Suspicious
Suspect

3030715727a1596b341a1b5352227124

MS Excel Document
MD5: 3030715727a1596b341a1b5352227124
Size: 664.47 KB
application/vnd.ms-excel

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3030715727a1596b341a1b5352227124
Sha1 6c695208318a604b62141a3304587bbdb30d5ca0
Sha256 e6ae38bf506ed49e46ef94ec85afc458058e983f2bb2bbb34e28b1d3acfcdbff
Sha384 7979dff9ddfa142cd4541de6a1284a623f55af35db4c9e328a2386d968b4e045d9cc97d5ec75381613b5aa26e54d21ba
Sha512 53de5165448eaf14db1091dc9c58321c997c34857caf9bb5b850e6a491b9db048061a1c754d6fd2ca7c093525a8975a240c9e890f65e0852a96417c360115043
SSDeep 12288:MsVhaCCwe7DXVhaNJMJekwX6Vdkwiu7ynxHlwWrZyjdTUfAVII9XKOstn:TVL/YrSKe7udkpu7ogjdTUN8s
TLSH 2EE423EABF42D45CC79B70D2E2B52774D68486172F176E0B3182C9187DFC4C01E5AE9A
3030715727a1596b341a1b5352227124
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
MOofdHBj.TmboN
Root Entry
olE10NativE
mgx7t9GEaDwsz
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:xlsx>oox:media>ole:doc
Shape oox:xlsx>oox:media>ole:doc
3 nodes
3030715727a1596b341a1b5352227124
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
MOofdHBj.TmboN
Root Entry
olE10NativE
mgx7t9GEaDwsz
docProps
core.xml
app.xml
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙