Malicious
Malicious

036f4745135f0dc3a0659756f7cbd583

MS Word Document
MD5: 036f4745135f0dc3a0659756f7cbd583
Size: 135.05 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 036f4745135f0dc3a0659756f7cbd583
Sha1 abeea0b165d641c15cea825c9d5aa7acd8129a14
Sha256 05fdec10ee1d5869d422ffdeeec305a56b291f1db016c9df56cbdd1bd95c7e08
Sha384 7a7416b53e2dafb3f3f1da91636c6afdeb35093a0d081e47db7d73702fb8053bb7f44f279ec4a6342b582a6fb384ffd7
Sha512 3b3d4f177bcd0e103532dfc25831ffd4a5f2986816b1d53d94ac396517c301aced4b3c0ee448a9e1e5490ffaa338a455697f7965b23019587161b0371a82ae45
SSDeep 3072:VufzpAwbKVeggHYqHfJDujl6zYMXjHOK4EdeYgUb1WL1JPDr:5wbKW5le4fOK4E92nr
TLSH 8FD3CFB7E362C90FCB4501325DABBF79866734C4A2941B1B1897F8685F43BC236A974C
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
vbaProject.bin
Malicious
media
image1.png
image1.png-preview.png
theme
theme1.xml
settings.xml
vbaData.xml
fontTable.xml
stylesWithEffects.xml
webSettings.xml
styles.xml
docProps
app.xml
core.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path oox:docm~T1059.005>oox:vba~T1027~T1059~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape oox:docm>oox:vba>scr:bat>scr:ps1
malicious 4 nodes
Path oox:docm~T1059.005>oox:media>img
Shape oox:docm>oox:media>img
technique3 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
CMd /chuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
ms^ie^huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
vbaProject.bin
Malicious
media
image1.png
image1.png-preview.png
theme
theme1.xml
settings.xml
vbaData.xml
fontTable.xml
stylesWithEffects.xml
webSettings.xml
styles.xml
docProps
app.xml
core.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
J2r2hVO_
Blacklist VBA
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

ThisDocument
VBA Macro
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
CMd /chuhuhuhuhuhuhuhuhuhuhu
036f4745135f0dc3a0659756f7cbd583 › word › vbaProject.bin › Root Entry › VBA › J2r2hVO_ › [Stored VBA]
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
036f4745135f0dc3a0659756f7cbd583 › word › vbaProject.bin › Root Entry › VBA › J2r2hVO_ › [Stored VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
036f4745135f0dc3a0659756f7cbd583 › word › vbaProject.bin › Root Entry › VBA › J2r2hVO_ › [Stored VBA]
Deobfuscated PowerShell UNKNWOWNmalicious
ms^ie^huhuhuhuhuhuhuhuhuhuhu
036f4745135f0dc3a0659756f7cbd583 › word › vbaProject.bin › Root Entry › VBA › J2r2hVO_ › [Stored VBA] › [Stored VBA].deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙