Malicious
Malicious

504368519288583f7d6b6981c641b4b9509bde[...]392.doc

MS Office Document
MD5: e267aa39a15e33909dae39ec74828f8b
Size: 183.3 KB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e267aa39a15e33909dae39ec74828f8b
Sha1 ed519641868e38c0531358622bc10b863979e301
Sha256 504368519288583f7d6b6981c641b4b9509bdee7aac1e0d6c2371fc952451392
Sha384 4fa776934204d8846118c4393f52393839272ec42b15309d3b2fd840b0dcb53908415abcbdd1d504c50a2ee55af028a4
Sha512 95d9712e8f760e589761337376b329c28e9b5ee2d6ededd77e9dae29dc5dab41927f382562848bd3e2dfeb72859ec6d373335cc51d6c91bf60c1a10da735bb8e
SSDeep 3072:Ean7O40C8HRLzZI5Cb1WdqfzdVWnTqUJxDZaQnRBvbmV8tbB:Ean7t0tRHK5C+qfzdVoqwB8Qqk
TLSH E0047B13A944CF43D03847B93D978EAD2B2A6E089C41A3EB21743F8F7E751911D9E26D
504368519288583f7d6b6981c641b4b9509bdee7aac1e0d6c2371fc952451392.doc
Malicious
Root Entry
Data
1Table
CompObj
WordDocument
SummaryInformation
DocumentSummaryInformation
Macros
PROJECT
PROJECTwm
VBA
dir
ThisDocument
_VBA_PROJECT
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path ole:doc~T1059.005>bin
Shape ole:doc>bin
technique2 nodes
Path ole:doc~T1059.005>ole:vba
Shape ole:doc>ole:vba
technique2 nodes
504368519288583f7d6b6981c641b4b9509bdee7aac1e0d6c2371fc952451392.doc
Malicious
Root Entry
Data
1Table
CompObj
WordDocument
SummaryInformation
DocumentSummaryInformation
Macros
PROJECT
PROJECTwm
VBA
dir
ThisDocument
_VBA_PROJECT

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
ThisDocument
VBA Macro
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙