Malicious
Malicious

ce37733a06f8241a9c154fc6dbbd7961

MS Excel Document
MD5: ce37733a06f8241a9c154fc6dbbd7961
Size: 569.43 KB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ce37733a06f8241a9c154fc6dbbd7961
Sha1 e18c9c4e8078384f260691197d5b9f97b5fcec4a
Sha256 aa35fc0f401673c49ade59da35761175d5de7cbc1fe3537bbd2c0a5401468920
Sha384 f84c0e1cef952f10ee9be55e1d2df3514669517f88a3c0a348396c269def3f349b9d89477856e4d36e58f6824551f634
Sha512 ddab177b03665facfe705a3695f39ae05bbf26181f2b4155c5053ff2893ecf8f6e4d848423d9b1e3aaaf4d4a9c6181f7049dae54b7e73c96d815b569fcfb0e11
SSDeep 12288:8poA8COkjk6+/E1UJxgxqWOr2/28+Eecj9HleuxdYZ0:woBkIj/AGxKqWc2uZEe6F7x20
TLSH 3EC4231AD301FC49CB1358BF941CD5A33E866C995006FB4F3941F6AE07A61CE87EE2A5
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
_rels
sheet5.xml.rels
sheet1.xml.rels
sheet3.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
_rels
drawing5.xml.rels
drawing7.xml.rels
drawing2.xml.rels
drawing3.xml.rels
drawing2.xml
drawing3.xml
drawing4.xml
drawing5.xml
drawing6.xml
drawing7.xml
media
image1.png
image1.png-preview.png
image2.png
image2.png-preview.png
image3.png
image3.png-preview.png
image4.png
image4.png-preview.png
image5.png
image5.png-preview.png
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet17
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
_VBA_PROJECT
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings3.bin
printerSettings8.bin
printerSettings7.bin
printerSettings6.bin
printerSettings5.bin
tables
table1.xml
calcChain.xml
customXml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
itemProps3.xml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docProps
core.xml
app.xml
custom.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
15 / 15
Path oox:xlsm~T1027~T1059.005~T1564.007>oox:media>img
Shape oox:xlsm>oox:media>img
malicious 3 nodes
Path oox:xlsm~T1027~T1059.005~T1564.007>bin
Shape oox:xlsm>bin
malicious 2 nodes
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
sheet3.xml
sheet4.xml
sheet5.xml
sheet6.xml
sheet7.xml
sheet8.xml
sheet9.xml
sheet10.xml
sheet11.xml
sheet12.xml
sheet13.xml
_rels
sheet5.xml.rels
sheet1.xml.rels
sheet3.xml.rels
sheet6.xml.rels
sheet7.xml.rels
sheet8.xml.rels
sheet9.xml.rels
sheet10.xml.rels
sheet11.xml.rels
sheet12.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
_rels
drawing5.xml.rels
drawing7.xml.rels
drawing2.xml.rels
drawing3.xml.rels
drawing2.xml
drawing3.xml
drawing4.xml
drawing5.xml
drawing6.xml
drawing7.xml
media
image1.png
image1.png-preview.png
image2.png
image2.png-preview.png
image3.png
image3.png-preview.png
image4.png
image4.png-preview.png
image5.png
image5.png-preview.png
image6.png
image6.png-preview.png
image7.png
image7.png-preview.png
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet17
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
_VBA_PROJECT
printerSettings
printerSettings1.bin
printerSettings2.bin
printerSettings3.bin
printerSettings8.bin
printerSettings7.bin
printerSettings6.bin
printerSettings5.bin
tables
table1.xml
calcChain.xml
customXml
itemProps1.xml
item2.xml
itemProps2.xml
item3.xml
itemProps3.xml
item1.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docProps
core.xml
app.xml
custom.xml

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
CSHA256
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Sheet17
VBA Macro
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙