Malicious
Malicious

261927f5140fa0abe2f60d82e35211f4

Share on LinkedIn
Print
MS Office Document
MD5: 261927f5140fa0abe2f60d82e35211f4
Size: 107.52 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 261927f5140fa0abe2f60d82e35211f4
Sha1 07343f01663ef050b87d60c2cfb7ee7f03f0a51d
Sha256 f94c1aaa08179bda1d9a6be54cf159ee9e80a92fcd01e6a6ecf6dbf434f9513e
Sha384 eaf979c26e52db4e05b1d63e554cf2546d9c1fb607b4aa868e26d80e7d8381b107b53987f4c341cdcf8f71472ce715b2
Sha512 11e1b41f1b35dfcaf4bd662ec00c441313c9f3c2fd38c9b06a4e14c4dcc4a15515ffa2ed3a8561c86200a5b71ddb5f663205056f147d4ed101e8dab92da1f467
SSDeep 1536:iREpq7Q9U8e1vk9HOH5o5SVRc1eHIgXYTyAOoOXH49n2qc2B:izG7eCOZo5SVu1epoTyPoqHyn
TLSH 03B3F15DB16DC024D41ACC74ACC0E6EFA6133C92ED0B951B36AAF70E14BD0914E6F76A
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MBD01CC55D2
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
theme
theme1.xml
worksheets
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet3.xml
sheet1.xml
drawings
_rels
drawing1.xml.rels
drawing1.xml
media
image1.png
image1.png-preview.png
styles.xml
sharedStrings.xml
printerSettings
printerSettings2.bin
printerSettings1.bin
printerSettings3.bin
docProps
thumbnail.wmf
core.xml
app.xml
CompObj
MBD01CC55D3
Ole
_VBA_PROJECT_CUR
PROJECT
PROJECTwm
VBA
dir
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
7 / 7
Path ole:doc~T1204~T1221>oox:xlsx>oox:media>img
Shape ole:doc>oox:xlsx>oox:media>img
malicious 4 nodes
Path ole:doc~T1204~T1221>oox:xlsx>bin
Shape ole:doc>oox:xlsx>bin
malicious 3 nodes
Config. Field Value
URL distante (OLE moniker) #1 httP:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙