Suspicious
Suspect

94e1802c44d61532b37fa83cf218d1f5

MS Excel Document
MD5: 94e1802c44d61532b37fa83cf218d1f5
Size: 717.99 KB
application/vnd.ms-excel

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 94e1802c44d61532b37fa83cf218d1f5
Sha1 2d38a5652efe0b33f25bccf280589a5724443ab5
Sha256 c382fb1b093a0ff937c806afdcf96045f82f27f5bd0ba3602a1a162db8754444
Sha384 79f9916229698f97ce51b0dc85ebb9b0974e820280bc13b380117ceaf6ebb1986423206c4058200b734d06be06a17c1c
Sha512 1311eba765306c2425720dd9f7661a46b732a320c7d9c4bfc16b766a3002ff2cbc62be5e00df33f9d214aa6dbcad0fb012166283e5876e0a1710c71af175ee30
SSDeep 12288:aQGgmAsQR55zp2v7EpTglVEYSKez0aMwg7FbdzuVY+SWkV2QRhPrfO:ZiAsQroATglWYS4aMZE3qAUPS
TLSH B0E423431280C75A84A737F8E2F86CB7C9377FD18B9996415E2F854CB6A70734E70A52
94e1802c44d61532b37fa83cf218d1f5
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
ziY.Wg7PUNU
Root Entry
Ole10NATivE
sF2DWkajj2CjVjKtXG1BoJX
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:xlsx>oox:media>ole:doc
Shape oox:xlsx>oox:media>ole:doc
3 nodes
94e1802c44d61532b37fa83cf218d1f5
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
styles.xml
theme
theme1.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
ziY.Wg7PUNU
Root Entry
Ole10NATivE
sF2DWkajj2CjVjKtXG1BoJX
docProps
core.xml
app.xml
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙