Malicious
Malicious

21d0170d64be9f25afacf9a7e2c696bc

Share on LinkedIn
Print
MS Excel Document
MD5: 21d0170d64be9f25afacf9a7e2c696bc
Size: 849.37 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 21d0170d64be9f25afacf9a7e2c696bc
Sha1 8ae31d7eadb1f138f5d32c69ccbb4b04f2a214c7
Sha256 5c6b94f0b8eea8d97c7d5e12c89c8a17a26d679578a79e10687dda3804d5a870
Sha384 86428f178150f484d1fd6408180481b67b5c28982eddd6767d12defca0a1da80f4294d982841f39f9954af1a04d7c89d
Sha512 63ded6b1a3d8ec3dd12fa86dfe593ce11d0e118754ce216986cd09eef1712548ecfcc874ce3ad9de153a199698e4429cca6dbb2d5fde8ee04e22b9e16778ecfa
SSDeep 12288:YMlMDadzn89+xamtgnZ+xTru0nTlOvch2wacCbPYLuNTiVQJbyvvtffl3caU23X8:BJ5nXMZi/n5Ovch6pJGB9MaUYXe8wn
TLSH B205131CFB1694ACCB2B657CC10817D2DC4A59568442B84E1EC4BB443E9A0FBDF8E6BD
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
sheet14.xml
sheet15.xml
sheet16.xml
sheet17.xml
sheet18.xml
sheet19.xml
sheet20.xml
sheet21.xml
sheet22.xml
sheet23.xml
sheet24.xml
sheet25.xml
sheet26.xml
sheet27.xml
sheet28.xml
_rels
sheet12.xml.rels
sheet13.xml.rels
sheet14.xml.rels
sheet15.xml.rels
sheet16.xml.rels
sheet17.xml.rels
sheet19.xml.rels
sheet20.xml.rels
sheet21.xml.rels
sheet22.xml.rels
sheet23.xml.rels
sheet24.xml.rels
sheet25.xml.rels
sheet26.xml.rels
sheet27.xml.rels
sheet28.xml.rels
sheet18.xml.rels
sheet3.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
drawing2.xml
vmlDrawing2.vml
vmlDrawing3.vml
_rels
drawing2.xml.rels
media
image1.png
image1.png-preview.png
Root Entry
Malicious
PROJECT
PROJECTlk
PROJECTwm
VBA
Malicious
dir
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
frmError
frmConnOk
frmResult
MxConfigH
MxlConfig
MxlLogger
MxlObjAttr
frmProgress
frmPwdInput
MxlParseXml
MxlPropFile
frmTemplates
_VBA_PROJECT.deobfuscated.vbs
frmResultQuery
ConvSheetToNode
frmProgressSynch
frmAbout
f
o
CompObj
VBFrame
frmError
f
o
VBFrame
frmConnOk
f
o
VBFrame
frmExport
f
o
VBFrame
frmResult
f
o
VBFrame
frmWizard
f
o
VBFrame
frmRegWarn
f
o
VBFrame
frmProgress
f
o
VBFrame
i04
f
o
CompObj
i12
f
frmPwdInput
f
o
VBFrame
frmTemplates
f
o
VBFrame
frmResultQuery
f
o
VBFrame
frmProgressQuery
f
o
VBFrame
i21
f
frmProgressSynch
f
o
VBFrame
i04
f
i05
f
metadata.xml
printerSettings
printerSettings1.bin
printerSettings10.bin
ctrlProps
ctrlProp1.xml
comments1.xml
comments2.xml
tables
table1.xml
calcChain.xml
customXml
item1.xml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
itemProps3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
custom.xml
userCustomization
customUI.xml
customUI
customUI.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
15 / 15
Path oox:xlsm~T1027~T1059.005~T1564.007>oox:media>img
Shape oox:xlsm>oox:media>img
malicious 3 nodes
Path oox:xlsm~T1027~T1059.005~T1564.007>bin
Shape oox:xlsm>bin
malicious 2 nodes
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
fihuhuhuhu
URLs in VB Code - #1 URIsuspect
fihuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙