Malicious
Malicious

0b472686dc4081569d996e3614822446

MS Office Document
MD5: 0b472686dc4081569d996e3614822446
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0b472686dc4081569d996e3614822446
Sha1 3f03db0780926ef3d50abcbc565ed1d970a309b8
Sha256 72a8628bccc5d51823e2e1361a48def17230fc6c95e9dd12cb4e5563cba87c70
Sha384 5b665cc1f66d82452f5e0d0c47d5a11cd8e8a3b1b828373f72e541bfe11348de35edceb08a6b3cce5897a9102e68148a
Sha512 484d9ac9ac9a744b7c9e6f87405fe4c3d1831d9107d4e9db204af005e05f88c40d3f985e6047cac892e4a6ae55ef20dbb3b9c9910e182f9022bb7e36b6f3b233
SSDeep 768:PKk3hOdsylKlgryzc4bNhZFGzE+cL2knAJDcOf9e2B8J5:Ck3hOdsylKlgryzc4bNhZFGzE+cL2kn/
TLSH 88D24FA2B2C6D80AD94503394DEBC6E66727FC215FA7834B3289F31E1F71AC08953657
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path ole:doc~T1059.005>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1059.005>ole:vba~T1059.005
Shape ole:doc>ole:vba
technique2 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
Blacklist VBA
VBA Macro
ThisWorkbook
VBA Macro
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0b472686dc4081569d996e3614822446 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Stored VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
0b472686dc4081569d996e3614822446 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Decompiled VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙