Malicious
Malicious

c261aae160d140353f1af0c6a5f059ff

MS Excel Document
MD5: c261aae160d140353f1af0c6a5f059ff
Size: 11.4 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c261aae160d140353f1af0c6a5f059ff
Sha1 d1486e4a8b9df16df0b68b8c607aa14f425dda4d
Sha256 21706398640bd196f67ca5272cac4ba12f4234cf80a9636312d2288b2d7d256c
Sha384 367b0924ab547fda4f2a8beba4312520b38a59fd72515939df45210d5a1000708a03cb0e9594100ae859c350972b1fe4
Sha512 483fe3921682dc68bba148251471339539a86fca4013123ff0956a3f24f2ccdedb1aca546d0c0f7071ba5c3d27af19b6e192847b3af29b14f53e8e194996df40
SSDeep 192:HeRb6oBLsdbLyj9RukiLIj2J00a/SaFUlbVvevUqzh9SvNBajaWv:HeROolok972J00iUlM9zhQ3ajv
TLSH 00329D4BC4B6186AC3B7E87F905A04F2B11930114683B75D7D04F99BA351AE3138E6EE
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 3secondary ignored: 5
bin 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path oox:xlsm>oox:vba~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape oox:xlsm>oox:vba>scr:bat>scr:ps1
malicious 4 nodes
Path oox:xlsm>ole:doc
Shape oox:xlsm>ole:doc
2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
docProps
core.xml
app.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
Blacklist VBA
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
c261aae160d140353f1af0c6a5f059ff › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Stored VBA]
Deobfuscated PowerShell UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
c261aae160d140353f1af0c6a5f059ff › xl › vbaProject.bin › Root Entry › VBA › Module1 › [Stored VBA] › [Stored VBA].deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙