Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 71759bf29eabe50d148cffc76af0df59
Sha1 02841d2c882417b25079a6472831593ad9be854b
Sha256 aea199b36ee2217a7ad57c692e0b63bb6396dbe982c8b1a072881c4900356b54
Sha384 c48210e7bfa9469b47bca4c2beeba1ffc784052bb6aafc0322a77bc8d968de858ebf5def4edbc29f97a150a4bd496f6f
Sha512 cf7aa0e11f2c62a6b66ba5a9b12dac0706b7aa6430c8c7a6cc794cc35763d42a2fbaf00e0dd14cc867142782f1b9ee70f57ce887545d50aecb5296b39f542a54
SSDeep 24576:TJ9yggpgCkP3586TYyiMpVZmjFBFojyQtKIOIKlHpVQ6l7LIWIulQB5kilPXIRIY:T1pnVAQtvy
TLSH 0855D511F603C62BC699223148BAA3F53778AC491A864B57725CB33D3FF6B90DA47784
[Repaired @0x0001AA61]
Malicious
Root Entry
Malicious
CompObj
Workbook
Malicious
[Repaired @0x0001A861]
Malicious
SummaryInformation
DocumentSummaryInformation
_VBA_PROJECT_CUR
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet7
Sheet8
Sheet9
Sheet10
Sheet11
Sheet12
Sheet13
Sheet14
Sheet15
Sheet16
Sheet18
Sheet20
Sheet21
Sheet36
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
__SRP_2c
__SRP_2d
__SRP_2e
__SRP_2f
__SRP_30
__SRP_31
__SRP_32
__SRP_33
__SRP_34
__SRP_35
__SRP_36
__SRP_37
ThisWorkbook
_VBA_PROJECT
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Repaired @0x0001AA61]
Malicious
Root Entry
Malicious
CompObj
Workbook
Malicious
[Repaired @0x0001A861]
Malicious
SummaryInformation
DocumentSummaryInformation
_VBA_PROJECT_CUR
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet7
Sheet8
Sheet9
Sheet10
Sheet11
Sheet12
Sheet13
Sheet14
Sheet15
Sheet16
Sheet18
Sheet20
Sheet21
Sheet36
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
__SRP_2c
__SRP_2d
__SRP_2e
__SRP_2f
__SRP_30
__SRP_31
__SRP_32
__SRP_33
__SRP_34
__SRP_35
__SRP_36
__SRP_37
ThisWorkbook
_VBA_PROJECT

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Sheet6
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Sheet7
VBA Macro
Sheet8
VBA Macro
Sheet9
VBA Macro
CSHA256
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
Module1
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
Blacklist VBA
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
Module2
Blacklist VBA
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
Module3
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
Blacklist VBA
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
Sheet10
VBA Macro
Sheet11
VBA Macro
Sheet12
VBA Macro
Sheet13
VBA Macro
Sheet14
VBA Macro
Sheet15
VBA Macro
Sheet16
VBA Macro
Sheet18
VBA Macro
Sheet20
VBA Macro
Sheet21
VBA Macro
Sheet36
VBA Macro
ThisWorkbook
VBA Macro
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
71759bf29eabe50d148cffc76af0df59
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
71759bf29eabe50d148cffc76af0df59 › [Repaired @0x0001AA61]
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
71759bf29eabe50d148cffc76af0df59 › Root Entry › _VBA_PROJECT_CUR › VBA › CSHA256 › [Stored VBA]
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
71759bf29eabe50d148cffc76af0df59 › Root Entry › _VBA_PROJECT_CUR › VBA › CSHA256 › [Decompiled VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙