Malicious
602b7db7fa7f79326a6f3a1f875bd490
MS Excel Document
MD5: 602b7db7fa7f79326a6f3a1f875bd490
Size: 610.16 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 602b7db7fa7f79326a6f3a1f875bd490 |
| Sha1 | 0985464447c7acae16caddff60d85e426343db03 |
| Sha256 | d5a939a986a7f4fd4889c4b0c4d2daa4788a16b52f958b2a56e912635e519f10 |
| Sha384 | 474ed9d5e5abe95bc3853773c2c6634d643f358599e65169f4e6567d27423d1617e61d14aa78690a17c8cf5a46be3054 |
| Sha512 | 4b9c6a138f06a173a5735fef4f75da22ccbcefe5819a70783b797d20e6cb00d56281cca28fc37f7d39f305c47b9931bcfd5b9d52cb448d8e7d527789b548b60a |
| SSDeep | 12288:/BM4hT5Bq+PWNpFwx5/W4GQKgI2iTKaGBU9GwLhT52Y6X+Ywbyf:/BM4hT5kCx5jGQKHeBU9GuhUYxYAg |
| TLSH | 9ED4CF085EEE28D5C78993BED742EE70AB0B8B4D58B2AF5C1A573D152401FB113FAE50 |
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
12 / 12
Path
oox:xlsm~T1059.005>oox:media>img
Shape
oox:xlsm>oox:media>img
technique3 nodes
Path
oox:xlsm~T1059.005>bin
Shape
oox:xlsm>bin
technique2 nodes
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| Target | file:/huhuhuhuhuhuhuhuhuhuhu |
| Path | externhuhuhuhuhuhuhu |
| XPath | /Relathuhuhuhuhuhuhuhuhuhuhu |
| Outer XML | <Relathuhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious
URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
602b7db7fa7f79326a6f3a1f875bd490 › xl › externalLinks › _rels › externalLink1.xml.rels
Trace COM ordonnée
UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
602b7db7fa7f79326a6f3a1f875bd490 › xl › vbaProject.bin › Root Entry › VBA › Clear_and_Compress_Macros › [Stored VBA]
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
602b7db7fa7f79326a6f3a1f875bd490 › xl › vbaProject.bin › Root Entry › VBA › EmbedPictures_Macros › [Stored VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.