Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 09dcefea25c0b967f565483921822ab5
Sha1 baaa9825603dcac31a412e96f9682ae98d1a87df
Sha256 17d5547ebd2e3a9ef610bbee77eb9dbb4955f37f616867b086507c88a56bd219
Sha384 452295706c672aafbe9ff46acf855445acef1700d0df0c29ae2daf52ffcce3fab61e0330c0832e5451354e36a27758be
Sha512 a372dadf4914cc6bfb0669c878e171d6a68c94e50174a29baac1f5e66a3e33e405a842da6f413bb9aa69e4c1a6654670b2452632bf6bfd41a875bfbf7d385698
SSDeep 98304:Aco/a1bgynNaOiJyeFgOLl61aU3h5I2WF1YFK:X82bD4OiJyeFgOLl61aU3h5I2WX
TLSH C1F56CC3EF440090A818A5F55C93A3E2F896978E7F9FA15F9C45CE14B132039EA5E5CE
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.bin.rels
workbook.bin
worksheets
_rels
sheet16.bin.rels
sheet1.bin.rels
sheet2.bin.rels
sheet3.bin.rels
sheet4.bin.rels
sheet12.bin.rels
sheet13.bin.rels
sheet14.bin.rels
sheet15.bin.rels
sheet11.bin.rels
sheet10.bin.rels
sheet9.bin.rels
sheet5.bin.rels
sheet6.bin.rels
sheet7.bin.rels
sheet8.bin.rels
sheet2.bin
sheet1.bin
sheet12.bin
sheet10.bin
sheet6.bin
sheet13.bin
sheet7.bin
sheet9.bin
sheet8.bin
sheet5.bin
sheet14.bin
sheet11.bin
sheet15.bin
sheet3.bin
sheet16.bin
sheet4.bin
binaryIndex1.bin
binaryIndex16.bin
binaryIndex9.bin
binaryIndex10.bin
binaryIndex7.bin
binaryIndex2.bin
binaryIndex3.bin
binaryIndex4.bin
binaryIndex5.bin
binaryIndex6.bin
binaryIndex8.bin
binaryIndex13.bin
binaryIndex14.bin
binaryIndex15.bin
binaryIndex12.bin
binaryIndex11.bin
drawings
drawing6.xml
drawing5.xml
drawing4.xml
drawing3.xml
drawing1.xml
drawing2.xml
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
frmMST
TH_ALL
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
__SRP_2c
__SRP_2d
__SRP_2e
__SRP_2f
__SRP_30
__SRP_31
__SRP_32
__SRP_33
__SRP_34
__SRP_35
__SRP_36
__SRP_37
__SRP_38
__SRP_39
__SRP_3a
__SRP_3b
__SRP_3c
__SRP_3d
__SRP_3e
__SRP_3f
ThisWorkbook
_VBA_PROJECT
frmMST
f
o
CompObj
VBFrame
i01
f
o
CompObj
frmMain
f
VBFrame
i78
f
o
i107
f
o
x
CompObj
i49
f
CompObj
i184
f
o
i50
f
i126
f
o
i252
f
i321
f
o
i359
f
i361
f
o
i122
f
o
styles.bin
sharedStrings.bin
theme
theme1.xml
calcChain.bin
printerSettings
printerSettings4.bin
printerSettings3.bin
printerSettings2.bin
printerSettings1.bin
printerSettings5.bin
printerSettings6.bin
printerSettings12.bin
printerSettings11.bin
printerSettings10.bin
printerSettings9.bin
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
12 / 12
Path oox:docm~T1027~T1059.005~T1564.007>bin
Shape oox:docm>bin
malicious 2 nodes
Path oox:docm~T1027~T1059.005~T1564.007>ole:doc~T1564.007
Shape oox:docm>ole:doc
malicious 2 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #6 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #7 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #8 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #9 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #10 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #11 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #12 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #13 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #14 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #15 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #16 URIsuspect
htthuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙