Malicious
Malicious

dcb4c95311d6c9f5519b1f66a0b5aa26

MS Excel Document
MD5: dcb4c95311d6c9f5519b1f66a0b5aa26
Size: 2.34 MB
application/vnd.ms-excel
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dcb4c95311d6c9f5519b1f66a0b5aa26
Sha1 094b4e277e07d60c6f2b31b629a503e55d3268a0
Sha256 9d66bfddb6058cd175177ae545831d76c64b2a9a41585d81cb83a54d0eaf210b
Sha384 8a3c0bd0c7d0a1ee8e30928d3705e1053597f863aff9dd71dd67561a1720765f526f7a3ad1a623615315374d0c88f18b
Sha512 42f0ab6f1091f507f59ffb602c65b418529d3eee319b05c13bb735a9fea6c42b30c54d07d223306ac2e6bb935dfb3e4ba0781b3cd0931981c0d59b44cc876036
SSDeep 49152:Mpsc2PGcXoKIJTQHC1O1WXELed/oh+A1hDIvlppikESOe8cR:MpscN1BUC1O1W0TspvYSOZi
TLSH 1CB53322425B39F7D67E887B641CF8E52A0877C41089AC7A21D25C0B1775BEB9049FFE
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
_rels
sheet1.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
_rels
drawing1.xml.rels
media
image1.png
image1.png-preview.png
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Module4
Module5
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
ThisWorkbook
_VBA_PROJECT
customXml
item1.xml
itemProps1.xml
item2.xml
item3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docProps
core.xml
app.xml
dcb4c95311d6c9f5519b1f66a0b5aa26
0x00002D97.svg
0x00002D97.svg-preview.jpg
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
12 / 12
Path oox:xlsm~T1059.005>oox:media>img
Shape oox:xlsm>oox:media>img
technique3 nodes
Path oox:xlsm~T1059.005>bin
Shape oox:xlsm>bin
technique2 nodes
[Content_Types].xml
_rels
.rels
xl
Malicious
workbook.xml
_rels
workbook.xml.rels
worksheets
sheet1.xml
sheet2.xml
_rels
sheet1.xml.rels
theme
theme1.xml
styles.xml
sharedStrings.xml
drawings
drawing1.xml
_rels
drawing1.xml.rels
media
image1.png
image1.png-preview.png
vbaProject.bin
Malicious
Root Entry
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Module4
Module5
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
ThisWorkbook
_VBA_PROJECT
customXml
item1.xml
itemProps1.xml
item2.xml
item3.xml
_rels
item1.xml.rels
item2.xml.rels
item3.xml.rels
docProps
core.xml
app.xml
dcb4c95311d6c9f5519b1f66a0b5aa26
0x00002D97.svg
0x00002D97.svg-preview.jpg

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Module1
Blacklist VBA
VBA Macro
Module2
Blacklist VBA
VBA Macro
Module4
VBA Macro
Module5
VBA Macro
Module6
Blacklist VBA
VBA Macro
Module7
Blacklist VBA
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
ThisWorkbook
VBA Macro
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙