Malicious
MS Excel Document
MD5: 100c92c34ffc0cd6832eb72ff0abe0a9
Size: 1.13 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 100c92c34ffc0cd6832eb72ff0abe0a9 |
| Sha1 | 6505ef1a0715aef98481d2dc226310e51d6c78de |
| Sha256 | 13d8c4aac39d22bd39177ede9291d6eb103a2c2de7ccece6f28d6986962d358f |
| Sha384 | c0e333e83affedc768d32eea40e5bd6569696afa5311affee6b309067c116777a2cdfe743ddd3beb20932b22ba52b8ab |
| Sha512 | 8c0e97b128268e595421957d19b83b8990a872bdde41bdaf764d1cb7dea5bc41009dd99b0b66b407c7967f15586643378359f94d781acb16cf45488ce33bcadc |
| SSDeep | 24576:FQvnPpaoWEzGZqOALOcsdNomd4OP/Zj0sDJy42Br:Fi3fpLhmd4o/Zj0sFr2J |
| TLSH | AE35222EBF0DC437F50352F8B62ACB81D056399E09D5A806387FE1FC079E91D9A4968D |
Malicious
Malicious
Malicious
ModCapitulo4
ModCapitulo5
ModCapitulo6
ModCapitulo7
ModCapitulo8
ModCapitulo9
ThisWorkbook
LoginUserForm
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
12 / 12
Path
oox:xlsm~T1027~T1059.005>oox:media>img
Shape
oox:xlsm>oox:media>img
technique3 nodes
Path
oox:xlsm~T1027~T1059.005>bin
Shape
oox:xlsm>bin
technique2 nodes
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential