12622ae9105f1c
Size: 1.04 MB
application/vnd.ms-office
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | db9ff235eae552276b12622ae9105f1c |
| Sha1 | f0e45e139ddddfb654f645c935e8e84f7812ae2b |
| Sha256 | 08d96f4f4e6bd0e23f5374936d2afe823cb5f3d7e6a1b064308038becfdcf25d |
| Sha384 | 15e358c9838cdd115c58767cd2b531ed56e53c8878b05a33aea58c9e33612b1c6668060e65551bdbce78fdf2f52c87cb |
| Sha512 | cb01d6fbc94ae6b5d8887b7f9e90438eea069ed6c87db0c5acb8b02bdb5a3f2b8ba5140d00c6a174f279ec14578621e61b620c72a529dfad42b647251326264b |
| SSDeep | 24576:kfMMUKNioqK7t1QRT/64rmBVJjkaQt7ffZ+sfBkqS:0eKN2K7tmB6j7jkaYM |
| TLSH | C525F112EF415976C94243310BA772C1E21CEC7BAE2A4D0E2749733A6D776E4E973D0A |
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #3 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL #4 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.6 |
| Producer | Oracle BI Publisher 12.2.1.4.0 |
| /Producer | Oracle BI Publisher 12.2.1.4.0 |
| Version | 1.7 |
| CreationDate | D:20260731145050-04'00 |
| Creator | Mozilla Firefox 153.0.1 |
| Producer | cairo 1.18.4 (https://cairographics.org) |
| /Producer | cairo 1.18.4 (https://cairographics.org) |
| /Creator | Mozilla Firefox 153.0.1 |
| /CreationDate | D:20260731145050-04'00 |