Malicious
Malicious

ca92ffaa066de4a811e0ae179c1adbc2

Share on LinkedIn
Print
MS Excel Document
MD5: ca92ffaa066de4a811e0ae179c1adbc2
Size: 849.24 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ca92ffaa066de4a811e0ae179c1adbc2
Sha1 4605fc8647d1027234894d3b72f7eb4aabb00590
Sha256 7ea9628a6d531b6d190d3333aadf636aae7b87de423ab6975a92dabcf7fbf5f8
Sha384 02e13f615a5ce1c6554443e26ab999d6d800e974c5ba7a383a905aa0bafe55a97b4316f440eac50cd167d323fa49a6f4
Sha512 3e0a5b9f0104a7218de647703159887d34d91ddfb0f7b0394e9cd4931b667bff9d9f3a16485896307aaea8f5eaeedf059c60dcd0cbe5581626ff97b42bd44017
SSDeep 12288:gLylMDadzn89+xamtgnZ+xTru0nTlOvchowFQcCbPYLuNTiCw317rvglDVCobOA2:guJ5nXMZi/n5OvchvQpJGCwvc2pBz
TLSH DC05122DF726899DCF2A943CC00803D79D0E595784E1A85E1E94BB443B5A4FF8F8E4AD
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
sheet14.xml
sheet15.xml
sheet16.xml
sheet17.xml
sheet18.xml
sheet19.xml
sheet20.xml
sheet21.xml
sheet22.xml
sheet23.xml
sheet24.xml
sheet25.xml
sheet26.xml
sheet27.xml
sheet28.xml
_rels
sheet12.xml.rels
sheet13.xml.rels
sheet14.xml.rels
sheet15.xml.rels
sheet16.xml.rels
sheet17.xml.rels
sheet19.xml.rels
sheet20.xml.rels
sheet21.xml.rels
sheet22.xml.rels
sheet23.xml.rels
sheet24.xml.rels
sheet25.xml.rels
sheet26.xml.rels
sheet27.xml.rels
sheet28.xml.rels
sheet18.xml.rels
sheet3.xml.rels
sheet2.xml.rels
sheet4.xml.rels
sheet5.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
vmlDrawing1.vml
drawing2.xml
vmlDrawing2.vml
vmlDrawing3.vml
_rels
drawing2.xml.rels
media
image1.png
image1.png-preview.png
Root Entry
Malicious
PROJECT
PROJECTlk
PROJECTwm
VBA
Malicious
dir
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
frmError
frmConnOk
frmResult
MxConfigH
MxlConfig
MxlLogger
MxlObjAttr
frmProgress
frmPwdInput
MxlParseXml
MxlPropFile
frmTemplates
_VBA_PROJECT.deobfuscated.vbs
frmResultQuery
ConvSheetToNode
frmProgressSynch
frmAbout
f
o
CompObj
VBFrame
frmError
f
o
VBFrame
frmConnOk
f
o
VBFrame
frmExport
f
o
VBFrame
frmResult
f
o
VBFrame
frmWizard
f
o
VBFrame
frmRegWarn
f
o
VBFrame
frmProgress
f
o
VBFrame
i04
f
o
CompObj
i12
f
frmPwdInput
f
o
VBFrame
frmTemplates
f
o
VBFrame
frmResultQuery
f
o
VBFrame
frmProgressQuery
f
o
VBFrame
i21
f
frmProgressSynch
f
o
VBFrame
i04
f
i05
f
metadata.xml
printerSettings
printerSettings1.bin
printerSettings10.bin
ctrlProps
ctrlProp1.xml
comments1.xml
comments2.xml
tables
table1.xml
calcChain.xml
customXml
item1.xml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
itemProps3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docMetadata
LabelInfo.xml
docProps
core.xml
app.xml
custom.xml
userCustomization
customUI.xml
customUI
customUI.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
15 / 15
Path oox:xlsm~T1027~T1059.005~T1564.007>oox:media>img
Shape oox:xlsm>oox:media>img
malicious 3 nodes
Path oox:xlsm~T1027~T1059.005~T1564.007>bin
Shape oox:xlsm>bin
malicious 2 nodes
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
fihuhuhuhu
URLs in VB Code - #1 URIsuspect
fihuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙