Malicious
Malicious

5f2b3f139be124410965d20687568350

MS Excel Document
MD5: 5f2b3f139be124410965d20687568350
Size: 23.87 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5f2b3f139be124410965d20687568350
Sha1 a7de3e68281fed8c26251247fdfd9c17e3be2b52
Sha256 2edb9dd4df9c8ebe605fd5807b94d472392ea95b0cb6a517b659d10192f83c80
Sha384 2fa3694f899b098235b5c15a19a42d7e72c19b1cb8316cf81184ab1948a6a68dd2674a55a56efeca8fab61667f8aaa5d
Sha512 bb9001083c7b72648fe8e6cc87b611f2ca2081bb00ec19bcbc65a34382c0f41c3cd7182eb70f8e7c806b2514ccb800e990e2717a0817f90108ee5d3ed359a8f8
SSDeep 384:QBPYLdQ5pWgLsssiCgqogQ1sZl/hAqi3KxYfhrSvplhdMed:QZYLdqkLs4gqogQ+Zl/h7xYfZy3hdH
TLSH 4BB2B058DA02DC05E175DABE830929F994452CE88703CE632F08E75C729379B6F6E49F
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
worksheets
sheet2.xml
sheet1.xml
theme
theme1.xml
sharedStrings.xml
docProps
app.xml
core.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
9 / 9
Path oox:xlsm~T1027~T1059~T1059.005~T1105>bin
Shape oox:xlsm>bin
technique2 nodes
Path oox:xlsm~T1027~T1059~T1059.005~T1105>ole:doc
Shape oox:xlsm>ole:doc
technique2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
wscriphuhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
styles.xml
worksheets
sheet2.xml
sheet1.xml
theme
theme1.xml
sharedStrings.xml
docProps
app.xml
core.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
Blacklist VBA
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

ЭтаКнига
VBA Macro
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Command (COM trace) #1 UNKNWOWNmalicious
wscriphuhuhuhuhuhuhuhuhuhuhu
5f2b3f139be124410965d20687568350 › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Decompiled VBA]
Dropped path (COM trace) #1 PATHmalicious
C:\Usehuhuhuhuhuhuhuhuhuhuhu
5f2b3f139be124410965d20687568350 › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Decompiled VBA]
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
5f2b3f139be124410965d20687568350 › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Decompiled VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
5f2b3f139be124410965d20687568350 › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Decompiled VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙