Malicious
Malicious

de7cc15f7205e07a0ec61c8b67cc5e07

Share on LinkedIn
Print
MS Office Document
MD5: de7cc15f7205e07a0ec61c8b67cc5e07
Size: 270.85 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 de7cc15f7205e07a0ec61c8b67cc5e07
Sha1 374d632ae421c74355c2b1f114571f56e62c3a2d
Sha256 f26ae78b51e068d1323bdd1c74d55db2679ea2be2e609eb451d0dd4ca0a742cf
Sha384 58167a96189304b281923c48b2c20af784d2015b0910e0a71f05c0e70907b06cd3e1d56a87871f9967662981c31f7fad
Sha512 5afe363ea4c20f53bf16c03fefa862c413861adce35dd705e336337428db6c9d30d069bb7cd0a1650ddbcaf5ec2e2b2e9e19520e2ae701b36ec28833807ab307
SSDeep 6144:pJvfaSouVqlUrjY6o0NmlEgN+AjK/al8BmXZWfG0YciBld9h:pVfavl36Dmln+Y0mXZKylr
TLSH 434412667607D48DD5A50836D6CD90DAEA29BCC29944DF0F3B80F32E3C736E5DB26608
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD014E11D5
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet3.xml.rels
sheet2.xml
sheet3.xml
sheet1.xml
media
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
image1.png
image1.png-preview.png
image3.emf
image2.emf
image4.png
image4.png-preview.png
drawings
drawing4.xml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
drawing4.xml.rels
drawing3.xml.rels
drawing2.xml.rels
drawing3.xml
vmlDrawing1.vml
drawing1.xml
drawing2.xml
theme
theme1.xml
embeddings
oleObject1.bin
Root Entry
Ole10Native
PDF @0x000000C8
sharedStrings.xml
styles.xml
printerSettings
printerSettings2.bin
printerSettings4.bin
customXml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item1.xml
item3.xml
itemProps2.xml
item2.xml
itemProps1.xml
itemProps3.xml
docProps
thumbnail.wmf
core.xml
app.xml
custom.xml
CompObj
MBD014E11D6
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>pdf>pdf
Shape ole:doc>oox:xlsx>oox:media>pdf>pdf
malicious 5 nodes
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>img
Shape ole:doc>oox:xlsx>oox:media>img
malicious 4 nodes
Config. Field Value
URL distante (OLE moniker) #1 HttP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙