Malicious
MS Excel Document
MD5: 068646c0636f8ae1c10f96abceeab373
Size: 1.26 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 068646c0636f8ae1c10f96abceeab373 |
| Sha1 | 9d6c34ef503d0023676c11d995375c179afe34ea |
| Sha256 | 42c83d1ac53b0b777fdb9b328cbbaaeb4de74335a06370b615cc88efe82fcf47 |
| Sha384 | 2d23dcb1a44dd86fcd83842adb002dd5b305bd6e4cb96576e3267e610188824073f077f53cfb637258213bf6dce1d48f |
| Sha512 | 6da02f27d4891dd6d990b74e3cc2b040b5348d97f87393835fbed2501b9d650adbd8a42aad207ae76e17beabaa93393b6b5c5104a803f685fcb2cb738ffd5b0d |
| SSDeep | 24576:p4K4ZBUmOprUKrVS5rOrkndZODjC+J9yQ5niqBWZ5UZquALq/yRmlq3wk3kfJtff:gUHrUKrVS5rOrkndZODv95bC9Lq/40fv |
| TLSH | 1B45012D019B4D49CA71D7B4868EC4D248DCAF3D2683641DC64E7BACFB63A1B123D29D |
Malicious
ModCapitulo4
ModCapitulo5
ModCapitulo6
ModCapitulo7
ModCapitulo8
ModCapitulo9
ThisWorkbook
LoginUserForm
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
12 / 12
Path
oox:xlsm~T1027~T1059.005>oox:media>img
Shape
oox:xlsm>oox:media>img
technique3 nodes
Path
oox:xlsm~T1027~T1059.005>bin
Shape
oox:xlsm>bin
technique2 nodes
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential