Suspicious
Suspect

dcca26b280913e7445c5a4a5ab29e461

MS Excel Document
MD5: dcca26b280913e7445c5a4a5ab29e461
Size: 3.07 MB
application/vnd.ms-excel

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 dcca26b280913e7445c5a4a5ab29e461
Sha1 fbb4f772b1de37fc002fe587b4ebc45727e40737
Sha256 25cfc4923dc84e2152a9621350d33a5aa76a28186de813316b5a2b6cd7df0ddb
Sha384 f67c68cab6ab127c0b5cc19d5071cd610968d6925b50d71270df1dfb5514849d758b2e357cb686c20911acfc180d8b61
Sha512 1bf73f25fe6bb95da880cf6d0706903c643c3e6293bf354759e2c835cdb73b9cec714a04de4f388b36713ff13c2b59a1ec0d490226b13a6361b41dd1f48cf3d2
SSDeep 49152:EOc2yD4lTPMS+bKw/8iAu1e8oqPPHjSXsxC9/O76SaAU0QbbOs6WIV4cUvSCZ2b:EoyEFPMSlA8if1oqP7SGC07eGWIV49Sx
TLSH 97E512BB98B268576B504667EB0F1C0A339B19D43B24D345EA41919C3F3B1D38EA2737
dcca26b280913e7445c5a4a5ab29e461
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
pcZiT1b9.06WL1J
Root Entry
qnvIwrtABl
OlE10NATIvE
docProps
core.xml
app.xml
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 7 STICH kept: 1secondary ignored: 6
bin 2oox:metadata 1oox:style 1oox:theme 1xml 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path oox:xlsx>oox:media>ole:doc
Shape oox:xlsx>oox:media>ole:doc
3 nodes
dcca26b280913e7445c5a4a5ab29e461
[Content_Types].xml
_rels
.rels
xl
_rels
workbook.xml.rels
workbook.xml
sharedStrings.xml
theme
theme1.xml
styles.xml
worksheets
sheet1.xml
_rels
sheet1.xml.rels
drawings
vmlDrawing1.vml
embeddings
pcZiT1b9.06WL1J
Root Entry
qnvIwrtABl
OlE10NATIvE
docProps
core.xml
app.xml
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙