MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5c9b643b5c7e4f1ca90f8f6ccaeb24f681441ce9fecbe5154416ad661143b2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Maldoc score: 23


Intelligence 11 IOCs YARA 7 File information Comments

SHA256 hash: d5c9b643b5c7e4f1ca90f8f6ccaeb24f681441ce9fecbe5154416ad661143b2e
SHA3-384 hash: 5f36d172155d1092158a20c9ec57e86a0910d4ed71bb8e78c954911b61e8e62f0e76371f0a0a4eab38d85f2b2b4e4dba
SHA1 hash: 924f979eab2ae7329fe03edcb5bf7914919ade7c
MD5 hash: 986f66510d4e0701f47d0c3b35d705e2
humanhash: missouri-snake-kansas-sixteen
File name:presupuestos_inhabi.xlsm
Download: download sample
File size:1'304'461 bytes
First seen:2026-06-24 08:11:18 UTC
Last seen:Never
File type:Excel file xlsm
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 24576:NLdoU9BiwIiaa9dAYWeSDz8aCea9YWDru8eRv0o123bT0o1K5:UqUziH9dAYWTDXCT9ZriR8pEoE5
TLSH T13455012DDA02AA1CD22A943CC30F74D1D988A0637201E91F399DFD191F872E7975EE9D
TrID 40.3% (.XLAM) Excel Macro-enabled Open XML add-in (83500/1/13)
27.7% (.XLSM) Excel Microsoft Office Open XML Format document (with Macro) (57500/1/12)
16.4% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
8.4% (.ZIP) Open Packaging Conventions container (17500/1/4)
5.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
Magika xlsx
Reporter abuse_ch
Tags:xlsm

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 23
File Format is MS Excel 2007+
Container Format is OpenXML
Office document contains VBA Macros
Embedded Images

MalwareBazaar found the following images embedded in this file:

MD5 hashdc.creator# of relations
4ad6fedb22369f395cd6a8610506741cmarroNone
8cff9f5bcb69770de027a4d2066ac2c3marroNone
44ad10b17a7bbd5fd53b5ea74d9a5a0dmarroNone
d472d91f68338bc935f1efcbdf31d52cmarroNone
OLE dump

MalwareBazaar was able to identify 143 sections in this file using oledump:

Section IDSection sizeSection name
A14965 bytesPROJECT
A22099 bytesPROJECTwm
A397 bytesUserForm1/CompObj
A4304 bytesUserForm1/VBFrame
A5867 bytesUserForm1/f
A6112 bytesUserForm1/i14/CompObj
A7157 bytesUserForm1/i14/f
A8120 bytesUserForm1/i14/o
A9896 bytesUserForm1/o
A101050 bytesVBA/Hoja1
A111051 bytesVBA/Hoja10
A121051 bytesVBA/Hoja11
A131051 bytesVBA/Hoja12
A141051 bytesVBA/Hoja13
A151051 bytesVBA/Hoja14
A161051 bytesVBA/Hoja15
A171051 bytesVBA/Hoja16
A181051 bytesVBA/Hoja17
A191051 bytesVBA/Hoja18
A201232 bytesVBA/Hoja19
A211231 bytesVBA/Hoja2
A221051 bytesVBA/Hoja20
A231051 bytesVBA/Hoja21
A241051 bytesVBA/Hoja22
A251051 bytesVBA/Hoja23
A261051 bytesVBA/Hoja24
A271051 bytesVBA/Hoja25
A281240 bytesVBA/Hoja26
A291051 bytesVBA/Hoja27
A301051 bytesVBA/Hoja28
A311051 bytesVBA/Hoja29
A325953 bytesVBA/Hoja3
A331051 bytesVBA/Hoja30
A341051 bytesVBA/Hoja31
A351051 bytesVBA/Hoja32
A361051 bytesVBA/Hoja33
A371187 bytesVBA/Hoja34
A381051 bytesVBA/Hoja35
A391187 bytesVBA/Hoja36
A401051 bytesVBA/Hoja37
A411051 bytesVBA/Hoja38
A421051 bytesVBA/Hoja39
A431051 bytesVBA/Hoja40
A441051 bytesVBA/Hoja41
A451051 bytesVBA/Hoja42
A461051 bytesVBA/Hoja43
A471051 bytesVBA/Hoja44
A481051 bytesVBA/Hoja45
A491051 bytesVBA/Hoja46
A501051 bytesVBA/Hoja47
A511051 bytesVBA/Hoja48
A521051 bytesVBA/Hoja49
A531239 bytesVBA/Hoja5
A541051 bytesVBA/Hoja50
A551051 bytesVBA/Hoja51
A561051 bytesVBA/Hoja52
A571051 bytesVBA/Hoja53
A581051 bytesVBA/Hoja54
A591051 bytesVBA/Hoja55
A601051 bytesVBA/Hoja56
A611051 bytesVBA/Hoja57
A621051 bytesVBA/Hoja58
A631051 bytesVBA/Hoja59
A641134 bytesVBA/Hoja6
A651051 bytesVBA/Hoja60
A661051 bytesVBA/Hoja61
A671051 bytesVBA/Hoja62
A681051 bytesVBA/Hoja63
A691051 bytesVBA/Hoja64
A701051 bytesVBA/Hoja65
A711051 bytesVBA/Hoja66
A721051 bytesVBA/Hoja67
A731051 bytesVBA/Hoja68
A741051 bytesVBA/Hoja69
A751239 bytesVBA/Hoja7
A761051 bytesVBA/Hoja70
A771051 bytesVBA/Hoja71
A781051 bytesVBA/Hoja72
A791051 bytesVBA/Hoja73
A801240 bytesVBA/Hoja74
A811232 bytesVBA/Hoja75
A821967 bytesVBA/Hoja76
A831127 bytesVBA/Hoja77
A841050 bytesVBA/Hoja8
A851050 bytesVBA/Hoja9
A861240 bytesVBA/ThisWorkbook
A8714175 bytesVBA/UserForm1
A8822208 bytesVBA/_VBA_PROJECT
A8920071 bytesVBA/__SRP_0
A902628 bytesVBA/__SRP_1
A91398 bytesVBA/__SRP_10
A922098 bytesVBA/__SRP_11
A93438 bytesVBA/__SRP_12
A94258 bytesVBA/__SRP_13
A95249 bytesVBA/__SRP_14
A96156 bytesVBA/__SRP_15
A97594 bytesVBA/__SRP_16
A98774 bytesVBA/__SRP_17
A99394 bytesVBA/__SRP_18
A100182 bytesVBA/__SRP_19
A101250 bytesVBA/__SRP_1a
A102182 bytesVBA/__SRP_1b
A103464 bytesVBA/__SRP_1c
A104106 bytesVBA/__SRP_1d
A1059628 bytesVBA/__SRP_1e
A106756 bytesVBA/__SRP_1f
A107464 bytesVBA/__SRP_2
A1084427 bytesVBA/__SRP_20
A109424 bytesVBA/__SRP_21
A110464 bytesVBA/__SRP_22
A111106 bytesVBA/__SRP_23
A112464 bytesVBA/__SRP_24
A113106 bytesVBA/__SRP_25
A114464 bytesVBA/__SRP_26
A115106 bytesVBA/__SRP_27
A116106 bytesVBA/__SRP_28
A117464 bytesVBA/__SRP_29
A118106 bytesVBA/__SRP_3
A119680 bytesVBA/__SRP_4
A120106 bytesVBA/__SRP_5
A1211836 bytesVBA/__SRP_6
A122410 bytesVBA/__SRP_7
A1232210 bytesVBA/__SRP_8
A124356 bytesVBA/__SRP_9
A125742 bytesVBA/__SRP_a
A126258 bytesVBA/__SRP_b
A127464 bytesVBA/__SRP_c
A128106 bytesVBA/__SRP_d
A1291632 bytesVBA/__SRP_e
A13021690 bytesVBA/__SRP_f
A1314765 bytesVBA/clsEventosForm
A13211102 bytesVBA/consultas
A1333518 bytesVBA/dir
A1342310 bytesVBA/filtros
A13522972 bytesVBA/mod_genera_formulario
A1362088 bytesVBA/mod_ia
A13749832 bytesVBA/mod_informes
A13810915 bytesVBA/mod_insumos
A1398972 bytesVBA/mod_listas_formulario
A1402342 bytesVBA/mod_load_ribbon
A1412705 bytesVBA/mod_utilidades
A1424330 bytesVBA/nuevosItems
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecbtnBuscar_ClickRuns when the file is opened and ActiveXobjects trigger events
AutoExecWorksheet_ChangeRuns when the file is opened and ActiveXobjects trigger events
Stringcode and P-code are different, this may havebeen used to hide malicious code
SuspiciousCreateObjectMay create an OLE object
SuspiciousCallByNameMay attempt to obfuscate malicious functioncalls
SuspiciousVBProjectMay attempt to modify the VBA code (self-modification)
SuspiciousVBComponentsMay attempt to modify the VBA code (self-modification)
SuspiciousCodeModuleMay attempt to modify the VBA code (self-modification)
SuspiciousAddFromStringMay attempt to modify the VBA code (self-modification)
SuspiciousHex StringsHex-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
210
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
xlsm
Verdict:
No threats detected
Analysis date:
2026-06-24 08:14:31 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/octet-stream
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
Result
Verdict:
Malicious
File Type:
Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
evasive macros macros-on-event
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
26 / 100
Signature
Document contains VBA stomped code (only p-code) potentially bypassing AV detection
Behaviour
Behavior Graph:
Gathering data
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2026-06-24 08:13:27 UTC
File Type:
Document
Extracted files:
706
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments