MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ea9628a6d531b6d190d3333aadf636aae7b87de423ab6975a92dabcf7fbf5f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Maldoc score: 1764


Intelligence 10 IOCs YARA 7 File information Comments

SHA256 hash: 7ea9628a6d531b6d190d3333aadf636aae7b87de423ab6975a92dabcf7fbf5f8
SHA3-384 hash: 6442c804df349776d2b4ebe13b1198fea9a3c88e0caa419ec907cc340ca932821534acede9aae08c0f54ac0e2571117a
SHA1 hash: 4605fc8647d1027234894d3b72f7eb4aabb00590
MD5 hash: ca92ffaa066de4a811e0ae179c1adbc2
humanhash: lemon-item-stream-pip
File name:R.E-LOECHES CAMBIO DE VALVULAS PTK30.xlsm
Download: download sample
File size:849'239 bytes
First seen:2026-08-05 12:53:44 UTC
Last seen:Never
File type:Excel file xlsm
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 12288:gLylMDadzn89+xamtgnZ+xTru0nTlOvchowFQcCbPYLuNTiCw317rvglDVCobOA2:guJ5nXMZi/n5OvchvQpJGCwvc2pBz
TLSH T1DC05122DF726899DCF2A943CC00803D79D0E595784E1A85E1E94BB443B5A4FF8F8E4AD
TrID 42.4% (.XLAM) Excel Macro-enabled Open XML add-in (83500/1/13)
29.2% (.XLSM) Excel Microsoft Office Open XML Format document (with Macro) (57500/1/12)
17.3% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
8.9% (.ZIP) Open Packaging Conventions container (17500/1/4)
2.0% (.ZIP) ZIP compressed archive (4000/1)
Magika xlsx
Reporter abuse_ch
Tags:xlsm

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 1764
File Format is MS Excel 2007+
Container Format is OpenXML
Office document contains VBA Macros
Office document contains 4 external relationships (see links below)
RelationshipExternal Link
hyperlink https://maximoapp.grupoclh.com/
hyperlink http://2.139.153.3:7710/meaweb/os/
hyperlink https://pmaximoapp.grupoclh.com/
hyperlink https://dmaximoapp.grupoclh.com/
Embedded Images

MalwareBazaar found the following images embedded in this file:

MD5 hashdc.creator# of relations
b6fee0c580077cafa778aac5283b303dBruno PortaluriNone
OLE dump

MalwareBazaar was able to identify 135 sections in this file using oledump:

Section IDSection sizeSection name
A12896 bytesPROJECT
A230 bytesPROJECTlk
A31328 bytesPROJECTwm
A412812 bytesVBA/ConvNodeToSheet
A512577 bytesVBA/ConvSheetToNode
A6998 bytesVBA/Hoja1
A764528 bytesVBA/Main
A81000 bytesVBA/MxAttrCfg
A91001 bytesVBA/MxConfig
A101055 bytesVBA/MxConfigH
A111004 bytesVBA/MxLoaderOS
A1225175 bytesVBA/MxMifService
A1317163 bytesVBA/MxNode
A149603 bytesVBA/MxNodeAttr
A1526928 bytesVBA/MxSheet
A16998 bytesVBA/MxTemplates
A1713803 bytesVBA/MxUtils
A1816465 bytesVBA/MxlConfig
A196146 bytesVBA/MxlLogger
A201914 bytesVBA/MxlObjAttr
A2122374 bytesVBA/MxlParseJson
A2213239 bytesVBA/MxlParseXml
A238408 bytesVBA/MxlPropFile
A248554 bytesVBA/Reg
A25998 bytesVBA/Sheet1
A26999 bytesVBA/Sheet16
A27999 bytesVBA/Sheet19
A28998 bytesVBA/Sheet2
A29999 bytesVBA/Sheet20
A30998 bytesVBA/Sheet3
A31999 bytesVBA/Sheet31
A32998 bytesVBA/Sheet4
A331007 bytesVBA/ThisWorkbook
A3424311 bytesVBA/_VBA_PROJECT
A3510701 bytesVBA/__SRP_0
A362895 bytesVBA/__SRP_1
A373751 bytesVBA/__SRP_2
A382056 bytesVBA/__SRP_3
A392883 bytesVBA/__SRP_4
A402112 bytesVBA/__SRP_5
A411039 bytesVBA/__SRP_6
A42492 bytesVBA/__SRP_7
A431483 bytesVBA/__SRP_8
A44602 bytesVBA/__SRP_9
A453586 bytesVBA/__SRP_a
A461914 bytesVBA/__SRP_b
A471279 bytesVBA/__SRP_c
A48656 bytesVBA/__SRP_d
A494472 bytesVBA/__SRP_e
A502132 bytesVBA/__SRP_f
A512894 bytesVBA/dir
A525165 bytesVBA/frmAbout
A531878 bytesVBA/frmConnOk
A548604 bytesVBA/frmError
A559841 bytesVBA/frmExport
A563479 bytesVBA/frmProgress
A575130 bytesVBA/frmProgressQuery
A585334 bytesVBA/frmProgressSynch
A592166 bytesVBA/frmPwdInput
A603140 bytesVBA/frmRegWarn
A612669 bytesVBA/frmResult
A622494 bytesVBA/frmResultQuery
A636913 bytesVBA/frmTemplates
A6431973 bytesVBA/frmWizard
A6597 bytesfrmAbout/CompObj
A66298 bytesfrmAbout/VBFrame
A67559 bytesfrmAbout/f
A689409 bytesfrmAbout/o
A6997 bytesfrmConnOk/CompObj
A70305 bytesfrmConnOk/VBFrame
A71447 bytesfrmConnOk/f
A72412 bytesfrmConnOk/o
A7397 bytesfrmError/CompObj
A74292 bytesfrmError/VBFrame
A75535 bytesfrmError/f
A76524 bytesfrmError/o
A7797 bytesfrmExport/CompObj
A78304 bytesfrmExport/VBFrame
A79783 bytesfrmExport/f
A80948 bytesfrmExport/o
A8197 bytesfrmProgress/CompObj
A82298 bytesfrmProgress/VBFrame
A83379 bytesfrmProgress/f
A84112 bytesfrmProgress/i04/CompObj
A85108 bytesfrmProgress/i04/f
A86112 bytesfrmProgress/i04/i12/CompObj
A8760 bytesfrmProgress/i04/i12/f
A880 bytesfrmProgress/i04/i12/o
A890 bytesfrmProgress/i04/o
A90292 bytesfrmProgress/o
A9197 bytesfrmProgressQuery/CompObj
A92299 bytesfrmProgressQuery/VBFrame
A93359 bytesfrmProgressQuery/f
A94112 bytesfrmProgressQuery/i21/CompObj
A95108 bytesfrmProgressQuery/i21/f
A96112 bytesfrmProgressQuery/i21/i22/CompObj
A9760 bytesfrmProgressQuery/i21/i22/f
A980 bytesfrmProgressQuery/i21/i22/o
A990 bytesfrmProgressQuery/i21/o
A100292 bytesfrmProgressQuery/o
A10197 bytesfrmProgressSynch/CompObj
A102334 bytesfrmProgressSynch/VBFrame
A1031239 bytesfrmProgressSynch/f
A104112 bytesfrmProgressSynch/i04/CompObj
A105108 bytesfrmProgressSynch/i04/f
A106112 bytesfrmProgressSynch/i04/i05/CompObj
A10760 bytesfrmProgressSynch/i04/i05/f
A1080 bytesfrmProgressSynch/i04/i05/o
A1090 bytesfrmProgressSynch/i04/o
A1101432 bytesfrmProgressSynch/o
A11197 bytesfrmPwdInput/CompObj
A112293 bytesfrmPwdInput/VBFrame
A113375 bytesfrmPwdInput/f
A114336 bytesfrmPwdInput/o
A11597 bytesfrmRegWarn/CompObj
A116308 bytesfrmRegWarn/VBFrame
A117223 bytesfrmRegWarn/f
A118288 bytesfrmRegWarn/o
A11997 bytesfrmResult/CompObj
A120296 bytesfrmResult/VBFrame
A121711 bytesfrmResult/f
A122752 bytesfrmResult/o
A12397 bytesfrmResultQuery/CompObj
A124302 bytesfrmResultQuery/VBFrame
A125615 bytesfrmResultQuery/f
A126656 bytesfrmResultQuery/o
A12797 bytesfrmTemplates/CompObj
A128304 bytesfrmTemplates/VBFrame
A129311 bytesfrmTemplates/f
A130284 bytesfrmTemplates/o
A13197 bytesfrmWizard/CompObj
A132299 bytesfrmWizard/VBFrame
A133895 bytesfrmWizard/f
A1341292 bytesfrmWizard/o
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExeccmdOk_ClickRuns when the file is opened and ActiveXobjects trigger events
AutoExectxtSearch_ChangeRuns when the file is opened and ActiveXobjects trigger events
IOChttps://bportaluri.com/mxloader-registrationURL
IOChttp://maximohost.com/URL
IOChttps://bportaluri.com/2021/04/mxloader-rest-query-where.htmlURL
IOChttps://www.ibm.com/developerworks/community/forums/html/top4526-8804-e2486565ffURL
IOChttps://bportaluri.com/2017/03/load-failure-codes-in-maximo.htmlURL
IOChttp://www.w3.org/2001/XMLSchema-instanceURL
IOChttps://en.wikipedia.org/wiki/Comma-separated_valuesURL
IOChttp://www.ibm.com/maximoURL
IOChttp://schemas.xmlsoap.org/soap/envelope/URL
IOChttp://www.normanbauer.com/2011/02/10/certificate-problems-with-vbscript-and-xml-http-calls/URL
IOChttp://www.logikdev.com/2010/07/07/use-serverxmlhttp-through-proxy/URL
IOChttps://moremaximo.com/discussion/autoscript-migration-with-mxloader-in-mas-instanceURL
IOChttps://www.json.org/json-en.htmlParseValueURL
IOChttps://github.com/VBA-tools/VBA-JSON/blob/master/JsonConverter.basURL
IOChttp://www.vbaccelerator.com/home/VB/Code/Techniques/RunTime_Debug_Tracing/VB6_Tracer_Utility_zip_cStringBuilder_cls.aspURL
IOChttps://github.com/VBA-tools/VBA-JSON/pull/82URL
IOChttps://bportaluri.com/mxloaderURL
IOChttps://bportaluri.com/mxloader/mxloader-changelogURL
IOChttps://bportaluri.c399URL
IOChttps://moremaximo.com/communities/commu-7d9b-4536-91d3-92892efefd61URL
IOChttps://stackoverflow.com/questions/17359835/what-is-the-difference-between-text-value-and-value2URL
IOChttps://www.ibm.com/developerworks/community/forums/html/top4153-8631-4484bf4b742aURL
IOChttps://www.motobit.com/tips/detpg_Base64/URL
IOChttp://Motobit.czURL
IOChttps://stackoverflow.com/questions/33734706/excels-fullname-property-with-onedriveURL
IOChttps://www.ibm.com/developerworks/community/forums/html/top48a1-b698-d1ba2f6262f-83aa-dc54e69955bdURL
IOChttps://gist.github.com/steve-jansen/7589478URLcode and P-code are different, this may havebeen used to hide malicious code
SuspiciousEnvironMay read system environment variables
SuspiciousenvironmentMay read system environment variables
SuspiciousOpenMay open a file
SuspiciousWriteMay write to a file (if combined with Open)
SuspiciousPutMay write to a file (if combined with Open)
SuspiciousOutputMay write to a file (if combined with Open)
SuspiciousbinaryMay read or write a binary file (if combinedwith Open)
SuspiciousFileCopyMay copy a file
SuspiciousKillMay delete a file
SuspiciousADODB.StreamMay create a text file
SuspiciousWriteTextMay create a text file
SuspiciousSaveToFileMay create a text file
SuspiciousRunMay run an executable file or a systemcommand
SuspiciouscreateMay execute file or a system command throughWMI
SuspiciousMkDirMay create a directory
SuspiciousCreateObjectMay create an OLE object
SuspiciousWindowsMay enumerate application windows (ifcombined with Shell.Application object)
SuspiciousUser-AgentMay download files from the Internet
SuspiciousChrMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousChrWMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousStrReverseMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousVBProjectMay attempt to modify the VBA code (self-modification)
SuspiciousVBComponentsMay attempt to modify the VBA code (self-modification)
SuspiciousSystemMay run an executable file or a systemcommand on a Mac (if combined withlibc.dylib)
SuspiciousHex StringsHex-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
158
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
xlsm
Verdict:
No threats detected
Analysis date:
2026-08-05 13:15:27 UTC
Tags:
macros

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
text/xml
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Launching a service
Searching for synchronization primitives
Result
Verdict:
Malicious
File Type:
Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive macros macros-on-event macros-on-open obfuscated
Verdict:
Malicious
Labled as:
Msoffice/malicious_confidence_100%
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl.evad
Score:
76 / 100
Signature
Antivirus detection for URL or domain
Document contains an embedded VBA macro which might access itself as a file (possible anti-VM)
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains an embedded VBA with functions possibly related to WSH operations (process, registry, environment, or keystrokes)
Document contains an embedded VBA with many string operations indicating source code obfuscation
Document contains VBA stomped code (only p-code) potentially bypassing AV detection
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
3 match(es)
Tags:
ADODB.Stream ATT&CK T1564.007 Blacklist VBA DeObfuscated Highly Suspicious Document Malicious Malicious Document MSXml2.DOMDocument Obfuscated Office Document Scripting.Dictionary Scripting.FileSystemObject T1027 T1059.005 VBA Stomping VBScript
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments