Malicious
Malicious

c261aae160d140353f1af0c6a5f059ff

Share on LinkedIn
Print
MS Excel Document
MD5: c261aae160d140353f1af0c6a5f059ff
Size: 11.4 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c261aae160d140353f1af0c6a5f059ff
Sha1 d1486e4a8b9df16df0b68b8c607aa14f425dda4d
Sha256 21706398640bd196f67ca5272cac4ba12f4234cf80a9636312d2288b2d7d256c
Sha384 367b0924ab547fda4f2a8beba4312520b38a59fd72515939df45210d5a1000708a03cb0e9594100ae859c350972b1fe4
Sha512 483fe3921682dc68bba148251471339539a86fca4013123ff0956a3f24f2ccdedb1aca546d0c0f7071ba5c3d27af19b6e192847b3af29b14f53e8e194996df40
SSDeep 192:HeRb6oBLsdbLyj9RukiLIj2J00a/SaFUlbVvevUqzh9SvNBajaWv:HeROolok972J00iUlM9zhQ3ajv
TLSH 00329D4BC4B6186AC3B7E87F905A04F2B11930114683B75D7D04F99BA351AE3138E6EE
[Content_Types].xml
_rels
.rels
xl
Malicious
_rels
workbook.xml.rels
workbook.xml
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 8 STICH kept: 3secondary ignored: 5
bin 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path oox:xlsm>oox:vba~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape oox:xlsm>oox:vba>scr:bat>scr:ps1
malicious 4 nodes
Path oox:xlsm>ole:doc
Shape oox:xlsm>ole:doc
2 nodes
Config. Field Value
URL in PowerShell #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
start huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙