Malicious
Malicious

7b25cc80d06e510844e6e7986feda7d1

MS Office Document
MD5: 7b25cc80d06e510844e6e7986feda7d1
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7b25cc80d06e510844e6e7986feda7d1
Sha1 72030687232fb309f83c781b19940c143b63f080
Sha256 be592d36972e47ba32ba4a1cd82e2450249fd07e0752289c844e61c6dc568715
Sha384 27cd6caf497692471141227a0771bb02efad6a94d3c7df23f1c0252cd1c675c7ed84bb7ec7650ae3501c131fe0c07979
Sha512 1614520dea028fd0c81c74937c9d3c915340d790187faa62d9ac02bd848d4acc043ca06a5a13649e47f5d892e510ced4aeae99b0d6dd288648062c663d76f57e
SSDeep 768:UKk3hOdsylKlgryzc4bNhZFGzE+cL2knAJDTqfxetY5OzX:/k3hOdsylKlgryzc4bNhZFGzE+cL2knk
TLSH 5AD250A6B2C6DC0AC95503394DE7C6E66726FC225F67838B3289F31E1F71AC08913657
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path ole:doc~T1059.005>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1059.005>ole:vba~T1059.005
Shape ole:doc>ole:vba
technique2 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
ThisWorkbook
VBA Macro
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
7b25cc80d06e510844e6e7986feda7d1 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Decompiled VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
7b25cc80d06e510844e6e7986feda7d1 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Stored VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙