Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
840.xls

Overview

General Information

Sample name:840.xls
Analysis ID:1634243
MD5:71918c291c0f0ebe8b805f668874352e
SHA1:d1a0e7ca536648fcc29d4fd25d10f02d68744654
SHA256:33ffc2f4edc498646a54368bbfb8a0c23b04e993be047f2163c8a9f4fe258915
Tags:CVE-2017-0199xlsuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Excel sheet contains many unusual embedded objects
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 6260 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 3164 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 5028 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\840.xls" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DesusertionIp: 3.39.153.44, DesusertionIsIpv6: false, DesusertionPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6260, Protocol: tcp, SourceIp: 192.168.2.9, SourceIsIpv6: false, SourcePort: 49716
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DesusertionIp: 192.168.2.9, DesusertionIsIpv6: false, DesusertionPort: 49716, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6260, Protocol: tcp, SourceIp: 3.39.153.44, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-10T21:23:50.532368+010020283713Unknown Traffic192.168.2.94972213.107.246.60443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 840.xlsAvira: detected
Source: C:\Users\user\AppData\Local\Temp\~DFFC4FC9A2FFE20641.TMPAvira: detection malicious, Label: W97M/AVI.Agent.rdejg
Source: 840.xlsVirustotal: Detection: 43%Perma Link
Source: 840.xlsReversingLabs: Detection: 28%
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: global trafficDNS query: name: link.saja.market
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49716
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49716
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49716
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49716 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49716
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49720
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49720
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49722
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49722
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49720
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49720 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49720
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49724
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 3.39.153.44:443 -> 192.168.2.9:49724
Source: global trafficTCP traffic: 192.168.2.9:49724 -> 3.39.153.44:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49722
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49722 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49722
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49725
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49725
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49725
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.9:49725 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.9:49725
Source: excel.exeMemory has grown: Private usage: 2MB later: 130MB
Source: Joe Sandbox ViewIP Address: 3.39.153.44 3.39.153.44
Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.9:49722 -> 13.107.246.60:443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: link.saja.market
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: 840.xls, ~DFFC4FC9A2FFE20641.TMP.14.drString found in binary or memory: https://link.saja.market/C2u1VBnfiL?&graphic=knowledgeable&vineyard8
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724

System Summary

barindex
Source: 840.xlsOLE: Microsoft Excel 2007+
Source: ~DFFC4FC9A2FFE20641.TMP.14.drOLE: Microsoft Excel 2007+
Source: 840.xlsOLE indicator, VBA macros: true
Source: ~DFFC4FC9A2FFE20641.TMP.14.drOLE indicator, VBA macros: true
Source: 840.xlsStream path 'MBD003EBE92/\x1Ole' : https://link.saja.market/C2u1VBnfiL?&graphic=knowledgeable&vineyard8,ciAHmAYjW###>+J^%HVO>?):]%uI3+5ww!|lag?reeB#{(QGjT,.9>g*&sW{a|uasU5Ty4ryOQVmiFd7N22aEKxjL82GNg49RbFWlqW4U2qpTjAFzrppWQmeUYJg6SjSxvb0eEVINA7QXMkT7kx4(*A%V9zd4[X
Source: ~DFFC4FC9A2FFE20641.TMP.14.drStream path 'MBD003EBE92/\x1Ole' : https://link.saja.market/C2u1VBnfiL?&graphic=knowledgeable&vineyard8,ciAHmAYjW###>+J^%HVO>?):]%uI3+5ww!|lag?reeB#{(QGjT,.9>g*&sW{a|uasU5Ty4ryOQVmiFd7N22aEKxjL82GNg49RbFWlqW4U2qpTjAFzrppWQmeUYJg6SjSxvb0eEVINA7QXMkT7kx4(*A%V9zd4[X
Source: classification engineClassification label: mal68.winXLS@4/4@3/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{A4FBD893-C1D2-4C62-A98E-379B4DB79833} - OProcSessId.datJump to behavior
Source: 840.xlsOLE indicator, Workbook stream: true
Source: ~DFFC4FC9A2FFE20641.TMP.14.drOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: 840.xlsVirustotal: Detection: 43%
Source: 840.xlsReversingLabs: Detection: 28%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\840.xls"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: 840.xlsStatic file information: File size 1197568 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: 840.xlsInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: 840.xlsStream path 'MBD003EBE91/MBD001688DC/Package' entropy: 7.96606885719 (max. 8.0)
Source: 840.xlsStream path 'Workbook' entropy: 7.99843056069 (max. 8.0)
Source: ~DFFC4FC9A2FFE20641.TMP.14.drStream path 'MBD003EBE91/MBD001688DC/Package' entropy: 7.96606885719 (max. 8.0)
Source: ~DFFC4FC9A2FFE20641.TMP.14.drStream path 'Workbook' entropy: 7.99843056069 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 588Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts3
Exploitation for Client Execution
1
Scripting
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Extra Window Memory Injection
LSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
840.xls44%VirustotalBrowse
840.xls29%ReversingLabsWin32.Exploit.CVE-2017-0199
840.xls100%AviraW97M/AVI.Agent.rdejg
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\~DFFC4FC9A2FFE20641.TMP100%AviraW97M/AVI.Agent.rdejg
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://link.saja.market/C2u1VBnfiL?&graphic=knowledgeable&vineyard80%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    high
    s-part-0044.t-0009.fb-t-msedge.net
    13.107.253.72
    truefalse
      high
      s-0005.dual-s-msedge.net
      52.123.128.14
      truefalse
        high
        service-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.com
        3.39.153.44
        truefalse
          high
          s-part-0032.t-0009.t-msedge.net
          13.107.246.60
          truefalse
            high
            otelrules.svc.static.microsoft
            unknown
            unknownfalse
              high
              link.saja.market
              unknown
              unknownfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://link.saja.market/C2u1VBnfiL?&graphic=knowledgeable&vineyard8840.xls, ~DFFC4FC9A2FFE20641.TMP.14.drfalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                3.39.153.44
                service-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.comUnited States
                8987AMAZONEXPANSIONGBfalse
                13.107.246.60
                s-part-0032.t-0009.t-msedge.netUnited States
                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1634243
                Start date and time:2025-03-10 21:21:29 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 5m 15s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsofficecookbook.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Run name:Without Instrumentation
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:840.xls
                Detection:MAL
                Classification:mal68.winXLS@4/4@3/2
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Found application associated with file extension: .xls
                • Found Word or Excel or PowerPoint or XPS Viewer
                • Attach to Office via COM
                • Active ActiveX Object
                • Active ActiveX Object
                • Scroll down
                • Close Viewer
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.109.28.47, 2.16.185.191, 199.232.210.172, 13.69.116.107, 23.60.203.209, 52.109.76.240, 52.123.128.14
                • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, eur.roaming1.live.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, roaming.officeapps.live.com, dual-s-0005-office.config.skype.com, login.live.com, onedscolprdweu09.westeurope.cloudapp.azure.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, c.pki.goog, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, uks-azsc-000.roaming.officeapps.live.com, neu-azsc-config.officeapps.live.com, config.officeapps.live.com, e16604.f.akamaiedge.net, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.net, uks-azsc-config.officeapps.live.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtCreateKey calls found.
                • Report size getting too big, too many NtQueryAttributesFile calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • Report size getting too big, too many NtReadVirtualMemory calls found.
                TimeTypeDescription
                16:23:49API Interceptor616x Sleep call for process: splwow64.exe modified
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                3.39.153.44POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                    POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                      POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                          13.107.246.60https://protect-us.mimecast.com/s/wFHoCqxrAnt7V914iZaD1vGet hashmaliciousUnknownBrowse
                          • www.mimecast.com/Customers/Support/Contact-support/
                          http://wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5Get hashmaliciousUnknownBrowse
                          • wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          service-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.comCOTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          Order_Mar25.xlsGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.153.44
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.153.44
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.153.44
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          s-0005.dual-s-msedge.netCOTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                          • 52.123.128.14
                          Order_Mar25.xlsGet hashmaliciousUnknownBrowse
                          • 52.123.128.14
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 52.123.129.14
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 52.123.129.14
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 52.123.129.14
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 52.123.129.14
                          phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
                          • 52.123.129.14
                          LinkedIn Message.emlGet hashmaliciousUnknownBrowse
                          • 52.123.128.14
                          EXTERNAL Olgoonik Development IT User Invitation.msgGet hashmaliciousUnknownBrowse
                          • 52.123.128.14
                          bg.microsoft.map.fastly.netU00b7pdf.vbsGet hashmaliciousFormBook, GuLoaderBrowse
                          • 199.232.214.172
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          file.exeGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          Section_PE32_image_Aint13_Aint13_body.efi.dllGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          Fd-Employee-Handbook(1).pdfGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          PEDIDO DE OR#U00c7AMENTO (Universidade NOVA de Lisboa) 03-10-2025#U00b7pdf.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                          • 199.232.214.172
                          ANGEBOTSANFRAGE (Universit#U00e4t Klagenfurt) 10-03-2025#U00b7pdf.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                          • 199.232.210.172
                          Online Notification.pdfGet hashmaliciousHTMLPhisherBrowse
                          • 199.232.210.172
                          FW 188355..msgGet hashmaliciousHTMLPhisherBrowse
                          • 199.232.214.172
                          s-part-0044.t-0009.fb-t-msedge.netATT09858.htmGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.72
                          R.D. Bitzer Co. Inc.xlsmGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          221036299-043825-sanlccjavap0004-6531.xlsGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          https://assets-fra.mkt.dynamics.com/b3baa109-6efd-ef11-b016-002248d9b9fa/digitalassets/standaloneforms/fe7058e5-a1fd-ef11-bae3-000d3a959714#_msdynmkt_donottrack=0,_msdynmkt_linkid=37db13e4-8bf7-4e91-a0fa-9dd02c9e6ee4Get hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.72
                          https://0utl00k_secure_pdfsharing.wesendit.com/dl/9WeFG1R9WGJTbgaCO/a3Jpc3RhbC5wbGFpc3RlZEBzb2RleG8uY29t__;!!P5FZM7ryyeY!UznDjsW7gO6EJncqNmJhgeM1Zawk4R__aUyCoG6Jb-mYlr-79K2gn3tFm6bOpnkuKuN_n69fA8HZASZsr-9bQyk$Get hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          https://0utl00k_secure_pdfsharing.wesendit.com/dl/9WeFG1R9WGJTbgaCO/a3Jpc3RhbC5wbGFpc3RlZEBzb2RleG8uY29t__;!!P5FZM7ryyeY!UznDjsW7gO6EJncqNmJhgeM1Zawk4R__aUyCoG6Jb-mYlr-79K2gn3tFm6bOpnkuKuN_n69fA8HZASZsr-9bQyk$Get hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          PastePictures 1.xlaGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          f1215469392.dllGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.253.72
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          MICROSOFT-CORP-MSN-AS-BLOCKUSCOTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          Nouvelle_commande9353834.xlsGet hashmaliciousUnknownBrowse
                          • 20.42.65.88
                          Order_Mar25.xlsGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.253.42
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          https://simplified.com/designs/7d05440c-37c6-4466-b5ff-6e61f39c0350/share?utm_content=7d05440c-37c6-4466-b5ff-6e61f39c0350&utm_campaign=share&utm_medium=link&utm_source=projectlinksGet hashmaliciousUnknownBrowse
                          • 13.107.246.60
                          AMAZONEXPANSIONGBCOTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          Order_Mar25.xlsGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          POETDB24-2577.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.153.44
                          POETDB24-25771.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 3.39.89.152
                          URGENT REQUEST FOR QUOTATION.exeGet hashmaliciousFormBookBrowse
                          • 3.33.130.190
                          Online Notification.pdfGet hashmaliciousHTMLPhisherBrowse
                          • 3.33.235.249
                          No context
                          No context
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):118
                          Entropy (8bit):3.5700810731231707
                          Encrypted:false
                          SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                          MD5:573220372DA4ED487441611079B623CD
                          SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                          SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                          SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):512
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):512
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon Mar 10 00:40:26 2025, Security: 1
                          Category:dropped
                          Size (bytes):1197568
                          Entropy (8bit):7.7297085918058865
                          Encrypted:false
                          SSDEEP:24576:5twhvu7MYDLpWDWzAg48MKzLdv4bJknXcvhzUrKfr9e/cWO:QyyWzv48P1v4bWXAhzUrKfr9f
                          MD5:71918C291C0F0EBE8B805F668874352E
                          SHA1:D1A0E7CA536648FCC29D4FD25D10F02D68744654
                          SHA-256:33FFC2F4EDC498646A54368BBFB8A0C23B04E993BE047F2163C8A9F4FE258915
                          SHA-512:8D1EB9A054DB6336553ACCB94CB3A8835B6F12E8493A2342C31BABA8927995A1381465BD88FDD171D9C1B5AA4FF974499E00E03FC890EF6A8F0A74E0254568CB
                          Malicious:true
                          Antivirus:
                          • Antivirus: Avira, Detection: 100%
                          Preview:......................>...............................................................................................................|.......~........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon Mar 10 00:40:26 2025, Security: 1
                          Entropy (8bit):7.7297085918058865
                          TrID:
                          • Microsoft Excel sheet (30009/1) 47.99%
                          • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                          • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                          File name:840.xls
                          File size:1'197'568 bytes
                          MD5:71918c291c0f0ebe8b805f668874352e
                          SHA1:d1a0e7ca536648fcc29d4fd25d10f02d68744654
                          SHA256:33ffc2f4edc498646a54368bbfb8a0c23b04e993be047f2163c8a9f4fe258915
                          SHA512:8d1eb9a054db6336553accb94cb3a8835b6f12e8493a2342c31baba8927995a1381465bd88fdd171d9c1b5aa4ff974499e00e03fc890ef6a8f0a74e0254568cb
                          SSDEEP:24576:5twhvu7MYDLpWDWzAg48MKzLdv4bJknXcvhzUrKfr9e/cWO:QyyWzv48P1v4bWXAhzUrKfr9f
                          TLSH:DC4512459BC2EC5ADA5D533049F68B690A069CF3D249710F292AFFD437B3E323762216
                          File Content Preview:........................>...............................................................................................................|.......~..............................................................................................................
                          Icon Hash:35ed8e920e8c81b5
                          Document Type:OLE
                          Number of OLE Files:1
                          Has Summary Info:
                          Application Name:Microsoft Excel
                          Encrypted Document:True
                          Contains Word Document Stream:False
                          Contains Workbook/Book Stream:True
                          Contains PowerPoint Document Stream:False
                          Contains Visio Document Stream:False
                          Contains ObjectPool Stream:False
                          Flash Objects Count:0
                          Contains VBA Macros:True
                          Code Page:1252
                          Author:
                          Last Saved By:
                          Create Time:2006-09-16 00:00:00
                          Last Saved Time:2025-03-10 00:40:26
                          Creating Application:Microsoft Excel
                          Security:1
                          Document Code Page:1252
                          Thumbnail Scaling Desired:False
                          Contains Dirty Links:False
                          Shared Document:False
                          Changed Hyperlinks:False
                          Application Version:786432
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                          VBA File Name:Sheet1.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 14 ee b0 07 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet1"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                          VBA File Name:Sheet2.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ` . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 14 ee a2 60 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet2"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                          VBA File Name:Sheet3.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 14 ee 32 8a 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet3"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                          VBA File Name:ThisWorkbook.cls
                          Stream Size:985
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 14 ee 92 3d 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "ThisWorkbook"
                          Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:244
                          Entropy:2.889430592781307
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:200
                          Entropy:3.2403503175049817
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . y . U . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                          General
                          Stream Path:MBD003EBE91/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD003EBE91/\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:296
                          Entropy:3.2973193143624515
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . S h e e t 1 ! P r i n t _ A r e a . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 f8 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 b7 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:MBD003EBE91/\x5SummaryInformation
                          CLSID:
                          File Type:dBase III DBT, version number 0, next free block index 65534, 1st item "\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\360\346\341\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377"
                          Stream Size:114800
                          Entropy:4.36630757606626
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . @ . . . . . . . . . . P . . . . . . . X . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . K e n n y C h e u n g . . . . . . . . . . . . 9 1 9 7 4 . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . m . . . @ . . . . _ ~ . \\ S . @ . . . . 0 N Z . . . . . . . . . G . . . t . . . . . . . . u . f . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 40 c0 01 00 09 00 00 00 01 00 00 00 50 00 00 00 04 00 00 00 58 00 00 00 08 00 00 00 70 00 00 00 12 00 00 00 80 00 00 00 0b 00 00 00 98 00 00 00 0c 00 00 00 a4 00 00 00 0d 00 00 00 b0 00 00 00 13 00 00 00 bc 00 00 00 11 00 00 00 c4 00 00 00
                          General
                          Stream Path:MBD003EBE91/MBD001688DC/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.219515110876372
                          Base64 Encoded:False
                          Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD003EBE91/MBD001688DC/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:257320
                          Entropy:7.966068857185235
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . S i . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 03 53 ca 69 a2 01 00 00 b2 06 00 00 13 00 d0 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 cc 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD003EBE91/Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:530780
                          Entropy:7.831634327574399
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . ? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . h : . 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                          General
                          Stream Path:MBD003EBE92/\x1Ole
                          CLSID:
                          File Type:data
                          Stream Size:570
                          Entropy:5.642166282722727
                          Base64 Encoded:False
                          Data ASCII:. . . . " H p . . . . . . . . . . . . . . . . y . . . K . * . . . h . t . t . p . s . : . / . / . l . i . n . k . . . s . a . j . a . . . m . a . r . k . e . t . / . C . 2 . u . 1 . V . B . n . f . i . L . ? . & . g . r . a . p . h . i . c . = . k . n . o . w . l . e . d . g . e . a . b . l . e . & . v . i . n . e . y . a . r . d . . . 8 , c i A . H m A Y j . . W # # # > + . J ^ % . . H V O > ? ) : ] % u I 3 + . 5 . w w . ! . . | l a . g ? r e e B # . { . . ( Q G j . T , . . 9 . > g * . . . & s . W { . a .
                          Data Raw:01 00 00 02 9b ba 82 22 fe 80 48 70 00 00 00 00 00 00 00 00 00 00 00 00 2e 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b 2a 01 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 6c 00 69 00 6e 00 6b 00 2e 00 73 00 61 00 6a 00 61 00 2e 00 6d 00 61 00 72 00 6b 00 65 00 74 00 2f 00 43 00 32 00 75 00 31 00 56 00 42 00 6e 00 66 00 69 00 4c 00 3f 00 26 00 67 00 72 00 61 00
                          General
                          Stream Path:Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:268533
                          Entropy:7.9984305606868205
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . y . . . . J . . ` R n % . . . X \\ . z k ' . g 6 . . . . . . . . . . . . . \\ . p . ^ = u E d ( U . 3 A \\ . . 3 @ : 4 . E . . . 8 c Q . b H & k [ 3 Y ~ s C , y o q > . . % W . l y . u ( 3 . . A . g B . . . . a . . . [ . . . . = . . . T . * . . . G . . p A | m r . . . . ) . . . . x . . . . q . . . . . . . . . . . . G = . . . , . ( p . e . N E @ . . . . M . . . " . . . 3 . . . . % . . . . . . 1 . . . ) . . D c = . @ k u # . ` 1 . . . = s ) m @ , K v . J .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 79 ca ae 0b f6 da 07 02 4a 0a 00 60 52 6e f2 25 99 fa a5 04 10 ba be f1 f1 d1 a6 58 5c cc 96 9b 7a d8 6b 27 bc 03 e0 67 cd 36 9e 17 0f d7 b9 d6 e1 00 02 00 b0 04 c1 00 02 00 a5 8f e2 00 00 00 5c 00 70 00 5e a0 d8 3d 75 a1 45 64 28 55 d4 13 33 41 5c 1f 0d 97 aa f3 e8 a8 33 40 3a 87 b2 34 2e de
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECT
                          CLSID:
                          File Type:ASCII text, with CRLF line terminators
                          Stream Size:529
                          Entropy:5.23867416648483
                          Base64 Encoded:True
                          Data ASCII:I D = " { A 2 6 7 B 7 0 5 - 5 E 3 0 - 4 4 2 F - 8 9 0 9 - C B D F 6 6 1 6 1 E 5 B } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 0 C 0 E D C E 6 2 C 1 A 3 0 1 A 3
                          Data Raw:49 44 3d 22 7b 41 32 36 37 42 37 30 35 2d 35 45 33 30 2d 34 34 32 46 2d 38 39 30 39 2d 43 42 44 46 36 36 31 36 31 45 35 42 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                          CLSID:
                          File Type:data
                          Stream Size:104
                          Entropy:3.0488640812019017
                          Base64 Encoded:False
                          Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                          Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                          CLSID:
                          File Type:data
                          Stream Size:2644
                          Entropy:3.983205698147401
                          Base64 Encoded:False
                          Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                          Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/dir
                          CLSID:
                          File Type:data
                          Stream Size:553
                          Entropy:6.368204104473992
                          Base64 Encoded:True
                          Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E
                          Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 10 c3 e5 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                          2025-03-10T21:23:50.532368+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.94972213.107.246.60443TCP
                          TimestampSource PortDest PortSource IPDest IP
                          Mar 10, 2025 21:23:32.715785027 CET49716443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:32.715820074 CET443497163.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:32.715890884 CET49716443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:32.716295958 CET49716443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:32.716319084 CET443497163.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:40.968219995 CET443497163.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:40.968314886 CET49716443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:40.968413115 CET49716443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:40.968431950 CET443497163.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:40.969367981 CET49720443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:40.969425917 CET443497203.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:40.969496012 CET49720443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:40.969842911 CET49720443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:40.969855070 CET443497203.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:42.265881062 CET49722443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:42.265933990 CET4434972213.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:42.266036987 CET49722443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:42.266650915 CET49722443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:42.266668081 CET4434972213.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:49.112385035 CET443497203.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:49.112577915 CET49720443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:49.112771988 CET49720443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:49.112787962 CET443497203.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:49.114234924 CET49724443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:49.114264011 CET443497243.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:49.114485025 CET49724443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:49.114742041 CET49724443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:49.114782095 CET443497243.39.153.44192.168.2.9
                          Mar 10, 2025 21:23:49.114938974 CET49724443192.168.2.93.39.153.44
                          Mar 10, 2025 21:23:50.532293081 CET4434972213.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:50.532367945 CET49722443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:50.539216042 CET49722443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:50.539235115 CET4434972213.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:50.540754080 CET49725443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:50.540802002 CET4434972513.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:50.540878057 CET49725443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:50.541390896 CET49725443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:50.541404009 CET4434972513.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:58.600708008 CET4434972513.107.246.60192.168.2.9
                          Mar 10, 2025 21:23:58.600774050 CET49725443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:58.601006985 CET49725443192.168.2.913.107.246.60
                          Mar 10, 2025 21:23:58.601023912 CET4434972513.107.246.60192.168.2.9
                          TimestampSource PortDest PortSource IPDest IP
                          Mar 10, 2025 21:23:32.680269957 CET5151053192.168.2.91.1.1.1
                          Mar 10, 2025 21:23:32.712053061 CET53515101.1.1.1192.168.2.9
                          Mar 10, 2025 21:23:42.225106001 CET6169053192.168.2.91.1.1.1
                          Mar 10, 2025 21:23:42.264611959 CET53616901.1.1.1192.168.2.9
                          Mar 10, 2025 21:24:02.430893898 CET6008653192.168.2.91.1.1.1
                          Mar 10, 2025 21:24:03.309047937 CET53600861.1.1.1192.168.2.9
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Mar 10, 2025 21:23:32.680269957 CET192.168.2.91.1.1.10x1962Standard query (0)link.saja.marketA (IP address)IN (0x0001)false
                          Mar 10, 2025 21:23:42.225106001 CET192.168.2.91.1.1.10x60bbStandard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                          Mar 10, 2025 21:24:02.430893898 CET192.168.2.91.1.1.10x8966Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Mar 10, 2025 21:22:40.057167053 CET1.1.1.1192.168.2.90xed02No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:22:40.057167053 CET1.1.1.1192.168.2.90xed02No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:22:40.057167053 CET1.1.1.1192.168.2.90xed02No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:22:42.740710020 CET1.1.1.1192.168.2.90xe1feNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:22:42.740710020 CET1.1.1.1192.168.2.90xe1feNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:23:32.712053061 CET1.1.1.1192.168.2.90x1962No error (0)link.saja.marketistio.saja.marketCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:32.712053061 CET1.1.1.1192.168.2.90x1962No error (0)istio.saja.marketservice-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:32.712053061 CET1.1.1.1192.168.2.90x1962No error (0)service-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.com3.39.153.44A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:23:32.712053061 CET1.1.1.1192.168.2.90x1962No error (0)service-eks-nlb-public-0b7cb0a32741e125.elb.ap-northeast-2.amazonaws.com3.39.89.152A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:23:42.264611959 CET1.1.1.1192.168.2.90x60bbNo error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:42.264611959 CET1.1.1.1192.168.2.90x60bbNo error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:42.264611959 CET1.1.1.1192.168.2.90x60bbNo error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:42.264611959 CET1.1.1.1192.168.2.90x60bbNo error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.nets-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:23:42.264611959 CET1.1.1.1192.168.2.90x60bbNo error (0)s-part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)azurefd-t-fb-prod.trafficmanager.netdual.s-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)dual.s-part-0044.t-0009.fb-t-msedge.nets-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Mar 10, 2025 21:24:03.309047937 CET1.1.1.1192.168.2.90x8966No error (0)s-part-0044.t-0009.fb-t-msedge.net13.107.253.72A (IP address)IN (0x0001)false

                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:16:22:33
                          Start date:10/03/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                          Imagebase:0x9a0000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:10
                          Start time:16:23:49
                          Start date:10/03/2025
                          Path:C:\Windows\splwow64.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\splwow64.exe 12288
                          Imagebase:0x7ff7e4f90000
                          File size:163'840 bytes
                          MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:14
                          Start time:16:24:07
                          Start date:10/03/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\840.xls"
                          Imagebase:0x9a0000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          No disassembly