Malicious
Malicious

90350a1a4ce42690e49d4e3fec7d67c3

Share on LinkedIn
Print
MS Excel Document
MD5: 90350a1a4ce42690e49d4e3fec7d67c3
Size: 1.87 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 90350a1a4ce42690e49d4e3fec7d67c3
Sha1 23e7c45fc03416caa7934f556b57ab2fae1320e6
Sha256 4b21147281f95a5358d6bbca5a8fdbea681268f4b11e43ef7a446b862d3d0bd9
Sha384 112c9632fc26291f24ec7d353ce79023b21ff63b4897287438ffb371b0c1f0b55eec8d71d2960eaab9868db55782d846
Sha512 0d2bcc694605674139acf7d4d7b8bc79e047384267fd29420877245c0842c215f64d76acd5467a5f4e87a36c70b21704392f897b28f5f1dba6345133e3aec208
SSDeep 49152:Lbnly000JTfi8qXxkEBAvKOfIqZE4sHXK90tMVhWA7Q9f:nNipiOzOfIyE9HXRtMVMeQt
TLSH E185D0A7E4C8369CFE0EDAB74E106F84A1F5ABF018919C3F4A5C7090590299F336959F
90350a1a4ce42690e49d4e3fec7d67c3
0x000F9B04.svg
0x000F9B04.svg-preview.jpg
0x000FA840.svg
0x000FA840.svg-preview.jpg
0x000FC429.svg
0x000FC429.svg-preview.jpg
0x000FD213.svg
0x000FD213.svg-preview.jpg
0x000FE4E4.svg
0x000FE4E4.svg-preview.jpg
0x000FF361.svg
0x000FF361.svg-preview.jpg
0x001002E6.svg
0x001002E6.svg-preview.jpg
0x001011A5.svg
0x001011A5.svg-preview.jpg
0x00103070.svg
0x00103070.svg-preview.jpg
0x00104285.svg
0x00104285.svg-preview.jpg
0x00106242.svg
0x00106242.svg-preview.jpg
0x00107D24.svg
0x00107D24.svg-preview.jpg
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
sheet14.xml
sheet15.xml
sheet16.xml
sheet17.xml
sheet18.xml
_rels
sheet1.xml.rels
sheet2.xml.rels
sheet3.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
sheet13.xml.rels
sheet14.xml.rels
sheet15.xml.rels
sheet16.xml.rels
sheet17.xml.rels
sheet4.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
drawing2.xml
drawing3.xml
drawing4.xml
vmlDrawing1.vml
_rels
drawing1.xml.rels
vmlDrawing1.vml.rels
vmlDrawing4.vml.rels
vmlDrawing5.vml.rels
drawing5.xml
vmlDrawing2.vml
drawing6.xml
drawing7.xml
drawing8.xml
drawing9.xml
vmlDrawing3.vml
drawing10.xml
drawing11.xml
drawing12.xml
drawing13.xml
drawing14.xml
drawing15.xml
vmlDrawing4.vml
drawing16.xml
vmlDrawing5.vml
media
image1.png
image1.png-preview.png
image2.png
image2.png-preview.png
image3.png
image3.png-preview.png
image4.png
image4.png-preview.png
image6.png
image6.png-preview.png
image8.png
image8.png-preview.png
image10.png
image10.png-preview.png
image12.png
image12.png-preview.png
image14.png
image14.png-preview.png
image16.png
image16.png-preview.png
image18.png
image18.png-preview.png
image20.png
image20.png-preview.png
image22.png
image22.png-preview.png
image24.png
image24.png-preview.png
image26.png
image26.png-preview.png
image28.emf
image29.emf
image30.emf
image31.emf
image32.emf
image33.emf
image34.emf
image35.emf
image36.emf
image37.emf
image38.emf
image39.emf
image40.emf
image41.emf
image42.emf
image43.emf
image44.emf
image45.emf
image46.emf
image47.emf
image48.emf
image49.emf
image50.emf
image51.emf
image52.emf
image53.emf
image54.emf
webextensions
taskpanes.xml
webextension1.xml
_rels
taskpanes.xml.rels
charts
chart1.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTlk
PROJECTwm
VBA
Malicious
dir
Sheet1
Sheet2
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
15 / 15
Path ole:doc~T1027~T1059.005~T1105>oox:vba~T1059.005>scr:ps1~T1027~T1059.001~T1105
Shape ole:doc>oox:vba>scr:ps1
malicious 3 nodes
Path ole:doc~T1027~T1059.005~T1105>oox:vba~T1027~T1059.005~T1105
Shape ole:doc>oox:vba
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
URL (COM trace) #2 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1 URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3 URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
file:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
file:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙