Malicious
Malicious

cb901bc9341105fdcea78b8d3748d8d8

MS Office Document
MD5: cb901bc9341105fdcea78b8d3748d8d8
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cb901bc9341105fdcea78b8d3748d8d8
Sha1 0cd5f9ff898e05f2cbe06d60021d966509484983
Sha256 c9ddb200f3d9a8dee8830108c613e42b51d78576f1e9f9cc4349983d1418344e
Sha384 51b02384798942a4442a0acfccbee048718f616f821e80af5cf53eee5a677ee858bc5a487b8b0b7170458d6dd70a033f
Sha512 8e86c26cf6ef58738a6d0ddaeea688b75e0a05a4548d8d97719057c2c9268c9a0351cc3e98fcd5fefc2383a1de37eec891dccfe34665add1130470960acd5380
SSDeep 768:AKk3hOdsylKlgryzc4bNhZFGzE+cL2knAJDt1f1e2jC8GGQ:Dk3hOdsylKlgryzc4bNhZFGzE+cL2knJ
TLSH D0D23FA2B2D6D80AD94503394CE7C7E66726FC225F63838B3289F31E1F71AC08953657
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path ole:doc~T1027~T1059.005~T1105>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1027~T1059.005~T1105>ole:vba~T1059.005
Shape ole:doc>ole:vba
technique2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
imageshuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
Blacklist VBA
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

ThisWorkbook
VBA Macro
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhu
cb901bc9341105fdcea78b8d3748d8d8
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
cb901bc9341105fdcea78b8d3748d8d8
Dropped path (COM trace) #1 PATHmalicious
imageshuhuhuhuhuhuhuhuhuhuhu
cb901bc9341105fdcea78b8d3748d8d8 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Decompiled VBA]
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
cb901bc9341105fdcea78b8d3748d8d8 › Root Entry › _VBA_PROJECT_CUR › VBA › Module1 › [Decompiled VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙