Suspicious
Suspect

dbcff0beaec0ad19c11a28a2f1c50a96

Share on LinkedIn
Print
MS Excel Document
MD5: dbcff0beaec0ad19c11a28a2f1c50a96
Size: 651.14 KB
application/vnd.ms-excel

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dbcff0beaec0ad19c11a28a2f1c50a96
Sha1 49e6375f4d3f0c86658f19937a529bbda5cdc828
Sha256 4fc06941e07dbff9fe5756f2803fe0075f29a7eca3969db7947b4d33d8ff6601
Sha384 a014986d5a7a973dad044e24671d50821482f2a5b55a95eca17d36f8cf6f3e6e7070af6b855f867bd70036c79db541a3
Sha512 19ae830f98cff50c623ced9021c606c4d2a039937b4d1e69f8bce8b5c5a56d4360c0de6117fdd3dfd9fef2e48bb6a668ddfc4c806b375916c987de23b5f7d713
SSDeep 12288:AwZvPYLSnYCby1bJ4ao7xh+wc28JlgQL9GZ:/BPszCbSbJ4/dh+p5TgQB+
TLSH 1CD4232E2413922FE5E136696D2D0C7D466DA0D2C2F1745CBACACA9714F13879B133AF
dbcff0beaec0ad19c11a28a2f1c50a96
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
theme
theme1.xml
drawings
_rels
drawing1.xml
vmlDrawing1.vml
worksheets
sheet2.xml
sheet1.xml
media
image1.jpeg
image1.jpeg-preview.png
sharedStrings.xml
styles.xml
printerSettings
printerSettings1.bin
embeddings
Root Entry
miUP64fPjVgfNg5lEmzo8C
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 9 STICH kept: 2secondary ignored: 7
bin 2img 1oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:xlsx>oox:media>ole:doc
Shape oox:xlsx>oox:media>ole:doc
3 nodes
Path oox:xlsx>oox:rel:ext
Shape oox:xlsx>oox:rel:ext
2 nodes
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Remote Resource Reference URIsuspect
https:huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙