Malicious
Malicious

602b7db7fa7f79326a6f3a1f875bd490

Share on LinkedIn
Print
MS Excel Document
MD5: 602b7db7fa7f79326a6f3a1f875bd490
Size: 610.16 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 602b7db7fa7f79326a6f3a1f875bd490
Sha1 0985464447c7acae16caddff60d85e426343db03
Sha256 d5a939a986a7f4fd4889c4b0c4d2daa4788a16b52f958b2a56e912635e519f10
Sha384 474ed9d5e5abe95bc3853773c2c6634d643f358599e65169f4e6567d27423d1617e61d14aa78690a17c8cf5a46be3054
Sha512 4b9c6a138f06a173a5735fef4f75da22ccbcefe5819a70783b797d20e6cb00d56281cca28fc37f7d39f305c47b9931bcfd5b9d52cb448d8e7d527789b548b60a
SSDeep 12288:/BM4hT5Bq+PWNpFwx5/W4GQKgI2iTKaGBU9GwLhT52Y6X+Ywbyf:/BM4hT5kCx5jGQKHeBU9GuhUYxYAg
TLSH 9ED4CF085EEE28D5C78993BED742EE70AB0B8B4D58B2AF5C1A573D152401FB113FAE50
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
worksheets
sheet4.xml
sheet3.xml
sheet2.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet1.xml
media
image5.jpeg
image5.jpeg-preview.png
image6.jpeg
image6.jpeg-preview.png
image4.jpeg
image4.jpeg-preview.png
image2.jpeg
image2.jpeg-preview.png
image3.jpeg
image3.jpeg-preview.png
image1.jpeg
image1.jpeg-preview.png
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
UserForm1
f
o
CompObj
VBFrame
drawings
_rels
drawing1.xml.rels
drawing1.xml
theme
theme1.xml
styles.xml
sharedStrings.xml
externalLinks
Malicious
_rels
Malicious
externalLink1.xml
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings3.bin
customXml
item2.xml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
itemProps2.xml
item3.xml
itemProps3.xml
itemProps1.xml
docProps
app.xml
custom.xml
core.xml
docMetadata
LabelInfo.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
12 / 12
Path oox:xlsm~T1059.005>oox:media>img
Shape oox:xlsm>oox:media>img
technique3 nodes
Path oox:xlsm~T1059.005>bin
Shape oox:xlsm>bin
technique2 nodes
Config. Field Value
Target file:/huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
file:/huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 6huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙