Suspicious
Suspect

fb6a0273b99a9a2e93e005ef41e351aa

Share on LinkedIn
Print
MS Office Document
MD5: fb6a0273b99a9a2e93e005ef41e351aa
Size: 889.34 KB
application/vnd.ms-office

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fb6a0273b99a9a2e93e005ef41e351aa
Sha1 9e623209eddd234216c05b2c47edd8bd48531425
Sha256 118e07b4e4c4dd181db7c257495788b5f6a85fff0044d569e6f4fc19077c871c
Sha384 05881b8ee9cfb652426160fb0f82313a9bcb5efd19d4be8b68fb39b27827d805041058be98f4e6578e5aa95556c30c13
Sha512 1bb7f3e00759c92db8d3cbf6194b28cc8eea0250dc43bb80a59c904c350f800a15301b88f0af7f43382489c744d38e13dcff8812c3b6c75cdd228cfd3e11bb21
SSDeep 12288:o9YomKc2uOi9ck5rN9Eg9oEhMgcNWk2lU9BXYzikeT1uGnlEneImO3nZrGzb9FZ:UU19FEDgcl9Bzpn2/xJrGX9FZ
TLSH B315231EBC899A27E173187A85CAC4878B0FBE43AE07DFFA2750770A153E69049DF015
fb6a0273b99a9a2e93e005ef41e351aa
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD001F8214
xl
workbook.xml
drawings
vmlDrawing1.vml
worksheets
sheet1.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
CONTENTS
Text (Preview)
#Stream obj 5 0
#Stream obj 6 0
#Stream obj 4 0
#Stream obj 234 0
#Stream obj 237 0
#Stream obj 238 0
#Stream obj 241 0
#Stream obj 242 0
#Stream obj 245 0
#Stream obj 11 0
#Stream obj 249 0
docProps
core.xml
CompObj
MBD001F8215
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
drawings
_rels
vmlDrawing1.vml.rels
vmlDrawing1.vml
worksheets
_rels
sheet1.xml.rels
sheet1.xml
theme
theme1.xml
styles.xml
media
image1.emf
embeddings
oleObject1.bin
Root Entry
Ole
CompObj
CONTENTS
#Stream obj 28 0
#Stream obj 24 0
#Stream obj 25 0
#Stream obj 34 0
#Stream obj 30 0
#Stream obj 31 0
#Stream obj 10 0
#Stream obj 5 0
#Stream obj 11 0
#Stream obj 16 0
#Stream obj 18 0
#Stream obj 21 0
#Stream obj 7 0
Structure
printerSettings
printerSettings1.bin
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
MBD001F8216
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 1secondary ignored: 8
bin 4oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>oox:xlsx>oox:media>ole:doc
Shape ole:doc>oox:xlsx>oox:media>ole:doc
4 nodes
Config. Field Value
URL #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Version
1.4
CreationDate
D:20220603065428-04'00'
Creator
Apache FOP Version 1.0
Producer
Apache FOP Version 1.0
/Creator
Apache FOP Version 1.0
/Producer
Apache FOP Version 1.0
/CreationDate
D:20220603065428-04'00'
Version
1.4
CreationDate
D:20260627193553+00'00'
Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
ModifiedDate
D:20260702085124-06'00'
Title
Transferencias Internacionales
Producer
Skia/PDF m149
/Title
Transferencias Internacionales
/Creator
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
/Producer
Skia/PDF m149
/CreationDate
D:20260627193553+00'00'
/ModDate
D:20260702085124-06'00'
An error has occurred. This application may no longer respond until reloaded. Reload 🗙