Malicious
MS Excel Document
MD5: 1c301cf396b2bf57458e057b24e50213
Size: 1.14 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 1c301cf396b2bf57458e057b24e50213 |
| Sha1 | 6f646db834cf1d9fe8f9cf11b1d5666f77eaff06 |
| Sha256 | 27d657176b8217b7ac3cf5e38f49b8ff064dcd9fc25759e351ae014b015d35c7 |
| Sha384 | d549463b6c255955956e6185b99d20080aeb3666eafff300637d70af83c83a2646184c245fb394e022f79ecd25c0f0fa |
| Sha512 | a90c6077a120cb1fde0c4009d42b6668da21883ec6fe4a8aa7b696c5e5184ee97aefb3d464df56bcf0ecbdbd39c54a2410e19545704632dce244834d200c697d |
| SSDeep | 24576:gPGPHupaKWEzGZqOALOLs+W9Tz5DHPQTJsvyOP+pBXwW:ARfpLdXNHPwJr17wW |
| TLSH | 8035122BFF0C8035F68361F8E21AEB446482355F488574867DAB69BC2F5BB2D97406CD |
Malicious
Malicious
Malicious
ModCapitulo4
ModCapitulo5
ModCapitulo6
ModCapitulo7
ModCapitulo8
ModCapitulo9
ThisWorkbook
LoginUserForm
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
12 / 12
Path
oox:xlsm~T1027~T1059.005>oox:media>img
Shape
oox:xlsm>oox:media>img
technique3 nodes
Path
oox:xlsm~T1027~T1059.005>bin
Shape
oox:xlsm>bin
technique2 nodes
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential