Malicious
MS Excel Document
MD5: 1ff1311914360ca2adfddb3ca9f3c227
Size: 457.3 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 1ff1311914360ca2adfddb3ca9f3c227 |
| Sha1 | 81328caa63ef141685d47ca1c9d8c804b2bcfb46 |
| Sha256 | e729e336a0ad2c39963d04930f4cab5023fba455638f21ea7f432264646d8983 |
| Sha384 | c42bc66cb6bb174ef903e1041e31ddc1fc9bf905bc75bd9da43b73445def457c7d25002d9f7eb9838c3a8f1c13f36684 |
| Sha512 | 95507a31c6add2dd5d44f0083c4fbd5946884131f510e7ac548520f747ec68c2ed81ebb8ec76b67c272152ab8141c072ba1a0770ecb53e065e88fdcea7b4603c |
| SSDeep | 12288:MOcazGlBdUqKVxfxLXnfBW87cErK6dGqSuELbEws5z2:MOFGjdtY3X08Y6FeEN5z2 |
| TLSH | 02A413E7413074DADA274A35A60F91D2FA7389C3520297297B4E95BA0BC1F3B3B5720D |
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 15
STICH kept: 8secondary ignored: 7
img
2bin
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
8 / 8
Path
oox:xlsm>ole:doc>ole:vba~T1059.005~T1564.007
Shape
oox:xlsm>ole:doc>ole:vba
malicious
3 nodes
Path
oox:xlsm>ole:doc>ole:vba~T1027~T1059.005~T1564.007
Shape
oox:xlsm>ole:doc>ole:vba
malicious
3 nodes
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 9huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential