Suspicious
Suspect

PDF @0x00000000

Share on LinkedIn
Print
MS Office Document
MD5: db9ff235eae552276b12622ae9105f1c
Size: 1.04 MB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 db9ff235eae552276b12622ae9105f1c
Sha1 f0e45e139ddddfb654f645c935e8e84f7812ae2b
Sha256 08d96f4f4e6bd0e23f5374936d2afe823cb5f3d7e6a1b064308038becfdcf25d
Sha384 15e358c9838cdd115c58767cd2b531ed56e53c8878b05a33aea58c9e33612b1c6668060e65551bdbce78fdf2f52c87cb
Sha512 cb01d6fbc94ae6b5d8887b7f9e90438eea069ed6c87db0c5acb8b02bdb5a3f2b8ba5140d00c6a174f279ec14578621e61b620c72a529dfad42b647251326264b
SSDeep 24576:kfMMUKNioqK7t1QRT/64rmBVJjkaQt7ffZ+sfBkqS:0eKN2K7tmB6j7jkaYM
TLSH C525F112EF415976C94243310BA772C1E21CEC7BAE2A4D0E2749733A6D776E4E973D0A
db9ff235eae552276b12622ae9105f1c
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD002D6FD3
Workbook
SummaryInformation
DocumentSummaryInformation
MBD00277360
Ole
CompObj
CONTENTS
#Stream obj 4 0
#Stream obj 14 0
#Stream obj 10 0
#Stream obj 47 0
#Stream obj 49 0
#Stream obj 52 0
#Stream obj 54 0
#Stream obj 63 0
#Stream obj 65 0
#Stream obj 68 0
#Stream obj 70 0
#Stream obj 73 0
#Stream obj 75 0
#Stream obj 13 0
#Stream obj 20 0
#Stream obj 78 0
#Stream obj 80 0
#Stream obj 83 0
#Stream obj 85 0
#Stream obj 57 0
#Stream obj 59 0
#Stream obj 26 0
#Stream obj 30 0
#Stream obj 34 0
#Stream obj 41 0
#Stream obj 44 0
#Stream obj 46 0
#Stream obj 93 0
MBD002D6FD4
Workbook
SummaryInformation
MBD00233248
CONTENTS
#Stream obj 13 0
#Stream obj 14 0
#Stream obj 5 0
#Stream obj 5 0.exif
#Stream obj 5 0-preview.png
#Stream obj 9 0
#Stream obj 6 0
#Stream obj 8 0
#Stream obj 17 0
Structure
MBD002D6FD5
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
URL #2 https:huhuhuhuhuhuhuhuhuhuhu
URL #3 https:huhuhuhuhuhuhuhuhuhuhu
URL #4 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.6
Producer
Oracle BI Publisher 12.2.1.4.0
/Producer
Oracle BI Publisher 12.2.1.4.0
Version
1.7
CreationDate
D:20260731145050-04'00
Creator
Mozilla Firefox 153.0.1
Producer
cairo 1.18.4 (https://cairographics.org)
/Producer
cairo 1.18.4 (https://cairographics.org)
/Creator
Mozilla Firefox 153.0.1
/CreationDate
D:20260731145050-04'00
An error has occurred. This application may no longer respond until reloaded. Reload 🗙