Suspect
dbcff0beaec0ad19c11a28a2f1c50a96
MS Excel Document
MD5: dbcff0beaec0ad19c11a28a2f1c50a96
Size: 651.14 KB
application/vnd.ms-excel
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | dbcff0beaec0ad19c11a28a2f1c50a96 |
| Sha1 | 49e6375f4d3f0c86658f19937a529bbda5cdc828 |
| Sha256 | 4fc06941e07dbff9fe5756f2803fe0075f29a7eca3969db7947b4d33d8ff6601 |
| Sha384 | a014986d5a7a973dad044e24671d50821482f2a5b55a95eca17d36f8cf6f3e6e7070af6b855f867bd70036c79db541a3 |
| Sha512 | 19ae830f98cff50c623ced9021c606c4d2a039937b4d1e69f8bce8b5c5a56d4360c0de6117fdd3dfd9fef2e48bb6a668ddfc4c806b375916c987de23b5f7d713 |
| SSDeep | 12288:AwZvPYLSnYCby1bJ4ao7xh+wc28JlgQL9GZ:/BPszCbSbJ4/dh+p5TgQB+ |
| TLSH | 1CD4232E2413922FE5E136696D2D0C7D466DA0D2C2F1745CBACACA9714F13879B133AF |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 9
STICH kept: 2secondary ignored: 7
bin
2img
1oox:metadata
1oox:style
1oox:theme
1xml
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
oox:xlsx>oox:media>ole:doc
Shape
oox:xlsx>oox:media>ole:doc
3 nodes
Path
oox:xlsx>oox:rel:ext
Shape
oox:xlsx>oox:rel:ext
2 nodes
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › worksheets › _rels › sheet1.xml.rels
Remote Resource Reference
URIsuspect
https:huhuhuhuhuhuhu
dbcff0beaec0ad19c11a28a2f1c50a96 › xl › drawings › _rels › drawing1.xml.rels
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.