Malicious
Malicious

60efa74b894ca64dbb57cb20495aa834

VBScript
MD5: 60efa74b894ca64dbb57cb20495aa834
Size: 2.74 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 60efa74b894ca64dbb57cb20495aa834
Sha1 8f6485ca31d5464bf443ecd03560deb24a12934b
Sha256 7997bfe7ec26d2ed24ab7fa1fb2a3542762876910d33284273f76e20928f1d72
Sha384 72c3ffd66beac328b7a588f2fe193aa9559aeb23953e01aa324547b18b6b0b3853073489ce5dda53f654351e8b215778
Sha512 a13e4c7b087c97a667c42cb83f74e125470e24c91253a08cfc55dbe998af6543a6ec522f212392ebbe36075e8e8db9e4209d7109fdf2d9ed46f5eaaff46a4ae9
SSDeep 6144:w/uBKyYPGn/84e15Xg1lIkGuDQMi2cSa2AnlPpyj3iaM1YdOOtup19IJVNABDEQo:Bu8dM1Y5tYDQo49fiZXZ849f0
TLSH DAC539B629D1DA05D6781432CE7B955C0CE02EDBDE84A9173E1FF30F377812162D8A9A
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MsoDataStore
0CZÌ33ÎP3USËÛBÓÇ3ÎHRÑÐ==
Item
Properties
33ßÍ2ÌOÏÙUG5ÝÂÎÞLÃVÖTÀ==
Item
Properties
OÈ3ÏßJÒØÊU4ÜXÔÊÌ5ÄÞÎYA==
Item
Properties
ÓÓ1ÄIDÂß3ÔÚX2ÎWVÞSXOOÐ==
Item
Properties
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path ole:doc~T1059.005~T1564.007>bin
Shape ole:doc>bin
malicious 2 nodes
Path ole:doc~T1059.005~T1564.007>ole:vba~T1059.005~T1564.007
Shape ole:doc>ole:vba
malicious 2 nodes
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
MsoDataStore
0CZÌ33ÎP3USËÛBÓÇ3ÎHRÑÐ==
Item
Properties
33ßÍ2ÌOÏÙUG5ÝÂÎÞLÃVÖTÀ==
Item
Properties
OÈ3ÏßJÒØÊU4ÜXÔÊÌ5ÄÞÎYA==
Item
Properties
ÓÓ1ÄIDÂß3ÔÚX2ÎWVÞSXOOÐ==
Item
Properties

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Módulo1
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙