Malicious
Malicious

f8de24d35a004e158a594303c04d4d85

MS Office Document
MD5: f8de24d35a004e158a594303c04d4d85
Size: 3.6 MB
application/vnd.ms-office
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 f8de24d35a004e158a594303c04d4d85
Sha1 a7ff51a83cc52836a9c4e1232aff7fbdb3b4d651
Sha256 5865cccca8ec217c98d0eca0b312c53d8b0c7e33318b847d369a03a385324e64
Sha384 3204e962eea459bbe97fd7f37c61206e70af2c99e20c22f76dd8ee2bcdb61d51cd7efe574aed62ce19dd35d41e30ccb2
Sha512 1ce5543a3eaad7586474f0218d5b6f3cc85ca2ec420e737d7b79e6e67bab18df1b6ca98c905fa74313a7421aa180484feb99791691abaa508f1627d9b56cc2cc
SSDeep 24576:cKl+JHcCwAs11L+qjxm7UITiwgJ5B77WMsFhSNLJ7Uq9B5Y7:AcTjsiwbgBy7
TLSH 9AF56663E62E0B6BC4398B78428F5B906318DC1B36915B471B5D3E68FDAECD3E931508
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
_VBA_PROJECT_CUR
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet1
Module2
Module3
Module4
Module5
Module6
Module7
Module9
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
Module10
Module11
Module14
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
ThisWorkbook
_VBA_PROJECT.deobfuscated.vbs
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
10 / 10
Path ole:doc~T1027~T1059~T1059.005~T1564.007>bin
Shape ole:doc>bin
malicious 2 nodes
Path ole:doc~T1027~T1059~T1059.005~T1564.007>ole:vba~T1059.005
Shape ole:doc>ole:vba
malicious 2 nodes
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Root Entry
Malicious
CompObj
Workbook
SummaryInformation
DocumentSummaryInformation
_VBA_PROJECT_CUR
Malicious
PROJECT
PROJECTwm
VBA
Malicious
dir
Sheet1
Module2
Module3
Module4
Module5
Module6
Module7
Module9
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
__SRP_8
__SRP_9
__SRP_a
__SRP_b
__SRP_c
__SRP_d
__SRP_e
__SRP_f
Module10
Module11
Module14
__SRP_10
__SRP_11
__SRP_12
__SRP_13
__SRP_14
__SRP_15
__SRP_16
__SRP_17
__SRP_18
__SRP_19
__SRP_1a
__SRP_1b
__SRP_1c
__SRP_1d
__SRP_1e
__SRP_1f
__SRP_20
__SRP_21
__SRP_22
__SRP_23
__SRP_24
__SRP_25
__SRP_26
__SRP_27
__SRP_28
__SRP_29
__SRP_2a
__SRP_2b
ThisWorkbook
_VBA_PROJECT.deobfuscated.vbs

vbaDNA - VBA Stomping & Purging Stategy detection

Module Name
Sheet1
VBA Macro
Module1
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro

Missing P-Code: The Office document under analysis has been identified as having undergone VBA Purging techniques, as the P-Code block within the document is currently inaccessible. As a result, the decompilation of the code was not possible, leaving only the stored code available in textual format for analysis.

VBA Purging essentially involves the elimination of the PerformanceCache section from the module streams.

To fully erase any traces of the P-Code section, the MODULEOFFSET between the two sections is adjusted to 0 by altering the _VBA_PROJECT stream, and all SRP streams that also house PerformanceCache data are removed. Following the removal of the compiled code, antivirus engines and Yara rules, which depend on precise string matches, are rendered ineffective.

This allows macros to bypass them effortlessly, owing to the compressed format of the remaining source code.

Module2
VBA Macro
Module3
VBA Macro
Module4
VBA Macro
Module5
VBA Macro
Module6
VBA Macro
Module7
VBA Macro
Module9
VBA Macro
Module10
VBA Macro
Module11
VBA Macro
Module12
VBA Stomping
ATT&CK T1564.007
Malicious
Malicious Document
VBA Macro
vbaDNA free preview is limited to 3 modules. Unlock the full module analysis (decompiled P-Code, stomping diffs).
Unlock with Essential
Module14
VBA Macro
ThisWorkbook
VBA Macro
Config. Field Value
URL (COM trace) #1 https:huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 4huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module12 › [Stored VBA]
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Stored VBA]
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Stored VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Stored VBA]
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Stored VBA]
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Stored VBA]
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Full Diff]
Trace COM ordonnée UNKNWOWNmalicious
line 7huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Full Diff]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Full Diff]
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Full Diff]
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Full Diff]
Command (COM trace) #1 UNKNWOWNmalicious
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Decompiled VBA]
Trace COM ordonnée UNKNWOWNmalicious
line 8huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Decompiled VBA]
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Decompiled VBA]
URLs in VB Code - #2 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Decompiled VBA]
URLs in VB Code - #3 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
f8de24d35a004e158a594303c04d4d85 › Root Entry › _VBA_PROJECT_CUR › VBA › Module15 › [Decompiled VBA]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙