Malicious
0779f13e0573421bdead715549529fef
MS Excel Document
MD5: 0779f13e0573421bdead715549529fef
Size: 845.43 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 0779f13e0573421bdead715549529fef |
| Sha1 | 6018f0e70d150c320e05910895baad14e65172d8 |
| Sha256 | b88c6e388d6ab7702dd19df4196efa75f3e029d46d03873798fee3444d2d0be8 |
| Sha384 | 510d2923e64f08ee9b773bf00f43ff8fad2a20bbacb5a758d0ef9d82639fff829ad1cd7f78581eae97884d41362c8f53 |
| Sha512 | 81d360cbb896ce89b1904cf34667526d74caa150cedfd8755892668f008d6c57b91d9925ff46f7d46b5954f13fc894df21e4fc2d18def9ca51e4e2d013241ed8 |
| SSDeep | 24576:UMGRs5g55R9dBWZ5UZquALfLqN9cSYW0ZFje:ERsgDC9LoWY |
| TLSH | 4E05121F4F0C6849D4AAC3B8E63C97D9540CB3AA8050FC5D2084B9ED6FE1BA6974929D |
Malicious
ModHojaC101
ModHojaC700
ThisWorkbook
LoginUserForm
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
11 / 11
Path
oox:xlsm~T1027~T1059.005>oox:media>img
Shape
oox:xlsm>oox:media>img
technique3 nodes
Path
oox:xlsm~T1027~T1059.005>bin
Shape
oox:xlsm>bin
technique2 nodes
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
ModHojaC101
ModHojaC700
ThisWorkbook
LoginUserForm
No malware configuration was found at this point.
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › Hoja7 › [Decompiled VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › Hoja7 › [Stored VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.