MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27d657176b8217b7ac3cf5e38f49b8ff064dcd9fc25759e351ae014b015d35c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Maldoc score: 35


Intelligence 9 IOCs YARA 7 File information Comments

SHA256 hash: 27d657176b8217b7ac3cf5e38f49b8ff064dcd9fc25759e351ae014b015d35c7
SHA3-384 hash: 57cc586b3970af9a99eb67fb76c174e40069253c3fe21c9978a88d749bedd85725c34652d7e5576d95b5c09fc5d55a25
SHA1 hash: 6f646db834cf1d9fe8f9cf11b1d5666f77eaff06
MD5 hash: 1c301cf396b2bf57458e057b24e50213
humanhash: wisconsin-april-early-bulldog
File name:CensoLocalCed11_2026.xlsm
Download: download sample
File size:1'143'760 bytes
First seen:2026-08-05 07:42:56 UTC
Last seen:Never
File type:Excel file xlsm
MIME type:application/octet-stream
ssdeep 24576:gPGPHupaKWEzGZqOALOLs+W9Tz5DHPQTJsvyOP+pBXwW:ARfpLdXNHPwJr17wW
TLSH T18035122BFF0C8035F68361F8E21AEB446482355F488574867DAB69BC2F5BB2D97406CD
TrID 42.4% (.XLAM) Excel Macro-enabled Open XML add-in (83500/1/13)
29.2% (.XLSM) Excel Microsoft Office Open XML Format document (with Macro) (57500/1/12)
17.3% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
8.9% (.ZIP) Open Packaging Conventions container (17500/1/4)
2.0% (.ZIP) ZIP compressed archive (4000/1)
Magika xlsx
Reporter abuse_ch
Tags:xlsm

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 35
File Format is MS Excel 2007+
Container Format is OpenXML
Office document contains VBA Macros
Office document contains 2 external relationships (see links below)
RelationshipExternal Link
hyperlink https://goo.su/opLECxx
hyperlink https://goo.su/9fyzAz
Embedded Images

MalwareBazaar found the following images embedded in this file:

MD5 hashdc.creator# of relations
9e6f02c81eaf6c574bbf697b59f133e2CRISTIAN PASTOR TORIBIO2
073d48ed4271766a76499dbaec8bf18cCRISTIAN PASTOR TORIBIO2
af24674d58801104da36d58f0e6ba09cCRISTIAN PASTOR TORIBIO2
e44757a4ee5a4b36733b9edd06388cbaCRISTIAN PASTOR TORIBIO2
10c5c336d411a0e35075005329ad9a63CRISTIAN PASTOR TORIBIO2
cb977c2dd4ec8c778a310a713c362180CRISTIAN PASTOR TORIBIO2
79fb8c81c25b8382d78edba2e9af6205CRISTIAN PASTOR TORIBIO2
12fc8a98fc73f2a47072d8d7ab6acc4aCRISTIAN PASTOR TORIBIO2
415c0caf28f56b6f5199c2d607365d4bCRISTIAN PASTOR TORIBIO2
8f3d9bd52126157de5f29c763b419f29CRISTIAN PASTOR TORIBIO2
OLE dump

MalwareBazaar was able to identify 80 sections in this file using oledump:

Section IDSection sizeSection name
A197 bytesLoginUserForm/CompObj
A2314 bytesLoginUserForm/VBFrame
A3463 bytesLoginUserForm/f
A4560 bytesLoginUserForm/o
A51692 bytesPROJECT
A6692 bytesPROJECTwm
A71030 bytesVBA/Hoja1
A83963 bytesVBA/Hoja10
A99418 bytesVBA/Hoja11
A105338 bytesVBA/Hoja12
A114846 bytesVBA/Hoja13
A121031 bytesVBA/Hoja14
A1317131 bytesVBA/Hoja2
A148412 bytesVBA/Hoja3
A1531630 bytesVBA/Hoja4
A167027 bytesVBA/Hoja5
A178760 bytesVBA/Hoja6
A1812365 bytesVBA/Hoja7
A199669 bytesVBA/Hoja8
A207758 bytesVBA/Hoja9
A212384 bytesVBA/LoginUserForm
A224963 bytesVBA/ModCapitulo4
A235613 bytesVBA/ModCapitulo5
A248684 bytesVBA/ModCapitulo6
A2510349 bytesVBA/ModCapitulo7
A267497 bytesVBA/ModCapitulo8
A275729 bytesVBA/ModCapitulo9
A2893843 bytesVBA/ModEnvioData
A29196487 bytesVBA/ModValidacion
A304099 bytesVBA/ThisWorkbook
A3112918 bytesVBA/_VBA_PROJECT
A3228640 bytesVBA/__SRP_0
A331319 bytesVBA/__SRP_1
A34214 bytesVBA/__SRP_10
A35252 bytesVBA/__SRP_11
A361752 bytesVBA/__SRP_12
A3736817 bytesVBA/__SRP_13
A381064 bytesVBA/__SRP_14
A39306 bytesVBA/__SRP_15
A408516 bytesVBA/__SRP_16
A41282 bytesVBA/__SRP_17
A42950 bytesVBA/__SRP_18
A43282 bytesVBA/__SRP_19
A44950 bytesVBA/__SRP_1a
A45282 bytesVBA/__SRP_1b
A46282 bytesVBA/__SRP_1c
A4729784 bytesVBA/__SRP_1d
A48950 bytesVBA/__SRP_1e
A49282 bytesVBA/__SRP_1f
A50212 bytesVBA/__SRP_2
A51232 bytesVBA/__SRP_20
A5217934 bytesVBA/__SRP_21
A53950 bytesVBA/__SRP_22
A54282 bytesVBA/__SRP_23
A553926 bytesVBA/__SRP_24
A56282 bytesVBA/__SRP_25
A5710246 bytesVBA/__SRP_26
A58282 bytesVBA/__SRP_27
A59950 bytesVBA/__SRP_28
A60282 bytesVBA/__SRP_29
A614868 bytesVBA/__SRP_2a
A62282 bytesVBA/__SRP_2b
A633108 bytesVBA/__SRP_2c
A64206 bytesVBA/__SRP_2d
A65206 bytesVBA/__SRP_3
A66169 bytesVBA/__SRP_4
A67156 bytesVBA/__SRP_5
A68169 bytesVBA/__SRP_6
A69156 bytesVBA/__SRP_7
A70625 bytesVBA/__SRP_8
A71362 bytesVBA/__SRP_9
A72169 bytesVBA/__SRP_a
A73156 bytesVBA/__SRP_b
A74169 bytesVBA/__SRP_c
A75156 bytesVBA/__SRP_d
A76169 bytesVBA/__SRP_e
A77156 bytesVBA/__SRP_f
A781546 bytesVBA/dir
A794016 bytesVBA/mdAesCtr
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecWorkbook_OpenRuns when the Excel Workbook is opened
AutoExecMod01_Next_ClickRuns when the file is opened and ActiveXobjects trigger events
AutoExecWorksheet_ChangeRuns when the file is opened and ActiveXobjects trigger events
Base647m6N202
Base64Sm6U202
Base643mvM212
Base64c_wY193
Base64S_8U184
Base64Sm:U206
Base64_m:X206
Base64PaUGEL
Base64Sm5U201
Base64Sm7U203
Base64Sm8U204
Base64Sm9U205
IOChttp://67.222.146.46:8009/estadistica/URL
IOChttps://escale2.minedu.gob.pe:8009/estadistica/URL
IOChttps://escale2-qa.minedu.gob.peURL
IOChttps://escale2.minedu.gob.peURL
IOC67.222.146.46IPv4 address
Stringcode and P-code are different, this may havebeen used to hide malicious code
SuspiciousOpenMay open a file
SuspiciousWriteMay write to a file (if combined with Open)
SuspiciousOutputMay write to a file (if combined with Open)
SuspiciousShellMay run an executable file or a systemcommand
SuspiciousCreateObjectMay create an OLE object
SuspiciousMSXML2.XMLHTTPMay download files from the Internet
SuspiciousMicrosoft.XMLHTTPMay download files from the Internet
SuspiciousChrMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousSystemMay run an executable file or a systemcommand on a Mac (if combined withlibc.dylib)
SuspiciousHex StringsHex-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
289
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
xlsm
Verdict:
No threats detected
Analysis date:
2026-08-05 07:56:18 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
text/xml
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Launching a service
Searching for synchronization primitives
Result
Verdict:
Malicious
File Type:
Excel File with Macro
Payload URLs
URL
File name
67.222.146.46
Hoja10
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive explorer lolbin macros macros-on-event macros-on-open
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad.expl
Score:
60 / 100
Signature
Creates and opens a fake document (probably a fake document to hide exploiting)
Document contains an embedded VBA with base64 encoded strings
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains an embedded VBA with many string operations indicating source code obfuscation
Downloads suspicious files via Chrome
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1952442 Sample: CensoLocalCed11_2026.xlsm Startdate: 05/08/2026 Architecture: WINDOWS Score: 60 55 us1.roaming1.live.com.akadns.net 2->55 57 statics-teams-cdn-office-net.s-0005.dual-s-msedge.net 2->57 59 13 other IPs or domains 2->59 85 Document contains an embedded VBA with base64 encoded strings 2->85 87 Document contains an embedded VBA with functions possibly related to HTTP operations 2->87 89 Document contains an embedded VBA with many string operations indicating source code obfuscation 2->89 91 Downloads suspicious files via Chrome 2->91 10 chrome.exe 19 2->10         started        14 unarchiver.exe 2->14         started        17 EXCEL.EXE 505 61 2->17         started        19 chrome.exe 2->19         started        signatures3 process4 dnsIp5 67 192.168.2.24, 137, 138, 443 unknown unknown 10->67 69 192.168.2.27 unknown unknown 10->69 47 INFO App GeoLOCALE...6Z-1-001.zip (copy), Zip 10->47 dropped 49 INFO App GeoLOCALE...6Z-1-001.zip (copy), Zip 10->49 dropped 51 INFO App GeoLOCALE...2Z-1-001.zip (copy), Zip 10->51 dropped 53 2 other malicious files 10->53 dropped 21 chrome.exe 10->21         started        95 Creates and opens a fake document (probably a fake document to hide exploiting) 14->95 24 cmd.exe 14->24         started        27 7za.exe 14->27         started        71 mr-z01.tm-azurefd.net 150.171.109.72, 443, 62813, 62828 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 17->71 73 52.110.2.203, 443, 62816 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 17->73 75 res-ocdi-stls-prod.edgesuite.net 23.210.73.83, 443, 62818 AKAMAI-ASN1NL United States 17->75 29 splwow64.exe 17->29         started        file6 signatures7 process8 dnsIp9 61 goo.su 82.202.170.126, 443, 52581, 53178 RU-JSCIOTRU Russia 21->61 63 142.250.188.10, 443, 50735, 51274 GOOGLE-GoogleLLCUS United States 21->63 65 23 other IPs or domains 21->65 93 Creates and opens a fake document (probably a fake document to hide exploiting) 24->93 31 Acrobat.exe 24->31         started        34 conhost.exe 24->34         started        36 conhost.exe 27->36         started        signatures10 process11 dnsIp12 83 34.233.49.149 AMAZON-AES-AmazoncomIncUS United States 31->83 38 AcroCEF.exe 31->38         started        40 AdobeCollabSync.exe 31->40         started        process13 process14 42 AcroCEF.exe 38->42         started        45 AdobeCollabSync.exe 40->45         started        dnsIp15 77 172.64.41.3 CLOUDFLARENET-CloudflareIncUS Canada 42->77 79 50.16.47.176 AMAZON-AES-AmazoncomIncUS United States 42->79 81 23.222.124.189 AKAMAI-AS-AkamaiTechnologiesIncUS United States 42->81
Verdict:
Malware
YARA:
3 match(es)
Tags:
Blacklist VBA DeObfuscated Microsoft.XMLHTTP Moderately Suspicious Document Msxml.DOMDocument Obfuscated Office Document System.Security.Cryptography.RijndaelManaged System.Security.Cryptography.ToBase64Transform System.Text.UTF8Encoding T1027 T1059.005 VBScript
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments