Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0779f13e0573421bdead715549529fef
Sha1 6018f0e70d150c320e05910895baad14e65172d8
Sha256 b88c6e388d6ab7702dd19df4196efa75f3e029d46d03873798fee3444d2d0be8
Sha384 510d2923e64f08ee9b773bf00f43ff8fad2a20bbacb5a758d0ef9d82639fff829ad1cd7f78581eae97884d41362c8f53
Sha512 81d360cbb896ce89b1904cf34667526d74caa150cedfd8755892668f008d6c57b91d9925ff46f7d46b5954f13fc894df21e4fc2d18def9ca51e4e2d013241ed8
SSDeep 24576:UMGRs5g55R9dBWZ5UZquALfLqN9cSYW0ZFje:ERsgDC9LoWY
TLSH 4E05121F4F0C6849D4AAC3B8E63C97D9540CB3AA8050FC5D2084B9ED6FE1BA6974929D
[Content_Types].xml
_rels
.rels
xl
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
sheet8.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
drawing10.xml
drawing2.xml
vmlDrawing1.vml
drawing11.xml
vmlDrawing10.vml
drawing12.xml
vmlDrawing11.vml
drawing3.xml
vmlDrawing2.vml
drawing4.xml
vmlDrawing3.vml
_rels
drawing1.xml.rels
drawing2.xml.rels
drawing3.xml.rels
drawing12.xml.rels
drawing5.xml
vmlDrawing4.vml
vmlDrawing9.vml
drawing6.xml
vmlDrawing5.vml
drawing7.xml
vmlDrawing6.vml
drawing8.xml
vmlDrawing7.vml
drawing9.xml
vmlDrawing8.vml
media
image1.png
image1.png-preview.png
image2.jpeg
image2.jpeg-preview.png
image3.jpeg
image3.jpeg-preview.png
image4.png
image4.png-preview.png
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
vbaProject.bin
Root Entry
PROJECT
PROJECTwm
VBA
dir
Hoja11
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
ModHojaC101
ModHojaC200
ModHojaC328
ModHojaC400
ModHojaC700
ModMatrices
ThisWorkbook
_VBA_PROJECT
LoginUserForm
LoginUserForm
f
o
CompObj
VBFrame
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings11.bin
printerSettings8.bin
printerSettings10.bin
ctrlProps
ctrlProp1.xml
calcChain.xml
comments1.xml
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path oox:xlsm~T1027~T1059.005>oox:media>img
Shape oox:xlsm>oox:media>img
technique3 nodes
Path oox:xlsm~T1027~T1059.005>bin
Shape oox:xlsm>bin
technique2 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
xl
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
sheet8.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
drawing10.xml
drawing2.xml
vmlDrawing1.vml
drawing11.xml
vmlDrawing10.vml
drawing12.xml
vmlDrawing11.vml
drawing3.xml
vmlDrawing2.vml
drawing4.xml
vmlDrawing3.vml
_rels
drawing1.xml.rels
drawing2.xml.rels
drawing3.xml.rels
drawing12.xml.rels
drawing5.xml
vmlDrawing4.vml
vmlDrawing9.vml
drawing6.xml
vmlDrawing5.vml
drawing7.xml
vmlDrawing6.vml
drawing8.xml
vmlDrawing7.vml
drawing9.xml
vmlDrawing8.vml
media
image1.png
image1.png-preview.png
image2.jpeg
image2.jpeg-preview.png
image3.jpeg
image3.jpeg-preview.png
image4.png
image4.png-preview.png
image6.png
image6.png-preview.png
image5.png
image5.png-preview.png
vbaProject.bin
Root Entry
PROJECT
PROJECTwm
VBA
dir
Hoja11
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
ModHojaC101
ModHojaC200
ModHojaC328
ModHojaC400
ModHojaC700
ModMatrices
ThisWorkbook
_VBA_PROJECT
LoginUserForm
LoginUserForm
f
o
CompObj
VBFrame
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings11.bin
printerSettings8.bin
printerSettings10.bin
ctrlProps
ctrlProp1.xml
calcChain.xml
comments1.xml
docProps
core.xml
app.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Hoja3
VBA Macro
Hoja5
VBA Macro
Hoja7
Blacklist VBA
VBA Macro
Hoja8
VBA Macro
Hoja9
VBA Macro
Hoja11
VBA Macro
mdAesCtr
Blacklist VBA
VBA Macro
ModHojaC101
VBA Macro
ModHojaC200
VBA Macro
ModHojaC328
VBA Macro
ModHojaC400
VBA Macro
ModHojaC700
VBA Macro
ModMatrices
VBA Macro
ThisWorkbook
VBA Macro
LoginUserForm
VBA Macro
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › Hoja7 › [Decompiled VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0779f13e0573421bdead715549529fef › xl › vbaProject.bin › Root Entry › VBA › Hoja7 › [Stored VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙