Malicious
Malicious

0f86c00cb4be89bd807449a3b611a7b3

MS Excel Document
MD5: 0f86c00cb4be89bd807449a3b611a7b3
Size: 131.49 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0f86c00cb4be89bd807449a3b611a7b3
Sha1 3e4d544b85f256a9410f2d37a5af5c8578c922f0
Sha256 83ba0872c801fa1703efa222709cc30471ab0eacd375a954b5a66ff87edcfbfe
Sha384 4d2a9453f6d4652aa0b632490be72d34d239780721fed42cb8f436c23705f9b3e7627b1969a8f1e7b57cc2680389aa02
Sha512 089aeb55f94fe83159350fa93c25a3a059db2e88a5e93555fa1611ddb12b22d99f2319b56a1fa788e93e9a02c63783df6ed52c5ac1bfd78bcdc739315bddf0c1
SSDeep 3072:Y1BfIHuR9JEeS4H492ZfzkP8wIsCsM/QJeQrdi:YHnEeS4a2DsqyBrQ
TLSH BED312104041B4E9EFFA563B70CCA6B715002E44A9A9D35E6A05FDBD678DC8F234AB8D
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
_rels
sheet2.xml.rels
sheet3.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
drawing2.xml
vmlDrawing2.vml
_rels
drawing1.xml.rels
drawing2.xml.rels
media
image1.png
image1.png-preview.png
image2.emf
image2.emf-preview.png
comments1.xml
comments2.xml
calcChain.xml
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path oox:xlsm~T1059.005~T1564.007>oox:media>img
Shape oox:xlsm>oox:media>img
malicious 3 nodes
Path oox:xlsm~T1059.005~T1564.007>bin
Shape oox:xlsm>bin
malicious 2 nodes
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
_rels
sheet2.xml.rels
sheet3.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
drawing2.xml
vmlDrawing2.vml
_rels
drawing1.xml.rels
drawing2.xml.rels
media
image1.png
image1.png-preview.png
image2.emf
image2.emf-preview.png
comments1.xml
comments2.xml
calcChain.xml
docProps
core.xml
app.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Módulo1
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Módulo2
VBA Macro
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙