Malicious
Malicious

100c92c34ffc0cd6832eb72ff0abe0a9

Share on LinkedIn
Print
MS Excel Document
MD5: 100c92c34ffc0cd6832eb72ff0abe0a9
Size: 1.13 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 100c92c34ffc0cd6832eb72ff0abe0a9
Sha1 6505ef1a0715aef98481d2dc226310e51d6c78de
Sha256 13d8c4aac39d22bd39177ede9291d6eb103a2c2de7ccece6f28d6986962d358f
Sha384 c0e333e83affedc768d32eea40e5bd6569696afa5311affee6b309067c116777a2cdfe743ddd3beb20932b22ba52b8ab
Sha512 8c0e97b128268e595421957d19b83b8990a872bdde41bdaf764d1cb7dea5bc41009dd99b0b66b407c7967f15586643378359f94d781acb16cf45488ce33bcadc
SSDeep 24576:FQvnPpaoWEzGZqOALOcsdNomd4OP/Zj0sDJy42Br:Fi3fpLhmd4o/Zj0sFr2J
TLSH AE35222EBF0DC437F50352F8B62ACB81D056399E09D5A806387FE1FC079E91D9A4968D
[Content_Types].xml
_rels
.rels
customXml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
item2.xml
item3.xml
itemProps1.xml
itemProps2.xml
itemProps3.xml
docProps
app.xml
core.xml
custom.xml
xl
calcChain.xml
comments1.xml
ctrlProps
ctrlProp1.xml
drawings
drawing1.xml
_rels
drawing1.xml.rels
drawing2.xml.rels
drawing3.xml.rels
drawing13.xml.rels
drawing2.xml
drawing3.xml
drawing4.xml
drawing5.xml
drawing6.xml
drawing7.xml
drawing8.xml
drawing9.xml
drawing10.xml
drawing11.xml
drawing12.xml
drawing13.xml
vmlDrawing1.vml
vmlDrawing2.vml
vmlDrawing3.vml
vmlDrawing4.vml
vmlDrawing5.vml
vmlDrawing6.vml
vmlDrawing7.vml
vmlDrawing8.vml
vmlDrawing9.vml
vmlDrawing10.vml
vmlDrawing11.vml
vmlDrawing12.vml
media
image1.jpeg
image1.jpeg-preview.png
image2.jpeg
image2.jpeg-preview.png
image3.png
image3.png-preview.png
image4.png
image4.png-preview.png
image5.png
image5.png-preview.png
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
image8.png
image8.png-preview.png
image9.png
image9.png-preview.png
image10.png
image10.png-preview.png
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings7.bin
printerSettings8.bin
printerSettings9.bin
printerSettings10.bin
printerSettings12.bin
sharedStrings.xml
styles.xml
theme
theme1.xml
vbaProject.bin
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Hoja11
Hoja12
Hoja13
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
__SRP_2c
__SRP_2d
ModCapitulo4
ModCapitulo5
ModCapitulo6
ModCapitulo7
ModCapitulo8
ModCapitulo9
ThisWorkbook
_VBA_PROJECT.deobfuscated.vbs
LoginUserForm
LoginUserForm
f
o
CompObj
VBFrame
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
_rels
sheet1.xml.rels
sheet3.xml.rels
sheet4.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
sheet13.xml.rels
sheet14.xml.rels
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
sheet14.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
12 / 12
Path oox:xlsm~T1027~T1059.005>oox:media>img
Shape oox:xlsm>oox:media>img
technique3 nodes
Path oox:xlsm~T1027~T1059.005>bin
Shape oox:xlsm>bin
technique2 nodes
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙