Suspicious
Suspect

d6ba5bbcb314030cea998a0c353a9bad

MS Excel Document
MD5: d6ba5bbcb314030cea998a0c353a9bad
Size: 4.82 MB
application/vnd.ms-excel

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d6ba5bbcb314030cea998a0c353a9bad
Sha1 63fa960d370a68108eb798413d9c629dbd35a696
Sha256 71fa5b48bd9f5a30f38be236a427c6a003edb31098f46d16dd8328e033f3bbd7
Sha384 971d984b02c1ed8e9f877f3bd5078b35c97d85e999a8a710049a56bf67c6f02bb13e2b4cc4855682b90c08d14971abfa
Sha512 ff4ce6fe7fad40e91c326157669719cde62f5b09d10fbbd965a337e64c2f7383775de543d1259b559e18356cb03ea770f2cf5686e1ae3ab4732d4f6603b15318
SSDeep 98304:yoyEFPZZitJ45gzjAr/z5ZoXXsnt6BcdmPfT51nXMI+VbKoTuRZbr7H:byEFPZZitJ424zQcdmPr51XMIqlTIbrT
TLSH 2E2623FB45B2A5536AA04667EB0F2C1A339B19E13614D342EA01919C3F7B1D38F92737
d6ba5bbcb314030cea998a0c353a9bad
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
Root Entry
3b8Ol46fdf
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:xlsx>oox:media>ole:doc
Shape oox:xlsx>oox:media>ole:doc
3 nodes
d6ba5bbcb314030cea998a0c353a9bad
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
Root Entry
3b8Ol46fdf
docProps
core.xml
app.xml
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙