Suspect
fb6a0273b99a9a2e93e005ef41e351aa
MS Office Document
MD5: fb6a0273b99a9a2e93e005ef41e351aa
Size: 889.34 KB
application/vnd.ms-office
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | fb6a0273b99a9a2e93e005ef41e351aa |
| Sha1 | 9e623209eddd234216c05b2c47edd8bd48531425 |
| Sha256 | 118e07b4e4c4dd181db7c257495788b5f6a85fff0044d569e6f4fc19077c871c |
| Sha384 | 05881b8ee9cfb652426160fb0f82313a9bcb5efd19d4be8b68fb39b27827d805041058be98f4e6578e5aa95556c30c13 |
| Sha512 | 1bb7f3e00759c92db8d3cbf6194b28cc8eea0250dc43bb80a59c904c350f800a15301b88f0af7f43382489c744d38e13dcff8812c3b6c75cdd228cfd3e11bb21 |
| SSDeep | 12288:o9YomKc2uOi9ck5rN9Eg9oEhMgcNWk2lU9BXYzikeT1uGnlEneImO3nZrGzb9FZ:UU19FEDgcl9Bzpn2/xJrGX9FZ |
| TLSH | B315231EBC899A27E173187A85CAC4878B0FBE43AE07DFFA2750770A153E69049DF015 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 9
STICH kept: 1secondary ignored: 8
bin
4oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
ole:doc>oox:xlsx>oox:media>ole:doc
Shape
ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Version | 1.4 |
| CreationDate | D:20220603065428-04'00' |
| Creator | Apache FOP Version 1.0 |
| Producer | Apache FOP Version 1.0 |
| /Creator | Apache FOP Version 1.0 |
| /Producer | Apache FOP Version 1.0 |
| /CreationDate | D:20220603065428-04'00' |
| Version | 1.4 |
| CreationDate | D:20260627193553+00'00' |
| Creator | |
| ModifiedDate | D:20260702085124-06'00' |
| Title | Transferencias Internacionales |
| Producer | Skia/PDF m149 |
| /Title | Transferencias Internacionales |
| /Creator | |
| /Producer | Skia/PDF m149 |
| /CreationDate | D:20260627193553+00'00' |
| /ModDate | D:20260702085124-06'00' |
| Config. Field | Value |
|---|---|
| URL #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.