Malicious
Malicious

c16df0bfc6fda86dbfa8948a566d32c1

MS Word Document
MD5: c16df0bfc6fda86dbfa8948a566d32c1
Size: 17.56 KB
application/msword
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c16df0bfc6fda86dbfa8948a566d32c1
Sha1 610921e6f95843045fec4393c088dd1f896a6571
Sha256 e38c53aedf49017c47725e4912fc7560e1c8ece2633c05057b22fd4a8ed28eb3
Sha384 a1ca33fa67fe6687344860c1ff9e4e95379aef7a19d329be54cc14b280c64ed3534f256fdfdf0d6c85edbbfc2928e1fa
Sha512 461ae0e01189f0abcd2b3ecc9b80743e023e726eec7ea8ac95778ba97d0166965fe724d38e6f19ce4e1787a93982de100934b41a2972b886e5f8c29c7f4f0f65
SSDeep 384:Xsz8ND9/dxdG5BEQjNxt/ZtNN+n222UhfFN1NKeVQ11NXHEHre8RK:XDVEBRZxllNGZfFN1NF0HOhRK
TLSH 38729E3DD1487430EA93A67C500F26F1F261D183E4527D5F3926FBAE9BA47CB071A488
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
theme
theme1.xml
vbaData.xml
settings.xml
fontTable.xml
webSettings.xml
styles.xml
customXml
itemProps1.xml
item1.xml
_rels
item1.xml.rels
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
8 / 8
Path oox:docm~T1059.005>oox:vba~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape oox:docm>oox:vba>scr:bat>scr:ps1
malicious 4 nodes
Path oox:docm~T1059.005>bin
Shape oox:docm>bin
technique2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
word
Malicious
_rels
document.xml.rels
vbaProject.bin.rels
document.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
theme
theme1.xml
vbaData.xml
settings.xml
fontTable.xml
webSettings.xml
styles.xml
customXml
itemProps1.xml
item1.xml
_rels
item1.xml.rels
docProps
core.xml
app.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
ThisDocument
Blacklist VBA
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
c16df0bfc6fda86dbfa8948a566d32c1 › word › vbaProject.bin › Root Entry › VBA › ThisDocument › [Stored VBA]
Deobfuscated PowerShell UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
c16df0bfc6fda86dbfa8948a566d32c1 › word › vbaProject.bin › Root Entry › VBA › ThisDocument › [Stored VBA] › [Stored VBA].deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙