Malicious
Malicious

89274bc96aa32923d5f34832aba6245e

MS Excel Document
MD5: 89274bc96aa32923d5f34832aba6245e
Size: 120.89 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 89274bc96aa32923d5f34832aba6245e
Sha1 76901d4432262ae1313e60054e1a56378a3a0eae
Sha256 0f5657269986cadddb478f8a5bb25becbeed713210247f3daea14becb0436571
Sha384 90b048083f93bc266e5db0a668fe10ae0ea6e628a8c8044db1ff9fdc712a0da236249e11a292bac62d54d65348a14f4c
Sha512 691baff92576f2969035d810239bd29b40f9fdf8a0e3824abaa1557c91dbdb5682d3220f5570546f8d4fba6ece927fbd41bcbedc30965ecb06bd56ab47e93207
SSDeep 3072:A98fkBzs4xcDWTgNoWcMfvA8/R7lS4Hqu6bCtL:fkBzs4CDWhMfvA8BlS4yb8
TLSH 5FC302828671A81DDBB611B5544C51F890D41C53F9E1E0DE37C4AA8C261BABF2B2CF8F
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
_rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
vmlDrawing2.vml
vmlDrawing3.vml
_rels
drawing1.xml.rels
media
image1.png
image1.png-preview.png
webextensions
taskpanes.xml
webextension1.xml
_rels
taskpanes.xml.rels
comments1.xml
comments2.xml
comments3.xml
calcChain.xml
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
11 / 11
Path oox:xlsm~T1059.005~T1564.007>oox:media>img
Shape oox:xlsm>oox:media>img
malicious 3 nodes
Path oox:xlsm~T1059.005~T1564.007>bin
Shape oox:xlsm>bin
malicious 2 nodes
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
_rels
sheet2.xml.rels
sheet3.xml.rels
sheet4.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
vmlDrawing2.vml
vmlDrawing3.vml
_rels
drawing1.xml.rels
media
image1.png
image1.png-preview.png
webextensions
taskpanes.xml
webextension1.xml
_rels
taskpanes.xml.rels
comments1.xml
comments2.xml
comments3.xml
calcChain.xml
docProps
core.xml
app.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Módulo1
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Módulo2
VBA Macro
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙