Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
PastePictures 1.xla

Overview

General Information

Sample name:PastePictures 1.xla
Analysis ID:1633444
MD5:c5c860ab09e407ff33e9e171f92feedd
SHA1:7bb228762dccf79efd386efae2d1c37e7501f735
SHA256:7094f139fc7a3b89cb19b4fdf34e59dd74291e5c828739c5c8eb190dfc4a6e9b
Infos:

Detection

Score:60
Range:0 - 100
Confidence:100%

Signatures

Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to WSH operations (process, registry, environment, or keystrokes)
Document contains an embedded VBA with hexadecimal encoded strings
Office process queries suspicious COM object (likely to drop second stage)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Found URL in obfuscated visual basic script code
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 8576 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 6420 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 23.88.6.149, DestinationIsIpv6: false, DestinationPort: 80, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 8576, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 49719
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.5, DestinationIsIpv6: false, DestinationPort: 49719, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 8576, Protocol: tcp, SourceIp: 23.88.6.149, SourceIsIpv6: false, SourcePort: 80
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-10T11:24:34.831088+010020283713Unknown Traffic192.168.2.54972213.107.253.72443TCP
2025-03-10T11:24:41.993805+010020283713Unknown Traffic192.168.2.54972313.107.253.72443TCP
2025-03-10T11:24:42.008751+010020283713Unknown Traffic192.168.2.54972413.107.253.72443TCP

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.5:49722 version: TLS 1.2
Source: ~DFF0C0FFD1FF540DED.TMP.0.drBinary string: http://translate.google.com/translate?slrutllangcode$uurlencode(url$) - obfuscation quality: 4
Source: ~DFF0C0FFD1FF540DED.TMP.0.drBinary string: http://translate.google.com/translate?slrutllangcode$uurlencode(url$) - obfuscation quality: 4
Source: Joe Sandbox ViewIP Address: 13.107.253.72 13.107.253.72
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49722 -> 13.107.253.72:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49724 -> 13.107.253.72:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49723 -> 13.107.253.72:443
Source: global trafficHTTP traffic detected: GET /ip.php HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: xn--80adkunbi5c.xn--p1ai
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /rules/excel.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /ip.php HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: xn--80adkunbi5c.xn--p1ai
Source: global trafficDNS traffic detected: DNS query: xn--80adkunbi5c.xn--p1ai
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru
Source: PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru/
Source: 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru/buy/EULA
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru/payments
Source: PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru/php2/updates.php
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://ExcelVBA.ru/programmes/Parser
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://bbs.vbstreets.ru/viewtopic.php?p=66
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://bbs.vbstreets.ru/viewtopic.php?p=6659672#p6659672
Source: 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://excelvba.ru/
Source: PastePictures 1.xla.0.drString found in binary or memory: http://excelvba.ru/resources/PastePictures/
Source: PastePictures 1.xla.0.drString found in binary or memory: http://http://website.com/images/
Source: PastePictures 1.xla.0.drString found in binary or memory: http://translate.google.com/translate?sl=ru&tl=
Source: 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://website.com/images/
Source: PastePictures 1.xla.0.drString found in binary or memory: http://website.com/images/123abc.jpg
Source: PastePictures 1.xla.0.drString found in binary or memory: http://website.com/pictures/
Source: PastePictures 1.xla.0.drString found in binary or memory: http://www.herber.de/forum/archiv/1192to1196/1192164_Punycode_Unicode.html
Source: PastePictures 1.xla.0.drString found in binary or memory: http://www.mvps.org/emorcillo/en/code/vb6/savejpggdip.shtml
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://www.wordarticles.com/Shorts/RibbonVBA/RibbonVBADemo.php
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://www.zhaojunpeng.com/posts/2016/10/28/excel-urldecode
Source: ~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drString found in binary or memory: http://xn--80aebe3cdmfdkg.xn--d1abbgf6aiiy.xn--p1ai/%D1%81%D0%BE%D0%B2%D0%B5%D1%82%D1%8B
Source: PastePictures 1.xla.0.drString found in binary or memory: https://ExcelVBA.ru/
Source: PastePictures 1.xla.0.drString found in binary or memory: https://askdev.ru/q/kak-ya-mogu-url-kodirovat-stroku-v-excel-vba-42634/
Source: PastePictures 1.xla.0.drString found in binary or memory: https://betacode.net/12473/javascript-url-encoding
Source: PastePictures 1.xla.0.drString found in binary or memory: https://consent.google.ru/
Source: PastePictures 1.xla.0.drString found in binary or memory: https://consent.google.ru/save
Source: PastePictures 1.xla.0.drString found in binary or memory: https://excelvba.ru/programmes/PastePictures/manuals/errors/webp
Source: PastePictures 1.xla.0.drString found in binary or memory: https://excelvba.ru/programmes/RenameFiles
Source: PastePictures 1.xla.0.drString found in binary or memory: https://www.google.ru/search
Source: PastePictures 1.xla.0.drString found in binary or memory: https://www.google.ru/search?q=
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.5:49722 version: TLS 1.2

System Summary

barindex
Source: 2C230000.0.drOLE, VBA macro line: downloads_folder$ = Replace(SETT.GetText("{374DE290-123F-4565-9164-39C4925E467B}", , USF$), "%USERPROFILE%", Environ("USERPROFILE"))
Source: PastePictures 1.xlaStream path '_VBA_PROJECT_CUR/VBA/Module1' : found possibly 'ADODB.Stream' functions open, savetofile, write
Source: PastePictures 1.xlaStream path '_VBA_PROJECT_CUR/VBA/thisWB' : found possibly 'ADODB.Stream' functions open, savetofile, write
Source: ~DF749E4C5DC9B304F7.TMP.0.drStream path '_VBA_PROJECT_CUR/VBA/Module1' : found possibly 'ADODB.Stream' functions open, savetofile, write
Source: ~DF749E4C5DC9B304F7.TMP.0.drStream path '_VBA_PROJECT_CUR/VBA/thisWB' : found possibly 'ADODB.Stream' functions open, savetofile, write
Source: 2C230000.0.drStream path '_VBA_PROJECT_CUR/F_FirstRun' : found possibly 'WScript.Shell' functions specialfolders, createshortcut, run, environ
Source: 2C230000.0.drStream path '_VBA_PROJECT_CUR/F_FirstRun' : found hex strings
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXECOM Object queried: ADODB.Stream HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32Jump to behavior
Source: PastePictures 1.xlaOLE, VBA macro line: Private Sub Workbook_Open()
Source: ~DF749E4C5DC9B304F7.TMP.0.drOLE, VBA macro line: Private Sub Workbook_Open()
Source: 2C230000.0.drOLE, VBA macro line: Private Sub CommandButton_Close_Click(): Unload Me: End Sub
Source: 2C230000.0.drOLE, VBA macro line: Private Sub Label_OpenExportFolder_Click()
Source: PastePictures 1.xla.0.drBinary or memory string: OriginalFilename vs PastePictures 1.xla
Source: classification engineClassification label: mal60.expl.winXLA@3/21@2/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Application Data\Microsoft\FormsJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{6969B2C8-28BA-40E9-9102-C224E58DBAB6} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{C62A69F0-16DC-11CE-9E98-00AA00574A4F}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: PastePictures 1.xlaStatic file information: File size 3037696 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 994Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information42
Scripting
Valid AccountsWindows Management Instrumentation42
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive13
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
PastePictures 1.xla2%VirustotalBrowse
PastePictures 1.xla3%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ExcelVBA.ru/programmes/Parser0%Avira URL Cloudsafe
http://excelvba.ru/0%Avira URL Cloudsafe
https://excelvba.ru/programmes/PastePictures/manuals/errors/webp0%Avira URL Cloudsafe
http://excelvba.ru/resources/PastePictures/0%Avira URL Cloudsafe
http://ExcelVBA.ru/php2/updates.php0%Avira URL Cloudsafe
https://consent.google.ru/0%Avira URL Cloudsafe
https://consent.google.ru/save0%Avira URL Cloudsafe
http://www.mvps.org/emorcillo/en/code/vb6/savejpggdip.shtml0%Avira URL Cloudsafe
http://www.herber.de/forum/archiv/1192to1196/1192164_Punycode_Unicode.html0%Avira URL Cloudsafe
http://xn--80aebe3cdmfdkg.xn--d1abbgf6aiiy.xn--p1ai/%D1%81%D0%BE%D0%B2%D0%B5%D1%82%D1%8B0%Avira URL Cloudsafe
http://ExcelVBA.ru/buy/EULA0%Avira URL Cloudsafe
http://http://website.com/images/0%Avira URL Cloudsafe
https://askdev.ru/q/kak-ya-mogu-url-kodirovat-stroku-v-excel-vba-42634/0%Avira URL Cloudsafe
https://excelvba.ru/programmes/RenameFiles0%Avira URL Cloudsafe
http://www.zhaojunpeng.com/posts/2016/10/28/excel-urldecode0%Avira URL Cloudsafe
http://bbs.vbstreets.ru/viewtopic.php?p=660%Avira URL Cloudsafe
http://ExcelVBA.ru0%Avira URL Cloudsafe
https://ExcelVBA.ru/0%Avira URL Cloudsafe
https://betacode.net/12473/javascript-url-encoding0%Avira URL Cloudsafe
http://bbs.vbstreets.ru/viewtopic.php?p=6659672#p66596720%Avira URL Cloudsafe
http://www.wordarticles.com/Shorts/RibbonVBA/RibbonVBADemo.php0%Avira URL Cloudsafe
http://ExcelVBA.ru/payments0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
truefalse
    high
    s-0005.dual-s-msedge.net
    52.123.129.14
    truefalse
      high
      xn--80adkunbi5c.xn--p1ai
      23.88.6.149
      truefalse
        unknown
        otelrules.svc.static.microsoft
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://otelrules.svc.static.microsoft/rules/excel.exe-Production-v19.bundlefalse
            high
            https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
              high
              https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                http://excelvba.ru/2C230000.0.dr, PastePictures 1.xla.0.drfalse
                • Avira URL Cloud: safe
                unknown
                https://www.google.ru/search?q=PastePictures 1.xla.0.drfalse
                  high
                  http://website.com/pictures/PastePictures 1.xla.0.drfalse
                    high
                    http://excelvba.ru/resources/PastePictures/PastePictures 1.xla.0.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://ExcelVBA.ru/php2/updates.phpPastePictures 1.xla.0.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://ExcelVBA.ru/programmes/Parser~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://www.google.ru/searchPastePictures 1.xla.0.drfalse
                      high
                      http://website.com/images/2C230000.0.dr, PastePictures 1.xla.0.drfalse
                        high
                        http://xn--80aebe3cdmfdkg.xn--d1abbgf6aiiy.xn--p1ai/%D1%81%D0%BE%D0%B2%D0%B5%D1%82%D1%8B~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://consent.google.ru/PastePictures 1.xla.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://excelvba.ru/programmes/PastePictures/manuals/errors/webpPastePictures 1.xla.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://website.com/images/123abc.jpgPastePictures 1.xla.0.drfalse
                          high
                          http://www.herber.de/forum/archiv/1192to1196/1192164_Punycode_Unicode.htmlPastePictures 1.xla.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://consent.google.ru/savePastePictures 1.xla.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.mvps.org/emorcillo/en/code/vb6/savejpggdip.shtmlPastePictures 1.xla.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://translate.google.com/translate?sl=ru&tl=PastePictures 1.xla.0.drfalse
                            high
                            http://ExcelVBA.ru/buy/EULA2C230000.0.dr, PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://http://website.com/images/PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://askdev.ru/q/kak-ya-mogu-url-kodirovat-stroku-v-excel-vba-42634/PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://bbs.vbstreets.ru/viewtopic.php?p=66~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://betacode.net/12473/javascript-url-encodingPastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://ExcelVBA.ru/PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.zhaojunpeng.com/posts/2016/10/28/excel-urldecode~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://excelvba.ru/programmes/RenameFilesPastePictures 1.xla.0.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://ExcelVBA.ru/PastePictures 1.xla.0.drfalse
                              unknown
                              http://bbs.vbstreets.ru/viewtopic.php?p=6659672#p6659672~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://ExcelVBA.ru~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://ExcelVBA.ru/payments~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.wordarticles.com/Shorts/RibbonVBA/RibbonVBADemo.php~DFF0C0FFD1FF540DED.TMP.0.dr, 2C230000.0.dr, PastePictures 1.xla.0.drfalse
                              • Avira URL Cloud: safe
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              13.107.253.72
                              s-part-0044.t-0009.fb-t-msedge.netUnited States
                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              23.88.6.149
                              xn--80adkunbi5c.xn--p1aiUnited States
                              18978ENZUINC-USfalse
                              Joe Sandbox version:42.0.0 Malachite
                              Analysis ID:1633444
                              Start date and time:2025-03-10 11:22:16 +01:00
                              Joe Sandbox product:CloudBasic
                              Overall analysis duration:0h 5m 0s
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Cookbook file name:defaultwindowsofficecookbook.jbs
                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                              Run name:Without Instrumentation
                              Number of analysed new started processes analysed:15
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • EGA enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Sample name:PastePictures 1.xla
                              Detection:MAL
                              Classification:mal60.expl.winXLA@3/21@2/2
                              Cookbook Comments:
                              • Found application associated with file extension: .xla
                              • Found Word or Excel or PowerPoint or XPS Viewer
                              • Attach to Office via COM
                              • Active AutoShape Object
                              • Scroll down
                              • Close Viewer
                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                              • Excluded IPs from analysis (whitelisted): 52.109.76.240, 52.109.89.19, 23.199.214.10, 20.189.173.10, 52.123.129.14, 4.175.87.197, 20.190.159.130, 150.171.28.10, 23.15.178.145
                              • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, weu-azsc-000.roaming.officeapps.live.com, g.bing.com, eur.roaming1.live.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, excelvba.ru, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, dual-s-0005-office.config.skype.com, login.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, www.bing.com, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, prod.roaming1.live.com.akadns.net, fe3cr.delivery.mp.microsoft.com, neu-azsc-config.officeapps.live.com, config.officeapps.live.com, onedscolprdwus09.westus.cloudapp.azure.com, e16604.f.akamaiedge.net, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.net
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtCreateKey calls found.
                              • Report size getting too big, too many NtQueryAttributesFile calls found.
                              • Report size getting too big, too many NtQueryValueKey calls found.
                              • Report size getting too big, too many NtReadVirtualMemory calls found.
                              • Report size getting too big, too many NtSetInformationFile calls found.
                              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                              TimeTypeDescription
                              06:24:27API Interceptor1022x Sleep call for process: splwow64.exe modified
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              13.107.253.72Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                    https://go.irt.calyx.ai/LiveGet hashmaliciousUnknownBrowse
                                      Purchase Order.xla.xlsxGet hashmaliciousUnknownBrowse
                                        Confirmation number 0001592289.xlsGet hashmaliciousUnknownBrowse
                                          phish_alert_sp2_2.0.0.0-1.emlGet hashmaliciousHTMLPhisherBrowse
                                            SecuriteInfo.com.Win64.Malware-gen.1550.5420.exeGet hashmaliciousUnknownBrowse
                                              MITRE Enterprise ATTACK v16.1.xlsxGet hashmaliciousMimikatzBrowse
                                                05 BOIRON F 240700457 ORDEN 05 MAR 2025.xlsGet hashmaliciousUnknownBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  s-0005.dual-s-msedge.netPOETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 52.123.128.14
                                                  f1215469392.dllGet hashmaliciousUnknownBrowse
                                                  • 52.123.129.14
                                                  Purchase Order No 1417.docGet hashmaliciousUnknownBrowse
                                                  • 52.123.128.14
                                                  Purchase Order No 1417.docGet hashmaliciousUnknownBrowse
                                                  • 52.123.129.14
                                                  f492136216_mpengine_dllGet hashmaliciousUnknownBrowse
                                                  • 52.123.128.14
                                                  qVucZkUdbX.exeGet hashmaliciousNitrogenBrowse
                                                  • 52.123.129.14
                                                  mal_temp.dotm.docGet hashmaliciousUnknownBrowse
                                                  • 52.123.129.14
                                                  Dear david@corerecon.com - Your Stay Has Been Successfully Booked Ocean Breeze Retreat.msgGet hashmaliciousScreenConnect ToolBrowse
                                                  • 52.123.129.14
                                                  RFQ-JC25-#595837.xlsxGet hashmaliciousUnknownBrowse
                                                  • 52.123.128.14
                                                  NEW ORDER (PO. 2100002 (BT-INC).xlsGet hashmaliciousUnknownBrowse
                                                  • 52.123.128.14
                                                  s-part-0044.t-0009.fb-t-msedge.netPurchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  f1215469392.dllGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  https://go.irt.calyx.ai/LiveGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  Purchase Order.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  Confirmation number 0001592289.xlsGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  ADFoyxP.exeGet hashmaliciousKeyLogger, StormKitty, VenomRATBrowse
                                                  • 13.107.253.72
                                                  phish_alert_sp2_2.0.0.0-1.emlGet hashmaliciousHTMLPhisherBrowse
                                                  • 13.107.253.72
                                                  https://assets-fra.mkt.dynamics.com/a4eec278-88f9-ef11-b013-6045bd6e9afa/digitalassets/standaloneforms/c345aa34-aff9-ef11-bae1-000d3a8999aeGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  ENZUINC-USi686.elfGet hashmaliciousUnknownBrowse
                                                  • 104.203.176.148
                                                  mpsl.elfGet hashmaliciousMiraiBrowse
                                                  • 23.88.52.204
                                                  jklmips.elfGet hashmaliciousUnknownBrowse
                                                  • 107.183.227.248
                                                  nabarm.elfGet hashmaliciousUnknownBrowse
                                                  • 104.202.132.51
                                                  1isequal9.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 107.183.94.187
                                                  cbr.mpsl.elfGet hashmaliciousMiraiBrowse
                                                  • 104.202.16.149
                                                  nabppc.elfGet hashmaliciousUnknownBrowse
                                                  • 104.202.38.20
                                                  transferencia HSBC.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 23.88.122.137
                                                  transferencia HSBC.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 23.88.122.137
                                                  transferencia HSBC.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 23.88.122.137
                                                  MICROSOFT-CORP-MSN-AS-BLOCKUSsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                  • 13.105.88.171
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 40.90.65.44
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.67
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.42
                                                  f1215469392.dllGet hashmaliciousUnknownBrowse
                                                  • 204.79.197.203
                                                  m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                  • 13.64.110.51
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  a0e9f5d64349fb13191bc781f81f42e1ALfzrNn09x.exeGet hashmaliciousLummaC StealerBrowse
                                                  • 13.107.253.72
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  • 13.107.253.72
                                                  EasyWay.exeGet hashmaliciousLummaC StealerBrowse
                                                  • 13.107.253.72
                                                  Aura.exeGet hashmaliciousLummaC StealerBrowse
                                                  • 13.107.253.72
                                                  EasyWay.exeGet hashmaliciousLummaC StealerBrowse
                                                  • 13.107.253.72
                                                  Aura.exeGet hashmaliciousLummaC StealerBrowse
                                                  • 13.107.253.72
                                                  No context
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):118
                                                  Entropy (8bit):3.5700810731231707
                                                  Encrypted:false
                                                  SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                                                  MD5:573220372DA4ED487441611079B623CD
                                                  SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                                                  SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                                                  SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                                                  Malicious:false
                                                  Reputation:high, very likely benign file
                                                  Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):152056
                                                  Entropy (8bit):4.414376250285914
                                                  Encrypted:false
                                                  SSDEEP:1536:fmmULzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3ow:fGg8WpFpKKHHedydFeo+oQLUlPow
                                                  MD5:BCAC93E69FA974D89F3138618E11B6BE
                                                  SHA1:9ADE96838A7DC747C93D93ADBE6EB66EFBE6AB74
                                                  SHA-256:987ABF7048B649665C400D4DF113EE8EE506C0F241160E368649F973D9DFF12F
                                                  SHA-512:8F66F561B845C459F78F3999CAA3922B990BB3C7BDBC638892239BE22D6D0C7FF7B7F2E188611532740D35417989C1734449AB8FAD775F3126F408700AE227BB
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......B...........^...............g...............W...............F..............<G...............g...............i...I..............T..................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 52x55, components 3
                                                  Category:dropped
                                                  Size (bytes):2100
                                                  Entropy (8bit):7.721295722573028
                                                  Encrypted:false
                                                  SSDEEP:48:dbSLiaTjHT1026++zkuYh7gB+//U7XY5B:IGaTjHT102F+zPcHU6B
                                                  MD5:3792CB24BE3053746AF936EA0A4A46FF
                                                  SHA1:3C3DCDFEE44C0919A44F03A4262FBC1E22467B53
                                                  SHA-256:0444E596DD2BE4FDDA6F993DE36AA02AC87AEDD4121DA24A440933F50706F189
                                                  SHA-512:957A63729641B30A9C1373C211BD59676A8B84DBFD58D234704915A2F63C774873307DCFA5221BED8D33CCD3222BCDB7A648A65CF20B16919CC05EDA351ACDA7
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:......JFIF.....`.`.....C....................................................................C.......................................................................7.4.."........................................9..........................!....1Q.2Aa."q.$B...3rt....................................)......................!1.Q..A....2a................?.c...F....[...u...jXqSaJe..:.\...F..~...sx.[..=...gu.Nt..h..........t....'N...j...Z.,%N(..1YO...>..=t..e..f...V(NJS....(g...pZHYNx...#.s..j......3b{.l...$.5.z.x..5..5`\........A....L'U._..Ur...~.^.i....>.~Qh....Fs..c..&.:.S... Y.e...-(i.<.>bP.$...d...zc.8./.m...S.R......7gtn.}.t|...:.....u....c,.1... _.4_.#.R.O~.]....6.....'.........J..K..I..?S.....[A.O..l+.....#%'U-.t..UTv.....C.\x.J....K....G..S.......&..O...8#...z*.A$/1.........{.......t:....Yn%n......~L..U.@L..G.X.Sn&..RV.#..}A.... n.T.U....P{.t]..$.uQ....{/.XSL.......G.e..V.O.....;..":..I.;.BVHJ...F1..^.G...lT&S....7.......<j>..s...w.M.$w~....1..q.:L@.....k
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):0.0
                                                  Encrypted:false
                                                  SSDEEP:3::
                                                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                  Malicious:false
                                                  Reputation:high, very likely benign file
                                                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):0.0
                                                  Encrypted:false
                                                  SSDEEP:3::
                                                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                  Malicious:false
                                                  Reputation:high, very likely benign file
                                                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                  Category:dropped
                                                  Size (bytes):65536
                                                  Entropy (8bit):4.0369188384733
                                                  Encrypted:false
                                                  SSDEEP:384:8rqUGNww97Zhb0TvuBjVzTWcokvmmgYF5fjW4SSGkPHr94T54sDODhO/M/LgWRZh:XHl90Tvu6cokSYX7W4LGkPGesaoMEWL
                                                  MD5:A59A5363B59A850BB77B337A7304244B
                                                  SHA1:2487CC4E9B4C68E761B63D3ECB085D15B752B699
                                                  SHA-256:F7224AE7BD1BA0A91460FF8F74CF391AD227FD3BC84B3974E88FB34F9DF4A71D
                                                  SHA-512:EDDC780FE7CB12DBE13EF0594B637FEA72DA8A94BD102DDDE10A902258CD1C225AE4B1EFEDCCA6940042233E4CBCE6A115C58F67EB8B628F39CC8B5A911D41DB
                                                  Malicious:false
                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):28672
                                                  Entropy (8bit):2.629476496118983
                                                  Encrypted:false
                                                  SSDEEP:768:0T2Z6FIphYHAeXVhc9sfyHLtyeGx2zNb8wiC/K61:0k6FIphYHAeXVhc9sfyHLtyeGx2zZ8wx
                                                  MD5:6A80110B2EB7CCD7EAB2885525EF02C7
                                                  SHA1:00FE57382255A975F45AC70156E379448B38E2C9
                                                  SHA-256:66C5196306DF4449AF47C88F84CE1A047864520DBA4F4BE54EBFB7D0249D9BF4
                                                  SHA-512:BEF7596DD9DD2BED77A739AF5B52A0210486A4BBDB5BDC09A3EC5496E07BCBD202814DCD5AA0CFC3EBCB30457CD558ED87A3F10FD787B6DCC6D3A0890F412367
                                                  Malicious:false
                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Author: ExcelVBA.ru, Last Saved By: ExcelVBA.ru, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Apr 3 17:54:13 2023, Last Saved Time/Date: Tue Jul 16 23:41:24 2024, Security: 0
                                                  Category:dropped
                                                  Size (bytes):3037696
                                                  Entropy (8bit):3.560036765906566
                                                  Encrypted:false
                                                  SSDEEP:12288:wrESVFJJqhJ7E1C9eyXQCJ9DeaQNkdNQQRtW+R9ikagBVbwlMbb9gQnqs7e76019:4DV1axQVsBVMaCWQI/q
                                                  MD5:F3125AC6EC8F4C01D7C4D4C2281F4014
                                                  SHA1:56BBE8EC441E7125DADBC48BF16020B0F9D1DD23
                                                  SHA-256:F695428496D6DF46B994B56D221EEB3D5E5EE617253DA181423E9019D45264F4
                                                  SHA-512:555E80F2878153604C3B2421F43AFB6F5888DA3133E5F66A790EE80F8D57CC7A5D34B01774CCFCDEC72813379726EC8FFB7ADBE3445F3500CFBF3BE0A8129D35
                                                  Malicious:false
                                                  Preview:......................>.................../...................................b.......d.......f.......h.......j.......l.......n.......p.......r.......t.......v.......x.......z.......|.......~...............b.......d.......f.......h.......j.......l.......n........................................................................................................................................................................................................................................................................................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...c.......d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):20480
                                                  Entropy (8bit):0.3071957075792542
                                                  Encrypted:false
                                                  SSDEEP:12:KrkayAh8eBEEActysmXooNcl95SVayUfjIABzg24Q7KQhv4ddO9dv:KoaUcET7FNiPI1UfXz4TQx6UB
                                                  MD5:544810D83ECCBD45BEEC82B8765807E5
                                                  SHA1:929AAD1ED4AF7041949C7DE5D852D6C4D3950645
                                                  SHA-256:4B793775A0A24DCDB2AE9472FA27865C7EED575408B971398F1E866BA586EB2E
                                                  SHA-512:173A5674F1F98C42442151E5D602644F9B21A990730750FBE57A3C57300D7CF970C84D22F0625B193C6E0918FFD2E8BDCC9E72C7CC6AC480717A6B780902851F
                                                  Malicious:false
                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                  Category:dropped
                                                  Size (bytes):32768
                                                  Entropy (8bit):4.349904045046581
                                                  Encrypted:false
                                                  SSDEEP:768:P0TkW4SdIXJGGkPD4uAV4J83W1XEsaoh1h9p:s4GdIXJGGkPD4u84J8m1U01h9
                                                  MD5:90CC00FFC0DADBCB3A7CB05366111E9B
                                                  SHA1:6D989B52493AA60AE8A086DAAC0DF544141AA05C
                                                  SHA-256:A9F2899012625921B5422053A7538B75E7979FFAB8DD8EB74DE08FA13B7C3676
                                                  SHA-512:DB628F8FEC3B3AF3248C9F1DE38FB7ACDAF8306E5315EA4970BAF961B8EE19048D3C3F52A0B5BE75A9594B1DBD989AEF9C7C1E8F9F496DC517996DE793C270FE
                                                  Malicious:false
                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                  Category:dropped
                                                  Size (bytes):13824
                                                  Entropy (8bit):4.207853074078052
                                                  Encrypted:false
                                                  SSDEEP:96:F4OpU6hNF/brbuvvZkb3kWyDBmayq9IxQjaf0advfk3krod0a5NkYhZcuNYwpmfv:F7ThnuvhY4y/0mvfYnvkwNXPh9ptO
                                                  MD5:60E2D4FF42A23654C517598012CC7E48
                                                  SHA1:B16542E73FDD94E627DC1C2C6F16D6AB44E0422B
                                                  SHA-256:0F8640EE07B5F5F5E1532A895A2F986A1ACA5D4BFBFE40B77BB3F4D224C78643
                                                  SHA-512:9F90A42F194F1B099867D8EAF0695948CBEAE855B2BAB518DCA419B18750CD888BA53177854BB5D0577659B0F173A90830F56E89C198A8F6AED386A14600C06C
                                                  Malicious:false
                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):65536
                                                  Entropy (8bit):0.17744662538018643
                                                  Encrypted:false
                                                  SSDEEP:48:2tytMR8+D7VRFeRLUMS8VfXAU05MAA1lQ/f8EfrCfeVf:2oo8+D7DFeRLUGVQnYuf3frCfeVf
                                                  MD5:F76C797EE2127271F5BE77E56C28D964
                                                  SHA1:FA9DE6038D95E0B177E6E0EB40A30FD53CDC2171
                                                  SHA-256:7447AD0FDEC1D28274AA6ADEE680B37DEDF9522AE59605D98F1C56E4B0B7303E
                                                  SHA-512:0DC33390BA317E55DFC16E27A4A60FA6F43A203B2DB0CC7C0159069F906676D6F709940F52D591BE96E296EA98465BB7978F3F70AA37F287204E897454B8C78C
                                                  Malicious:false
                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):0.0
                                                  Encrypted:false
                                                  SSDEEP:3::
                                                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                  Malicious:false
                                                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):0.0
                                                  Encrypted:false
                                                  SSDEEP:3::
                                                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                  Malicious:false
                                                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):114688
                                                  Entropy (8bit):1.829476261476348
                                                  Encrypted:false
                                                  SSDEEP:768:/i+WGX8NsN33+C3JO+WUO3tNs+c1s7lIN3UNVr1CFMp+aps:VMNsNntSdNsQs3MQFPaG
                                                  MD5:7A2C52ED9807A4CD220C8074C2F1CCD1
                                                  SHA1:7CB73C87D8F9415F4019E839B41C28AFC246B693
                                                  SHA-256:DD9F73996F23CF6A1FD3D3CF3C151512C1BB0FAE0DBDD0737A1D3783948897A6
                                                  SHA-512:5A6EB190319CC4AEF46913C5D37CA04F66C3AC6E02ECB036251EA4C6CBEE22597A4CEB9A8806AE54A0FDCA86724EA57B159ADE5EDF5D59F58BD520A0883AF3E0
                                                  Malicious:false
                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                  Category:dropped
                                                  Size (bytes):1196032
                                                  Entropy (8bit):5.319741720439088
                                                  Encrypted:false
                                                  SSDEEP:24576:XYF6xjeruJU4/m6k33AHVPsGczBfUKzWh9ZRh9LuQW71n1h9Yc61KPb0U131hTKl:XY4xxNbkgHVPvcz
                                                  MD5:D8EDE4CE345AF0D4EA1836BC0BAD96A5
                                                  SHA1:0282E857042436C827F5CBA15A8A3F17B27AFB99
                                                  SHA-256:3FB8FF021CD068363633B28AEC9947051ED21AF5CB049423C778FE3C42329DD6
                                                  SHA-512:B29CC34007C491B947887E71005D286DE91EEE1442A8A3EAED2B91ABCB32DFF24AD8686A41C3F7EA6B0FD756CE175943B882A6BED0D6B65D29F14506EC8E4B5D
                                                  Malicious:false
                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):28672
                                                  Entropy (8bit):2.982589146818369
                                                  Encrypted:false
                                                  SSDEEP:768:2LcKoSsxz1PDZLDZjlbR868O8KldzH3K7uDphYHceXVhca+fMHLtyeGxcbB8/dgq:2LcKoSsxz1PDZLDZjlbR868O8KlVH3Kq
                                                  MD5:587DBCF4765AB09473E1407FADD3E9AD
                                                  SHA1:B044027960B9CA61F12826F4F0B91C67C83252A7
                                                  SHA-256:8CDEF4DD87FAF0172EE1941B57EC57E92E9DC27B8A74D6B192413C4224CBAE93
                                                  SHA-512:59418A0139AF4B3506C1B4E8DE062CB890D8E6C5216F8E3F109BED8BF64713E32B36E223312C73761F776C67C22D34A95B9954351FB321517E793BB754E3AFFF
                                                  Malicious:false
                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                  Category:dropped
                                                  Size (bytes):16384
                                                  Entropy (8bit):0.3613836054883338
                                                  Encrypted:false
                                                  SSDEEP:3:YmsalTlLPltl2N81HRQjlORGt7RQ//W1XR9//3R9//3R9//:rl912N0xs+CFQXCB9Xh9Xh9X
                                                  MD5:679672A5004E0AF50529F33DB5469699
                                                  SHA1:427A4EC3281C9C4FAEB47A22FFBE7CA3E928AFB0
                                                  SHA-256:205D000AA762F3A96AC3AD4B25D791B5F7FC8EFB9056B78F299F671A02B9FD21
                                                  SHA-512:F8615C5E5CF768A94E06961C7C8BEF99BEB43E004A882A4E384F5DD56E047CA59B963A59971F78DCF4C35D1BB92D3A9BC7055BFA3A0D597635DE1A9CE06A3476
                                                  Malicious:false
                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Title: Excel, Author: EducatedFool, Comments: ==== http://ExcelVBA.ru/ ===== Excel ICQ: 5836318 Skype: ExcelVBA.ru======================, Last Saved By: user, Revision Number: 3607, Name of Creating Application: AddinUpdater, Create Time/Date: Tue Jul 16 23:41:20 2024, Last Saved Time/Date: Mon Mar 10 10:24:27 2025, Security: 0
                                                  Category:dropped
                                                  Size (bytes):1461248
                                                  Entropy (8bit):5.761568487045853
                                                  Encrypted:false
                                                  SSDEEP:24576:yp2fbYyljNsBxiR+QFcETmvIlBykGq8TitQ1h9fsQj19/ogvSotBCyGUON87oDeq:yp2TLoxOtxykGVi
                                                  MD5:7E3E2AD0F646494A7CD8EF48E3450880
                                                  SHA1:0202E92266DCC6AEA30C72A8338BC7022DFC8E4B
                                                  SHA-256:2F27115BDED2B18398623F9D0042C5E7C0ECA24C08B388F7A7F473F370CBB6B4
                                                  SHA-512:F5E95D02282F7B0833C27B01F457FF4D6D2CB1C095C4CFABAED12BE85EA72FE999CAB18AE3D5DF97C9BD1A1F9547EC3BEF76E3DBE721609A78CD56AB40E17083
                                                  Malicious:false
                                                  Preview:......................>...................................................F...b.......d.......................I...............~...........................J....................................................................................................................................................................................................................................................................................................................................................................C....................................................................C............................................................................"..................................&.........................!A...."#13Q.........................!.......................!..1Q#ab............?.i....^.Es-.Gbf.0....5............Xu.........E......k@.i-w..p....C..y=.T..va...Yb.J<n.V...?..:s..{......m..........J.!o....t...^:.p.+..6..S.C!Bs........%.? &.N..@..5......0....................
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Title: Excel, Author: EducatedFool, Comments: ==== http://ExcelVBA.ru/ ===== Excel ICQ: 5836318 Skype: ExcelVBA.ru======================, Last Saved By: ExcelVBA.ru, Revision Number: 3607, Name of Creating Application: AddinUpdater, Create Time/Date: Tue Jul 16 23:41:20 2024, Last Saved Time/Date: Tue Jul 16 23:41:21 2024, Security: 0
                                                  Category:dropped
                                                  Size (bytes):1430528
                                                  Entropy (8bit):5.7602769127006805
                                                  Encrypted:false
                                                  SSDEEP:24576:Gs5Uv9j/ktNsSzg1zrqZym96Ovy48fnJvU1RL5jkv+uxewE4+XteiZ67s2saeQ02:h5UlLk/pzezriTGfJ2
                                                  MD5:B803829B0DF6CF6005800F17C6358D25
                                                  SHA1:59177A94F5B5B749638B05BE6BD0D20790F4BCC1
                                                  SHA-256:7E147256E5D0C12CBA07472F3A2A4FA7EA34788DBB8165B74AC28FC58171DEBE
                                                  SHA-512:2B1E4E643F251BA20BC7D36C9EBFE4F720F17258CEE4769DC6B8D336919DF66FC31A5F9C3966E54BD80437B3829524202C5F1BFD5B5A41BBBB6BAB5C79A25528
                                                  Malicious:false
                                                  Preview:......................>...................................................g...........}...........r.......Q.......k.......R...o.......f.......w......................................................................................................................................................................................................................................................................................................................................................................................1...@.......CommandButton_NextStep;.f....5........................................................................... ...................................Microsoft Forms 2.0 Form.....Embedded Object......9.q...............:...;...<...=...>...?...@...VERSION 5.00..Begin {C62A69F0-16DC-11CE-9E98-00AA00574A4F} F_UsageExample .. Caption = "......... ....... ........ . Excel: ...... .............".. ClientHeight = 6300.. ClientLeft = 45.. ClientTop
                                                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Title: Excel, Author: EducatedFool, Comments: ==== http://ExcelVBA.ru/ ===== Excel ICQ: 5836318 Skype: ExcelVBA.ru======================, Last Saved By: ExcelVBA.ru, Revision Number: 3607, Name of Creating Application: AddinUpdater, Create Time/Date: Tue Jul 16 23:41:20 2024, Last Saved Time/Date: Tue Jul 16 23:41:21 2024, Security: 0
                                                  Category:dropped
                                                  Size (bytes):1430528
                                                  Entropy (8bit):5.7602769127006805
                                                  Encrypted:false
                                                  SSDEEP:24576:Gs5Uv9j/ktNsSzg1zrqZym96Ovy48fnJvU1RL5jkv+uxewE4+XteiZ67s2saeQ02:h5UlLk/pzezriTGfJ2
                                                  MD5:B803829B0DF6CF6005800F17C6358D25
                                                  SHA1:59177A94F5B5B749638B05BE6BD0D20790F4BCC1
                                                  SHA-256:7E147256E5D0C12CBA07472F3A2A4FA7EA34788DBB8165B74AC28FC58171DEBE
                                                  SHA-512:2B1E4E643F251BA20BC7D36C9EBFE4F720F17258CEE4769DC6B8D336919DF66FC31A5F9C3966E54BD80437B3829524202C5F1BFD5B5A41BBBB6BAB5C79A25528
                                                  Malicious:true
                                                  Preview:......................>...................................................g...........}...........r.......Q.......k.......R...o.......f.......w......................................................................................................................................................................................................................................................................................................................................................................................1...@.......CommandButton_NextStep;.f....5........................................................................... ...................................Microsoft Forms 2.0 Form.....Embedded Object......9.q...............:...;...<...=...>...?...@...VERSION 5.00..Begin {C62A69F0-16DC-11CE-9E98-00AA00574A4F} F_UsageExample .. Caption = "......... ....... ........ . Excel: ...... .............".. ClientHeight = 6300.. ClientLeft = 45.. ClientTop
                                                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Author: ExcelVBA.ru, Last Saved By: ExcelVBA.ru, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Apr 3 17:54:13 2023, Last Saved Time/Date: Tue Jul 16 23:41:24 2024, Security: 0
                                                  Entropy (8bit):3.5600350377931385
                                                  TrID:
                                                  • Microsoft Excel sheet (30009/1) 47.99%
                                                  • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                                                  • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                                                  File name:PastePictures 1.xla
                                                  File size:3'037'696 bytes
                                                  MD5:c5c860ab09e407ff33e9e171f92feedd
                                                  SHA1:7bb228762dccf79efd386efae2d1c37e7501f735
                                                  SHA256:7094f139fc7a3b89cb19b4fdf34e59dd74291e5c828739c5c8eb190dfc4a6e9b
                                                  SHA512:bb351d796e6b440dbcaa2111b77b6d008273a61b19b204c9966d0f15f176480a4f27b155982b9b457b0551e66a7988e93b59b7ce8c3fdfdf2ec162c4878fe886
                                                  SSDEEP:12288:4rESVFJJqhJ7E1C9eyXQCJ9DeaQNkdNQQRtW+R9ikagBVbwlMbb9gQnqs7e76019:wDV1axQVsBVMaCWQI/q
                                                  TLSH:2DE5EBA055AB8680F61F95606DA8BB610272F1A3B9CB1F33133F6506DF9CD212EC6D4D
                                                  File Content Preview:........................>.................../...................................b.......d.......f.......h.......j.......l.......n.......p.......r.......t.......v.......x.......z.......|.......~...............b.......d.......f.......h.......j.......l......
                                                  Icon Hash:cbe126242426202b
                                                  Document Type:OLE
                                                  Number of OLE Files:1
                                                  Has Summary Info:
                                                  Application Name:Microsoft Excel
                                                  Encrypted Document:False
                                                  Contains Word Document Stream:False
                                                  Contains Workbook/Book Stream:True
                                                  Contains PowerPoint Document Stream:False
                                                  Contains Visio Document Stream:False
                                                  Contains ObjectPool Stream:False
                                                  Flash Objects Count:0
                                                  Contains VBA Macros:True
                                                  Code Page:1251
                                                  Author:ExcelVBA.ru
                                                  Last Saved By:ExcelVBA.ru
                                                  Create Time:2023-04-03 16:54:13
                                                  Last Saved Time:2024-07-16 22:41:24
                                                  Creating Application:Microsoft Excel
                                                  Security:0
                                                  Document Code Page:1251
                                                  Thumbnail Scaling Desired:False
                                                  Contains Dirty Links:False
                                                  Shared Document:False
                                                  Changed Hyperlinks:False
                                                  Application Version:917504
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/FP
                                                  VBA File Name:FP.frm
                                                  Stream Size:1171
                                                  Data ASCII:. . . . . . . . V . . . . . . L . . . ] . . . . . . . . . . . . . . F J . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S < . . . . S < . . . . S < . . . . S < . . . . . . . . . . . 0 . { . D . 7 . A . 3 . E . 9 . B . D . - .
                                                  Data Raw:01 16 03 00 00 f0 00 00 00 56 03 00 00 d4 00 00 00 4c 02 00 00 ff ff ff ff 5d 03 00 00 b1 03 00 00 00 00 00 00 01 00 00 00 46 bd 4a 17 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                  Attribute VB_Name = "FP"
                                                  Attribute VB_Base = "0{D7A3E9BD-4315-4980-8EEA-60C05984219D}{F2CC75FE-BBD7-42FB-B9BD-4AC6B65E7C71}"
                                                  Attribute VB_GlobalNameSpace = False
                                                  Attribute VB_Creatable = False
                                                  Attribute VB_PredeclaredId = True
                                                  Attribute VB_Exposed = False
                                                  Attribute VB_TemplateDerived = False
                                                  Attribute VB_Customizable = False
                                                  

                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/Module1
                                                  VBA File Name:Module1.bas
                                                  Stream Size:4249
                                                  Data ASCII:. . . . . . . . B . . . . . . . . . K . . . / . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . < 8 . . . . . . < J . . . . . . < . . . . . . . < . . . . . . . . . . . . . . . . . . . . . .
                                                  Data Raw:01 16 03 00 00 f0 00 00 00 42 04 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 4b 04 00 00 2f 0c 00 00 00 00 00 00 01 00 00 00 46 bd a6 9b 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                  Attribute VB_Name = "Module1"
                                                  Sub HWID()
                                                     '  2024 ExcelVBA.ru
                                                      On Error Resume Next
                                                      Dim ff&, txt$, i&, j&, f$, ra As Range, arrR, ProjName$, pi_step&, Percent$, size&, pos&, f2$, FSO As New FileSystemObject
                                                      f$ = ThisWorkbook.FullName
                                                      ProjName$ = sh.Range("b1")
                                                      size& = sh.Range("b2").Value2: ReDim b(1 To size&) As Byte
                                                      
                                                      Set ra = sh.Range(sh.Range("a1"), sh.Range("a" & sh.Rows.Count).End(xlUp))
                                                      If ra.Rows.Count = 1 Then MsgBox "File is empty", vbCritical: Exit Sub
                                                      arrR = ra.Value
                                                      pi_step& = Fix(UBound(arrR) / 50)
                                                      
                                                      Application.DisplayAlerts = False
                                                      ThisWorkbook.Saved = True
                                                      ThisWorkbook.ChangeFileAccess 3
                                                      SetAttr f$, vbNormal
                                                      FSO.GetFile(f$).Attributes = 0
                                                      ThisWorkbook.Saved = True
                                                      
                                                      FP.Show: FP.Caption = ProjName$ & " add-in for MS Excel"
                                                      FP.PrBar.Width = 20: FP.Repaint
                                                      FP.Text = "Unpacking " & ProjName$
                                                      Const HE$ = "&H"
                                                      For i = LBound(arrR) To UBound(arrR)
                                                          txt$ = arrR(i, 1)
                                                          If i Mod pi_step& = 0 Then
                                                              Percent = Format(i / UBound(arrR) * 100, "##") & " %"
                                                              FP.Text = "Unpacking " & ProjName$ & ".xla    " & Percent$
                                                              FP.PrBar.Width = 20 + 1.7 * Val(Percent): FP.Repaint
                                                          End If
                                                          For j = 1 To Len(txt) / 2
                                                              pos& = pos& + 1: b(pos) = Val(HE$ & Mid$(txt, 2 * j - 1, 2))
                                                          Next j
                                                      Next i
                                                      
                                                      FP.PrBar.Width = 190: FP.Text = "Updating " & ProjName$ & " file ...": FP.Repaint
                                                      With CreateObject("ADODB.Stream")
                                                          .Open: .Type = 1: .Write b: DoEvents
                                                          .SaveToFile f$, 2: .Close: DoEvents
                                                      End With
                                                      
                                                      Application.OnTime Now + TimeSerial(0, 0, 1), "'" & f$ & "'!HWID"
                                                      FP.Hide
                                                      ThisWorkbook.Saved = True
                                                      Application.DisplayAlerts = True
                                                      ThisWorkbook.Close False
                                                  End Sub
                                                  

                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/sh
                                                  VBA File Name:sh.cls
                                                  Stream Size:987
                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . F ( w . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 46 bd 28 77 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                  Attribute VB_Name = "sh"
                                                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                  Attribute VB_GlobalNameSpace = False
                                                  Attribute VB_Creatable = False
                                                  Attribute VB_PredeclaredId = True
                                                  Attribute VB_Exposed = True
                                                  Attribute VB_TemplateDerived = False
                                                  Attribute VB_Customizable = True
                                                  

                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/thisWB
                                                  VBA File Name:thisWB.cls
                                                  Stream Size:4749
                                                  Data ASCII:. . . . . . . . . . . . . . ( . . . . . . w . . . . . . . . . . . F . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . P . . . . . S L . . . . S . . . . . S . . . . . < 8 . . . . . . < J . . . . . . < 0 . . . . . . < 8 . . . . . .
                                                  Data Raw:01 16 03 00 00 f0 00 00 00 f2 04 00 00 d4 00 00 00 28 02 00 00 ff ff ff ff fb 04 00 00 77 0d 00 00 00 00 00 00 01 00 00 00 46 bd c6 c3 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                  Attribute VB_Name = "thisWB"
                                                  Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                                  Attribute VB_GlobalNameSpace = False
                                                  Attribute VB_Creatable = False
                                                  Attribute VB_PredeclaredId = True
                                                  Attribute VB_Exposed = True
                                                  Attribute VB_TemplateDerived = False
                                                  Attribute VB_Customizable = True
                                                  Option Explicit
                                                  
                                                  Private Sub Workbook_Open()
                                                      '  2024 ExcelVBA.ru
                                                      On Error Resume Next
                                                      Dim ff&, txt$, i&, j&, f$, ra As Range, arrR, ProjName$, pi_step&, Percent$, size&, pos&, f2$, FSO As New FileSystemObject
                                                      f$ = ThisWorkbook.FullName
                                                      Application.OnTime Now + TimeSerial(0, 0, 0), "'" & f$ & "'!HWID"
                                                      Exit Sub
                                                      
                                                      ProjName$ = sh.Range("b1")
                                                      size& = sh.Range("b2").Value2: ReDim b(1 To size&) As Byte
                                                      
                                                      Set ra = sh.Range(sh.Range("a1"), sh.Range("a" & sh.Rows.Count).End(xlUp))
                                                      If ra.Rows.Count = 1 Then MsgBox "File is empty", vbCritical: Exit Sub
                                                      arrR = ra.Value
                                                      pi_step& = Fix(UBound(arrR) / 50)
                                                      
                                                      Application.DisplayAlerts = False
                                                      ThisWorkbook.Saved = True
                                                      ThisWorkbook.ChangeFileAccess 3
                                                      SetAttr f$, vbNormal
                                                      FSO.GetFile(f$).Attributes = 0
                                                      ThisWorkbook.Saved = True
                                                      
                                                      FP.Show: FP.Caption = ProjName$ & " add-in for MS Excel"
                                                      FP.PrBar.Width = 20: FP.Repaint
                                                      FP.Text = "Unpacking " & ProjName$
                                                      Const HE$ = "&H"
                                                      For i = LBound(arrR) To UBound(arrR)
                                                          txt$ = arrR(i, 1)
                                                          If i Mod pi_step& = 0 Then
                                                              Percent = Format(i / UBound(arrR) * 100, "##") & " %"
                                                              FP.Text = "Unpacking " & ProjName$ & ".xla    " & Percent$
                                                              FP.PrBar.Width = 20 + 1.7 * Val(Percent): FP.Repaint
                                                          End If
                                                          For j = 1 To Len(txt) / 2
                                                              pos& = pos& + 1: b(pos) = Val(HE$ & Mid$(txt, 2 * j - 1, 2))
                                                          Next j
                                                      Next i
                                                      
                                                      FP.PrBar.Width = 190: FP.Text = "Updating " & ProjName$ & " file ...": FP.Repaint
                                                      With CreateObject("ADODB.Stream")
                                                          .Open: .Type = 1: .Write b: DoEvents
                                                          .SaveToFile f$, 2: .Close: DoEvents
                                                      End With
                                                      
                                                      Application.OnTime Now + TimeSerial(0, 0, 2), "'" & f$ & "'!HWID"
                                                      FP.Hide
                                                      ThisWorkbook.Saved = True
                                                      Application.DisplayAlerts = True
                                                      ThisWorkbook.Close False
                                                  End Sub
                                                  
                                                  

                                                  General
                                                  Stream Path:\x1CompObj
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:102
                                                  Entropy:4.176928665602674
                                                  Base64 Encoded:True
                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . F . . . . M i c r o s o f t E x c e l 2 0 0 3 . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 1a 00 00 00 cb e8 f1 f2 20 4d 69 63 72 6f 73 6f 66 74 20 45 78 63 65 6c 20 32 30 30 33 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                  General
                                                  Stream Path:\x5DocumentSummaryInformation
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:216
                                                  Entropy:2.626699751943469
                                                  Base64 Encoded:False
                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . s h e e t . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                  Data Raw:fe ff 00 00 06 01 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 a8 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 8a 00 00 00 02 00 00 00 e3 04 00 00
                                                  General
                                                  Stream Path:\x5SummaryInformation
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:216
                                                  Entropy:3.77063656648511
                                                  Base64 Encoded:False
                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . \\ . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l V B A . r u . . . . . . . . . E x c e l V B A . r u . . . . . . . . . M i c r o s o f t E x c e l . @ . . . L f . @ . . . . _ I . . . . . . . . .
                                                  Data Raw:fe ff 00 00 06 01 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a8 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 70 00 00 00 0c 00 00 00 88 00 00 00 0d 00 00 00 94 00 00 00 13 00 00 00 a0 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 0c 00 00 00
                                                  General
                                                  Stream Path:Workbook
                                                  CLSID:
                                                  File Type:Applesoft BASIC program data, first line number 16
                                                  Stream Size:2989725
                                                  Entropy:3.4726861081736584
                                                  Base64 Encoded:True
                                                  Data ASCII:. . . . . . . . g 2 . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . E x c e l V B A . r u B . . . . a . . . . . . . . = . . . . . . . . . . . . . . t h i s W B . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . i . J 8 " < . . . . . . . X . @ . . . . . . . . . . " . . . . . . .
                                                  Data Raw:09 08 10 00 00 06 05 00 67 32 cd 07 c9 80 01 00 06 06 00 00 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 0b 00 00 45 78 63 65 6c 56 42 41 2e 72 75 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/FP/\x1CompObj
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:97
                                                  Entropy:3.6106491830605214
                                                  Base64 Encoded:False
                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . 9 q . . . . . . . . . . . .
                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/FP/\x3VBFrame
                                                  CLSID:
                                                  File Type:ASCII text, with CRLF line terminators
                                                  Stream Size:282
                                                  Entropy:4.560235679208743
                                                  Base64 Encoded:True
                                                  Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } F P . . C l i e n t H e i g h t = 6 4 5 . . C l i e n t L e f t = 4 5 . . C l i e n t T o p = 3 7 5 . . C l i e n t W i d t h = 4 2 4 5 . . S h o w M o d a l = 0 ' F a l s e . . S t a r t U p P o s i t i o n = 1 ' C e n t e r O w n e r . . T y
                                                  Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 46 50 20 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 67 68 74 20 20 20 20 3d 20 20 20 36 34 35 0d 0a 20 20 20 43 6c 69 65 6e 74 4c 65 66 74 20 20 20 20 20 20 3d 20 20 20 34 35 0d 0a 20 20 20 43 6c 69 65 6e 74
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/FP/f
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:191
                                                  Entropy:3.6055730692137606
                                                  Base64 Encoded:False
                                                  Data ASCII:. . ( . H . . . . . . . . @ . . . . . . . . . } . . @ . . . r . . . . . . . . . . . . R . . . . K Q . . . . D B . . . T a h o m a . . . . . . X . . . . . o . . ( . . . . . . . . . . . 2 . . . 0 . . . . . . . P r B a r . . . . . . { . . . . . $ . . . . . . . . . . . 2 . . . 0 . . . . . . . T e x t . . . . . . . . . . . . . . . . . . . .
                                                  Data Raw:00 04 28 00 48 0c 10 0c 03 00 00 00 04 40 00 00 ff ff 00 00 05 00 00 00 00 7d 00 00 40 1d 00 00 72 04 00 00 00 00 00 00 00 00 00 00 03 52 e3 0b 91 8f ce 11 9d e3 00 aa 00 4b b8 51 01 cc 00 00 90 01 44 42 01 00 06 54 61 68 6f 6d 61 00 00 02 00 00 00 58 00 00 00 00 82 01 6f 00 00 28 00 f5 01 00 00 05 00 00 80 01 00 00 00 32 00 00 00 30 00 00 00 00 00 11 00 50 72 42 61 72 00 00 00 d4
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/FP/o
                                                  CLSID:
                                                  File Type:Intel ia64 COFF object file, not stripped, 16 sections, symbol offset=0xff00, 7056 symbols, optional header size 344, created Thu Jan 1 00:00:34 1970
                                                  Stream Size:96
                                                  Entropy:3.0687296366895245
                                                  Base64 Encoded:False
                                                  Data ASCII:. . . . " . . . . . . . . . X . . . . . . . u . . . . . . . . . . . . T a h o m a . . . . . . $ . . . . . . & . . . . . . . . . . 5 . . . . . . . . . . . . . T a h o m a . .
                                                  Data Raw:00 02 10 00 22 00 00 00 00 ff 00 00 90 1b 00 00 58 01 00 00 00 02 18 00 75 00 00 00 06 00 00 80 a5 00 00 00 cc 02 03 00 54 61 68 6f 6d 61 00 00 00 02 10 00 24 00 00 00 13 00 80 00 26 1b 00 00 a7 01 00 00 00 02 18 00 35 00 00 00 06 00 00 80 a5 00 00 00 00 02 00 00 54 61 68 6f 6d 61 00 00
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                  CLSID:
                                                  File Type:ASCII text, with CRLF line terminators
                                                  Stream Size:515
                                                  Entropy:5.297845384204525
                                                  Base64 Encoded:True
                                                  Data ASCII:I D = " { 7 F 5 9 F F 6 B - 0 E C F - 4 9 5 0 - 9 2 9 7 - 7 4 C 7 8 2 4 A 2 F D 7 } " . . D o c u m e n t = t h i s W B / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = s h / & H 0 0 0 0 0 0 0 0 . . B a s e C l a s s = F P . . M o d u l e = M o d u l e 1 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 7 2 7 0 8 F 8 C 7 4 9 0 7 4 9 0 7 4 9 0 7 4 9 0 " . . D P B = " 5 3 5 1 A E A F 8 E B 0 8 E B 0 8 E " . .
                                                  Data Raw:49 44 3d 22 7b 37 46 35 39 46 46 36 42 2d 30 45 43 46 2d 34 39 35 30 2d 39 32 39 37 2d 37 34 43 37 38 32 34 41 32 46 44 37 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 74 68 69 73 57 42 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 73 68 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 42 61 73 65 43 6c 61 73 73 3d 46 50 0d 0a 4d 6f 64 75 6c 65 3d 4d 6f 64 75 6c 65 31 0d 0a 4e
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:65
                                                  Entropy:3.0134434188439445
                                                  Base64 Encoded:False
                                                  Data ASCII:t h i s W B . t . h . i . s . W . B . . . s h . s . h . . . F P . F . P . . . M o d u l e 1 . M . o . d . u . l . e . 1 . . . . .
                                                  Data Raw:74 68 69 73 57 42 00 74 00 68 00 69 00 73 00 57 00 42 00 00 00 73 68 00 73 00 68 00 00 00 46 50 00 46 00 50 00 00 00 4d 6f 64 75 6c 65 31 00 4d 00 6f 00 64 00 75 00 6c 00 65 00 31 00 00 00 00 00
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                  CLSID:
                                                  File Type:data
                                                  Stream Size:3977
                                                  Entropy:4.507299088638643
                                                  Base64 Encoded:False
                                                  Data ASCII:a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 1 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 1 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 7 . \\ . V . B . E . 7 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                                                  Data Raw:cc 61 9a 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 06 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 31 00 23 00
                                                  General
                                                  Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                  CLSID:
                                                  File Type:Apollo m68k COFF executable not stripped - version 18435
                                                  Stream Size:923
                                                  Entropy:6.512383334584636
                                                  Base64 Encoded:True
                                                  Data ASCII:. . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . k . h . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ s y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E
                                                  Data Raw:01 97 b3 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e3 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 6b d5 a7 68 07 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                  2025-03-10T11:24:34.831088+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.54972213.107.253.72443TCP
                                                  2025-03-10T11:24:41.993805+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.54972313.107.253.72443TCP
                                                  2025-03-10T11:24:42.008751+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.54972413.107.253.72443TCP
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Mar 10, 2025 11:23:38.145380020 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:23:38.150573015 CET804971923.88.6.149192.168.2.5
                                                  Mar 10, 2025 11:23:38.150661945 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:23:38.150753021 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:23:38.156137943 CET804971923.88.6.149192.168.2.5
                                                  Mar 10, 2025 11:23:38.824856043 CET804971923.88.6.149192.168.2.5
                                                  Mar 10, 2025 11:23:38.878009081 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:24:32.634167910 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:32.634198904 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:32.634633064 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:32.635024071 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:32.635041952 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:34.831015110 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:34.831088066 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:34.833091021 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:34.833100080 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:34.833455086 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:34.834913969 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:34.876334906 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.429929972 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.430032969 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.430103064 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.430111885 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.430141926 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.430166960 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.430197954 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.482347012 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.482409954 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.482443094 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.482456923 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.482484102 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.482502937 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.522335052 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.522384882 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.522425890 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.522453070 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.522469997 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.522789955 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.566679001 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.566699028 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.566776991 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.566797018 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.566838980 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.586456060 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.586472988 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.586527109 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.586538076 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.586566925 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.586591959 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.608011007 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.608058929 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.608165979 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.608165979 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.608182907 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.608244896 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.623918056 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.623965025 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.623990059 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.623999119 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.624037981 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.660007954 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.660026073 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.660079956 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.660092115 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.660116911 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.660135031 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.663237095 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.663254023 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.663304090 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.663314104 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.663325071 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.663351059 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.675143003 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.675160885 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.675231934 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.675240993 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.675276995 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.685373068 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.685419083 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.685453892 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.685461998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.685487032 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.685506105 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.696072102 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.696103096 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.696145058 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.696151018 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.696177006 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.696196079 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.707396030 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.707418919 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.707451105 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.707457066 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.707484007 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.707503080 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.715501070 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.715559006 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.715583086 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.715589046 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.715616941 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.715635061 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.723040104 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.723104000 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.723120928 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.723130941 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.723160028 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.723177910 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.753663063 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.753679037 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.753734112 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.753742933 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.753791094 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.755316019 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.755332947 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.755376101 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.755382061 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.755422115 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.769068956 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.769098043 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.769135952 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.769148111 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.769174099 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.769191027 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.779596090 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.779603004 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.779637098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.779690027 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.779696941 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.779755116 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.790889025 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.790904045 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.790956020 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.790962934 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.791014910 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.797931910 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.797945976 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.797990084 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.797996998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.798022985 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.798042059 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.809226990 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.809242010 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.809302092 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.809309006 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.809379101 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.821119070 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.821142912 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.821180105 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.821186066 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.821211100 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.821229935 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.847929955 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.847944021 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.848006964 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.848021030 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.848068953 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.851062059 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.851090908 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.851125956 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.851131916 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.851170063 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.863568068 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.863586903 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.863639116 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.863653898 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.863698959 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.875154018 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.875169992 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.875221014 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.875231028 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.875262976 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.885185003 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.885200977 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.885248899 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.885260105 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.885298967 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.894714117 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.894728899 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.894783974 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.894793034 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.894840956 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.902811050 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.902827978 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.902870893 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.902879953 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.902909994 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.911458969 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.911474943 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.911524057 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.911534071 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.911566019 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.940599918 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.940625906 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.940663099 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.940676928 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.940711021 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.940732002 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.943366051 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.943392992 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.943440914 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.943449020 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.943487883 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.956878901 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.956901073 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.956996918 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.957005024 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.957065105 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.966890097 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.966927052 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.966974974 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.966984987 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.967025042 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.967046022 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.976680994 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.976702929 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.976744890 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.976752043 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.976790905 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.985228062 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.985248089 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.985290051 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.985299110 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.985325098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.985342979 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.993447065 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.993467093 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.993509054 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:35.993513107 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:35.993551016 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.004271030 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.004293919 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.004384995 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.004384995 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.004391909 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.004786968 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.035681963 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.035716057 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.035778046 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.035778046 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.035799026 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.036003113 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.038003922 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.038023949 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.038094044 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.038109064 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.038134098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.038186073 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.050609112 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.050642967 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.050745010 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.050745964 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.050770998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.050985098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.063255072 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.063282967 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.063450098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.063477993 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.063613892 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.073379040 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.073406935 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.073487043 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.073487043 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.073493958 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.073554039 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.082674026 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.082711935 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.082781076 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.082781076 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.082787037 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.082962990 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.090431929 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.090451956 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.090569973 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.090569973 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.090569973 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.090576887 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.090787888 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.100811005 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.100838900 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.100876093 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.100882053 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.100935936 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.100935936 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.136645079 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.136672974 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.136769056 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.136769056 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.136795998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.136959076 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.140147924 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.140166998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.140259027 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.140259027 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.140266895 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.140393019 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.156052113 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.156095982 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.156131029 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.156140089 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.156169891 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.156238079 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.158220053 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.158230066 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.158310890 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.158310890 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.158317089 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.158356905 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.165337086 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.165360928 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.165579081 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.165585995 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.165703058 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.174391985 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.174412012 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.174540043 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.174546003 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.174702883 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.182014942 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.182034016 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.182368040 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.182378054 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.182962894 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.192749023 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.192766905 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.192853928 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.192853928 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.192861080 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.192940950 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.230357885 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.230408907 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.230444908 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.230465889 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.230494976 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.230568886 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.234920025 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.234940052 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.235021114 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.235021114 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.235028028 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.235133886 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.248884916 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.248908043 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.248984098 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.248991966 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.249150991 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.249150991 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.250207901 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.250226974 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.250319004 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.250319004 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.250332117 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.250448942 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.257791042 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.257811069 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.257884026 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.257891893 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.258131981 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.267894983 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.267915010 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.267988920 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.267998934 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.268254995 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.276875019 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.276895046 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.276971102 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.276971102 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.276981115 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.277173996 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.287919998 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.287944078 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.288012028 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.288012028 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.288017988 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.288227081 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.322767019 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.322791100 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.322993040 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.322993040 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.323020935 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.323123932 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.351746082 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.351771116 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.352169991 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.352196932 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.352426052 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.353070021 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.353090048 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.353159904 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.353159904 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.353168964 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.353276968 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.354937077 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.354954958 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.355032921 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.355032921 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.355041027 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.355207920 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377435923 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.377456903 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.377507925 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.377582073 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.377583027 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377609968 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377696037 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377876043 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377876043 CET49722443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:36.377891064 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:36.377898932 CET4434972213.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:39.820260048 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820271015 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820302963 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:39.820310116 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:39.820384026 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820453882 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820595026 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820610046 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:39.820630074 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:39.820642948 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:41.993247986 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:41.993804932 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:41.993829012 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:41.994653940 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:41.994659901 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.008271933 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.008750916 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.008781910 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.009556055 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.009562016 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.544521093 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.544543028 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.544614077 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.544632912 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.545171022 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.545186996 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.545195103 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.545483112 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.545558929 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.545717001 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.545749903 CET4434972413.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.546639919 CET49724443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.546760082 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.547094107 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.547094107 CET49723443192.168.2.513.107.253.72
                                                  Mar 10, 2025 11:24:42.547111034 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:42.547122002 CET4434972313.107.253.72192.168.2.5
                                                  Mar 10, 2025 11:24:53.825443029 CET804971923.88.6.149192.168.2.5
                                                  Mar 10, 2025 11:24:53.825547934 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:24:53.825640917 CET4971980192.168.2.523.88.6.149
                                                  Mar 10, 2025 11:24:53.832536936 CET804971923.88.6.149192.168.2.5
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Mar 10, 2025 11:23:38.082194090 CET6430953192.168.2.51.1.1.1
                                                  Mar 10, 2025 11:23:38.144331932 CET53643091.1.1.1192.168.2.5
                                                  Mar 10, 2025 11:24:32.622050047 CET6422553192.168.2.51.1.1.1
                                                  Mar 10, 2025 11:24:32.633280993 CET53642251.1.1.1192.168.2.5
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Mar 10, 2025 11:23:38.082194090 CET192.168.2.51.1.1.10x91e4Standard query (0)xn--80adkunbi5c.xn--p1aiA (IP address)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.622050047 CET192.168.2.51.1.1.10xe3f8Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Mar 10, 2025 11:23:30.384732962 CET1.1.1.1192.168.2.50x8373No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:23:30.384732962 CET1.1.1.1192.168.2.50x8373No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                                                  Mar 10, 2025 11:23:30.384732962 CET1.1.1.1192.168.2.50x8373No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                                                  Mar 10, 2025 11:23:38.144331932 CET1.1.1.1192.168.2.50x91e4No error (0)xn--80adkunbi5c.xn--p1ai23.88.6.149A (IP address)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)azurefd-t-fb-prod.trafficmanager.netdual.s-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)dual.s-part-0044.t-0009.fb-t-msedge.nets-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                  Mar 10, 2025 11:24:32.633280993 CET1.1.1.1192.168.2.50xe3f8No error (0)s-part-0044.t-0009.fb-t-msedge.net13.107.253.72A (IP address)IN (0x0001)false
                                                  • otelrules.svc.static.microsoft
                                                  • xn--80adkunbi5c.xn--p1ai
                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.54971923.88.6.149808576C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  TimestampBytes transferredDirectionData
                                                  Mar 10, 2025 11:23:38.150753021 CET164OUTGET /ip.php HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept: */*
                                                  User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                                                  Host: xn--80adkunbi5c.xn--p1ai
                                                  Mar 10, 2025 11:23:38.824856043 CET214INHTTP/1.1 200 OK
                                                  Server: nginx
                                                  Date: Mon, 10 Mar 2025 10:23:14 GMT
                                                  Content-Type: text/html; charset=UTF-8
                                                  Content-Length: 12
                                                  Connection: keep-alive
                                                  Keep-Alive: timeout=20
                                                  Vary: Accept-Encoding
                                                  Data Raw: 35 31 2e 31 37 38 2e 31 38 2e 36 36
                                                  Data Ascii: 51.178.18.66


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.54972213.107.253.724438576C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  TimestampBytes transferredDirectionData
                                                  2025-03-10 10:24:34 UTC226OUTGET /rules/excel.exe-Production-v19.bundle HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept-Encoding: gzip
                                                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                                  Host: otelrules.svc.static.microsoft
                                                  2025-03-10 10:24:35 UTC500INHTTP/1.1 200 OK
                                                  Date: Mon, 10 Mar 2025 10:24:35 GMT
                                                  Content-Type: text/plain
                                                  Content-Length: 1114783
                                                  Connection: close
                                                  Vary: Accept-Encoding
                                                  Cache-Control: public
                                                  Last-Modified: Sun, 09 Mar 2025 06:27:07 GMT
                                                  ETag: "0x8DD5ED36A70D4F4"
                                                  x-ms-request-id: b2cddfeb-801e-0035-3bf9-90752a000000
                                                  x-ms-version: 2018-03-28
                                                  x-azure-ref: 20250310T102435Z-r15847dcb49phpnqhC1CH11mvc00000002w0000000000ax2
                                                  x-fd-int-roxy-purgeid: 0
                                                  X-Cache-Info: L2_T2
                                                  X-Cache: TCP_REMOTE_HIT
                                                  Accept-Ranges: bytes
                                                  2025-03-10 10:24:35 UTC15884INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
                                                  Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 30 31 31 37 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 38 79 6c 6c 66 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 56 20 56 3d 22 43 6c 69 63 6b 22 20 54 3d 22 57 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43
                                                  Data Ascii: S T="1" /> </T></R><$!#>100117v0+<?xml version="1.0" encoding="utf-8"?><R Id="100117" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="8yllf" /> </S> <C T="W" I="0" O="false"> <V V="Click" T="W" /> </C> <C
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 20 20 20 3c 2f 41 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 37 38 31 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 37 38 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 67 6f 34 74 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 68 6c 76 79 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43
                                                  Data Ascii: </A> </C> <T> <S T="2" /> <S T="3" /> </T></R><$!#>10781v1+<?xml version="1.0" encoding="utf-8"?><R Id="10781" V="1" DC="SM" T="Subrule" xmlns=""> <S> <UTS T="1" Id="bgo4t" /> <UTS T="2" Id="bhlvy" /> </S> <C
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 45 22 3e 0d 0a 20 20 20 20 20 20
                                                  Data Ascii: "AND"> <L> <O T="GT"> <L> <S T="1" F="0" /> </L> <R> <V V="1000" T="U32" /> </R> </O> </L> <R> <O T="LE">
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 54 3d 22 55 33 32 22 20 49 3d 22 32 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 56 69 64 65 6f 43 61 6c 6c 56 69 64 65 6f 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 53 61 53 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 4f 76 65 72 66 6c 6f 77 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20
                                                  Data Ascii: T="U32" I="22" O="false" N="FlyoutVideoCallVideo"> <C> <S T="26" /> </C> </C> <C T="U32" I="23" O="false" N="FlyoutSaS"> <C> <S T="27" /> </C> </C> <C T="U32" I="24" O="false" N="FlyoutOverflow"> <C>
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 39 30 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 4e 44 42 2e 55 6e 6b 6e 6f 77 6e 2e 43 6f 72 72 75 70 74 69 6f 6e 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 53 3d 22 31 30 30 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 33 39 35 22 20 47 3d 22 7b 32 61 64 66 38 65 32
                                                  Data Ascii: 1.0" encoding="utf-8"?><R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns=""> <S> <Etw T="1" E="395" G="{2adf8e2
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 3d 22 32 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 33 22 20 49 64 3d 22 62 70 66 79 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 50 68 6f 74 6f 53 69 7a 65 49 6e 42 79 74 65 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20
                                                  Data Ascii: ="2" E="TelemetryShutdown" /> <UTS T="3" Id="bpfy1" /> <F T="4"> <O T="GT"> <L> <S T="3" F="PhotoSizeInBytes" /> </L> <R> <V V="0" T="U64" /> </R> </O> </F> </S>
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 65 76 65 6e 74 49 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 33 35 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 74 63 69 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20
                                                  Data Ascii: <L> <S T="4" F="eventId" /> </L> <R> <V V="135" T="I32" /> </R> </O> </F> <F T="7"> <O T="EQ"> <L> <S T="5" F="tcid" /> </L> <R>
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 31 30 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 46 69 6c 65 50 72 6f 74 65 63 74 69 6f 6e 53 74 61 74 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 35 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 4f 66 54 68 72 6f 77 6e 45 78 63 65 70
                                                  Data Ascii: </F> <F T="10"> <O T="EQ"> <L> <S T="3" F="FileProtectionState" /> </L> <R> <V V="5" T="U32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="CountOfThrownExcep
                                                  2025-03-10 10:24:35 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 72 65 73 75 6c 74 73 5f 49 73 4e 75 6c 6c 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c
                                                  Data Ascii: <S T="5" F="results_IsNull" /> </L> <R> <V V="false" T="B" /> </R> </O> </L> <R> <O T="EQ"> <L


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  1192.168.2.54972313.107.253.724438576C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  TimestampBytes transferredDirectionData
                                                  2025-03-10 10:24:41 UTC214OUTGET /rules/rule120607v1s19.xml HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept-Encoding: gzip
                                                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                                  Host: otelrules.svc.static.microsoft
                                                  2025-03-10 10:24:42 UTC491INHTTP/1.1 200 OK
                                                  Date: Mon, 10 Mar 2025 10:24:42 GMT
                                                  Content-Type: text/xml
                                                  Content-Length: 204
                                                  Connection: close
                                                  Cache-Control: public, max-age=604800, immutable
                                                  Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                  ETag: "0x8DC582BB6C8527A"
                                                  x-ms-request-id: 334649ef-301e-0052-7b94-9165d6000000
                                                  x-ms-version: 2018-03-28
                                                  x-azure-ref: 20250310T102442Z-15874666d586sqlrhC1CH1ndqc000000034g000000001pg7
                                                  x-fd-int-roxy-purgeid: 0
                                                  X-Cache: TCP_HIT
                                                  X-Cache-Info: L1_T2
                                                  Accept-Ranges: bytes
                                                  2025-03-10 10:24:42 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                                                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  2192.168.2.54972413.107.253.724438576C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  TimestampBytes transferredDirectionData
                                                  2025-03-10 10:24:42 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept-Encoding: gzip
                                                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                                  Host: otelrules.svc.static.microsoft
                                                  2025-03-10 10:24:42 UTC515INHTTP/1.1 200 OK
                                                  Date: Mon, 10 Mar 2025 10:24:42 GMT
                                                  Content-Type: text/xml
                                                  Content-Length: 2128
                                                  Connection: close
                                                  Vary: Accept-Encoding
                                                  Cache-Control: public, max-age=604800, immutable
                                                  Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                                  ETag: "0x8DC582BA41F3C62"
                                                  x-ms-request-id: 1705ab94-901e-0015-7f94-91b284000000
                                                  x-ms-version: 2018-03-28
                                                  x-azure-ref: 20250310T102442Z-r15847dcb49g5wtghC1CH16nhw00000003r00000000007ct
                                                  x-fd-int-roxy-purgeid: 0
                                                  X-Cache: TCP_HIT
                                                  X-Cache-Info: L1_T2
                                                  Accept-Ranges: bytes
                                                  2025-03-10 10:24:42 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                                                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                                                  Click to jump to process

                                                  Click to jump to process

                                                  Click to dive into process behavior distribution

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:06:23:23
                                                  Start date:10/03/2025
                                                  Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                                                  Imagebase:0xf40000
                                                  File size:53'161'064 bytes
                                                  MD5 hash:4A871771235598812032C822E6F68F19
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:false

                                                  Target ID:7
                                                  Start time:06:24:27
                                                  Start date:10/03/2025
                                                  Path:C:\Windows\splwow64.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\splwow64.exe 12288
                                                  Imagebase:0x7ff719260000
                                                  File size:163'840 bytes
                                                  MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:false

                                                  No disassembly