Suspicious
Suspect

fb6a0273b99a9a2e93e005ef41e351aa

MS Office Document
MD5: fb6a0273b99a9a2e93e005ef41e351aa
Size: 889.34 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fb6a0273b99a9a2e93e005ef41e351aa
Sha1 9e623209eddd234216c05b2c47edd8bd48531425
Sha256 118e07b4e4c4dd181db7c257495788b5f6a85fff0044d569e6f4fc19077c871c
Sha384 05881b8ee9cfb652426160fb0f82313a9bcb5efd19d4be8b68fb39b27827d805041058be98f4e6578e5aa95556c30c13
Sha512 1bb7f3e00759c92db8d3cbf6194b28cc8eea0250dc43bb80a59c904c350f800a15301b88f0af7f43382489c744d38e13dcff8812c3b6c75cdd228cfd3e11bb21
SSDeep 12288:o9YomKc2uOi9ck5rN9Eg9oEhMgcNWk2lU9BXYzikeT1uGnlEneImO3nZrGzb9FZ:UU19FEDgcl9Bzpn2/xJrGX9FZ
TLSH B315231EBC899A27E173187A85CAC4878B0FBE43AE07DFFA2750770A153E69049DF015
fb6a0273b99a9a2e93e005ef41e351aa
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001F8214
xl
workbook.xml
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD001F8215
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD001F8216
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20220603065428-04'00'
Creator
Apache FOP Version 1.0
Producer
Apache FOP Version 1.0
/Creator
Apache FOP Version 1.0
/Producer
Apache FOP Version 1.0
/CreationDate
D:20220603065428-04'00'
Version
1.4
CreationDate
D:20260627193553+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
ModifiedDate
D:20260702085124-06'00'
Title
Transferencias Internacionales
Producer
Skia/PDF m149
/Title
Transferencias Internacionales
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
/Producer
Skia/PDF m149
/CreationDate
D:20260627193553+00'00'
/ModDate
D:20260702085124-06'00'
fb6a0273b99a9a2e93e005ef41e351aa
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001F8214
xl
workbook.xml
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD001F8215
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD001F8216
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙