Malicious
Malicious

897cb084996039a8732bcdf4f8043cda

MS Excel Document
MD5: 897cb084996039a8732bcdf4f8043cda
Size: 90.76 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 897cb084996039a8732bcdf4f8043cda
Sha1 6f513ed7ad48084f1315975f2dfa4d4300da447c
Sha256 b886360844748c3190ce13d70bf195060158f700d4d7c796252e511463dd8439
Sha384 e47890992aba2edb2efa395e87cbf91ae21a904091cc27d77630fddf001af096125a54956023dff26fa869302eed9c06
Sha512 2be69de4c5c11009b87ad3aeb7df9e8717268cac61effbc6e6c857a4960d11f732b68a0a5fa873d0fbb300f821d37c3fcbef36b1bb3ce30fd4f8a478e983881d
SSDeep 1536:rPACXR5O0MjO/oRUzu08sn1QNOquYsBfVDcyY54J1vCom04:UK5OeoRUzZ8sn131xnY54J1vUN
TLSH 2893F119D2B7F826C7AAB8F8D31C5BF1920E5902408235472D54B84C6B4337F6B9D7AE
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet6.xml
sheet5.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet5.xml.rels
sheet6.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
vbaProject.bin
Root Entry
PROJECT
PROJECTwm
VBA
dir
Module1
Module2
Module3
Module4

Module4


__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
_VBA_PROJECT
drawings
drawing1.xml
vmlDrawing1.vml
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings3.bin
ctrlProps
ctrlProp1.xml
calcChain.xml
docMetadata
LabelInfo.xml
customXml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
itemProps3.xml
docProps
core.xml
app.xml
custom.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 4secondary ignored: 5
bin 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path oox:xlsm>oox:rel:ext~T1221
Shape oox:xlsm>oox:rel:ext
technique2 nodes
Path oox:xlsm>oox:vba~T1059.005
Shape oox:xlsm>oox:vba
technique2 nodes
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet6.xml
sheet5.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet5.xml.rels
sheet6.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
vbaProject.bin
Root Entry
PROJECT
PROJECTwm
VBA
dir
Module1
Module2
Module3
Module4

Module4


__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
_VBA_PROJECT
drawings
drawing1.xml
vmlDrawing1.vml
externalLinks
Malicious
externalLink1.xml
_rels
Malicious
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings3.bin
ctrlProps
ctrlProp1.xml
calcChain.xml
docMetadata
LabelInfo.xml
customXml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
itemProps3.xml
docProps
core.xml
app.xml
custom.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
VBA Macro
Module2
VBA Macro
Module3
VBA Macro
Module4
VBA Macro
Config. Field Value
Target https:huhuhuhuhuhuhuhuhuhuhu
Path externhuhuhuhuhuhuhu
XPath /Relathuhuhuhuhuhuhuhuhuhuhu
Outer XML <Relathuhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Remote Template - Highly Suspicious URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
897cb084996039a8732bcdf4f8043cda › xl › externalLinks › _rels › externalLink1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙