Malicious
Malicious

261927f5140fa0abe2f60d82e35211f4

MS Office Document
MD5: 261927f5140fa0abe2f60d82e35211f4
Size: 107.52 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 261927f5140fa0abe2f60d82e35211f4
Sha1 07343f01663ef050b87d60c2cfb7ee7f03f0a51d
Sha256 f94c1aaa08179bda1d9a6be54cf159ee9e80a92fcd01e6a6ecf6dbf434f9513e
Sha384 eaf979c26e52db4e05b1d63e554cf2546d9c1fb607b4aa868e26d80e7d8381b107b53987f4c341cdcf8f71472ce715b2
Sha512 11e1b41f1b35dfcaf4bd662ec00c441313c9f3c2fd38c9b06a4e14c4dcc4a15515ffa2ed3a8561c86200a5b71ddb5f663205056f147d4ed101e8dab92da1f467
SSDeep 1536:iREpq7Q9U8e1vk9HOH5o5SVRc1eHIgXYTyAOoOXH49n2qc2B:izG7eCOZo5SVu1epoTyPoqHyn
TLSH 03B3F15DB16DC024D41ACC74ACC0E6EFA6133C92ED0B951B36AAF70E14BD0914E6F76A
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD01CC55D2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
theme
theme1.xml
worksheets
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet3.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
drawing1.xml
media
image1.png
image1.png-preview.png
styles.xml
sharedStrings.xml
printerSettings
printerSettings2.bin
printerSettings1.bin
printerSettings3.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD01CC55D3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
7 / 7
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>img
Shape ole:doc>oox:xlsx>oox:media>img
malicious 4 nodes
Path ole:doc~T1204~T1221>oox:xlsx>bin
Shape ole:doc>oox:xlsx>bin
malicious 3 nodes
Config. Field Value
URL distante (OLE moniker) #1 httP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD01CC55D2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
theme
theme1.xml
worksheets
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet3.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
drawing1.xml
media
image1.png
image1.png-preview.png
styles.xml
sharedStrings.xml
printerSettings
printerSettings2.bin
printerSettings1.bin
printerSettings3.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD01CC55D3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
Config. Field Value
URL distante (OLE moniker) #1 httP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙