Malicious
Malicious

cb901bc9341105fdcea78b8d3748d8d8

Share on LinkedIn
Print
MS Office Document
MD5: cb901bc9341105fdcea78b8d3748d8d8
Size: 30.21 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cb901bc9341105fdcea78b8d3748d8d8
Sha1 0cd5f9ff898e05f2cbe06d60021d966509484983
Sha256 c9ddb200f3d9a8dee8830108c613e42b51d78576f1e9f9cc4349983d1418344e
Sha384 51b02384798942a4442a0acfccbee048718f616f821e80af5cf53eee5a677ee858bc5a487b8b0b7170458d6dd70a033f
Sha512 8e86c26cf6ef58738a6d0ddaeea688b75e0a05a4548d8d97719057c2c9268c9a0351cc3e98fcd5fefc2383a1de37eec891dccfe34665add1130470960acd5380
SSDeep 768:AKk3hOdsylKlgryzc4bNhZFGzE+cL2knAJDt1f1e2jC8GGQ:Dk3hOdsylKlgryzc4bNhZFGzE+cL2knJ
TLSH D0D23FA2B2D6D80AD94503394CE7C7E66726FC225F63838B3289F31E1F71AC08953657
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path ole:doc~T1027~T1059.005~T1105>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1027~T1059.005~T1105>ole:vba~T1059.005
Shape ole:doc>ole:vba
technique2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
imageshuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Dropped path (COM trace) #1 PATHmalicious
imageshuhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙