Malicious
MS Excel Document
MD5: 90350a1a4ce42690e49d4e3fec7d67c3
Size: 1.87 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | 90350a1a4ce42690e49d4e3fec7d67c3 |
| Sha1 | 23e7c45fc03416caa7934f556b57ab2fae1320e6 |
| Sha256 | 4b21147281f95a5358d6bbca5a8fdbea681268f4b11e43ef7a446b862d3d0bd9 |
| Sha384 | 112c9632fc26291f24ec7d353ce79023b21ff63b4897287438ffb371b0c1f0b55eec8d71d2960eaab9868db55782d846 |
| Sha512 | 0d2bcc694605674139acf7d4d7b8bc79e047384267fd29420877245c0842c215f64d76acd5467a5f4e87a36c70b21704392f897b28f5f1dba6345133e3aec208 |
| SSDeep | 49152:Lbnly000JTfi8qXxkEBAvKOfIqZE4sHXK90tMVhWA7Q9f:nNipiOzOfIyE9HXRtMVMeQt |
| TLSH | E185D0A7E4C8369CFE0EDAB74E106F84A1F5ABF018919C3F4A5C7090590299F336959F |
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
15 / 15
Path
ole:doc~T1027~T1059.005~T1105>oox:vba~T1059.005>scr:ps1~T1027~T1059.001~T1105
Shape
ole:doc>oox:vba>scr:ps1
malicious
3 nodes
Path
ole:doc~T1027~T1059.005~T1105>oox:vba~T1027~T1059.005~T1105
Shape
ole:doc>oox:vba
malicious
2 nodes
| Config. Field | Value |
|---|---|
| URL (COM trace) #1 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL (COM trace) #2 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #3 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
| URL in PowerShell #2 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #1
URImalicious
http:/huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #2
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
URL in PowerShell #3
URImalicious
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 5huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 3huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 2huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
file:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
file:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential