Malicious
c261aae160d140353f1af0c6a5f059ff
MS Excel Document
MD5: c261aae160d140353f1af0c6a5f059ff
Size: 11.4 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | c261aae160d140353f1af0c6a5f059ff |
| Sha1 | d1486e4a8b9df16df0b68b8c607aa14f425dda4d |
| Sha256 | 21706398640bd196f67ca5272cac4ba12f4234cf80a9636312d2288b2d7d256c |
| Sha384 | 367b0924ab547fda4f2a8beba4312520b38a59fd72515939df45210d5a1000708a03cb0e9594100ae859c350972b1fe4 |
| Sha512 | 483fe3921682dc68bba148251471339539a86fca4013123ff0956a3f24f2ccdedb1aca546d0c0f7071ba5c3d27af19b6e192847b3af29b14f53e8e194996df40 |
| SSDeep | 192:HeRb6oBLsdbLyj9RukiLIj2J00a/SaFUlbVvevUqzh9SvNBajaWv:HeROolok972J00iUlM9zhQ3ajv |
| TLSH | 00329D4BC4B6186AC3B7E87F905A04F2B11930114683B75D7D04F99BA351AE3138E6EE |
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 8
STICH kept: 3secondary ignored: 5
bin
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
oox:xlsm>oox:vba~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
oox:xlsm>oox:vba>scr:bat>scr:ps1
malicious
4 nodes
Path
oox:xlsm>ole:doc
Shape
oox:xlsm>ole:doc
2 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Malicious
Malicious
Malicious
Malicious
Malicious
Malicious
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | https:huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
c261aae160d140353f1af0c6a5f059ff › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Stored VBA]
Deobfuscated PowerShell
UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
c261aae160d140353f1af0c6a5f059ff › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Stored VBA] › [Stored VBA].deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.