Malicious
4da972b7c30f42b505f1c97e04a2d3af
MS Excel Document
MD5: 4da972b7c30f42b505f1c97e04a2d3af
Size: 922.77 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 4da972b7c30f42b505f1c97e04a2d3af |
| Sha1 | 467856f3abdf84c5de7a1eef542991dc80f3a7c1 |
| Sha256 | d7c8d502f16f7e19756d7d9a80c6bc15e594c305ff6e509aa6d226e71a2d0c47 |
| Sha384 | 5b3d5261ac75db0b168536419955527518e631ca6c0c36105ce022d266f77b086da99bd6cc154d0437807a898cee0b7c |
| Sha512 | 489b28db72d912b3b666c321a23baeeb69fba166c548c5db3271f56f73df89fb13cafd36455115d8b1ec6fe112d2b3e34a88f84157ac930ec0c3a3ea4de59f3a |
| SSDeep | 24576:ZXpzlzTZVETa8BWZ5UZquALfTq/8tG/Yq5yY/4j5:pz0RC9LMwMpyG4j5 |
| TLSH | 4E15121ACA4D185BCE7ED3742B3C5BC6540C63898844E86E6144F68CAFD0B4FBB5E66C |
Malicious
Malicious
Malicious
Malicious
ModHojaC101
ModHojaC700
ModHojaC900
ThisWorkbook
LoginUserForm
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
14 / 14
Path
oox:xlsm~T1027~T1059.005~T1564.007>oox:media>img
Shape
oox:xlsm>oox:media>img
malicious
3 nodes
Path
oox:xlsm~T1027~T1059.005~T1564.007>bin
Shape
oox:xlsm>bin
malicious
2 nodes
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
ModHojaC101
ModHojaC700
ModHojaC900
ThisWorkbook
LoginUserForm
No malware configuration was found at this point.
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Decompiled VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #3
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › ModEnvioDatos › [Stored VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › Hoja8 › [Decompiled VBA]
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › vbaProject.bin › Root Entry › VBA › Hoja8 › [Stored VBA]
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
4da972b7c30f42b505f1c97e04a2d3af › xl › worksheets › _rels › sheet9.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.