Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Purchase Inquiry.xla.xlsx

Overview

General Information

Sample name:Purchase Inquiry.xla.xlsx
Analysis ID:1636038
MD5:0c37ce3722d5c40f455a85337c2755a0
SHA1:7d103a5ac1acc8b50a1a94330d012c42360ce9d2
SHA256:8a1fbda779334255e8bd64158f0fa7cb7e203921f8701e60f1c8ab7a8c2f1a54
Tags:xlsxuser-lowmal3
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Unable to load, office file is protected or invalid

Classification

  • System is w11x64_office
  • EXCEL.EXE (PID: 7768 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
    • splwow64.exe (PID: 5848 cmdline: C:\Windows\splwow64.exe 12288 MD5: AF4A7EBF6114EE9E6FBCC910EC3C96E6)
  • EXCEL.EXE (PID: 5096 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx" MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 5.161.200.29, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7768, Protocol: tcp, SourceIp: 192.168.2.25, SourceIsIpv6: false, SourcePort: 49756
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.25, DestinationIsIpv6: false, DestinationPort: 49756, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7768, Protocol: tcp, SourceIp: 5.161.200.29, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Purchase Inquiry.xla.xlsxVirustotal: Detection: 26%Perma Link
Source: Purchase Inquiry.xla.xlsxReversingLabs: Detection: 23%
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49763 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49762 version: TLS 1.2
Source: global trafficDNS query: name: st3.pro
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49756
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49756
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49756
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49756
Source: global trafficTCP traffic: 192.168.2.25:49756 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49757
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49757
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49757
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.25:49757
Source: global trafficTCP traffic: 192.168.2.25:49757 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49761 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49761
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49763 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49763
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 192.168.2.25:49762 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49762
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 192.168.2.25:49764 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49764
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.25:49765 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.25:49765
Source: Joe Sandbox ViewIP Address: 13.107.253.72 13.107.253.72
Source: Joe Sandbox ViewIP Address: 5.161.200.29 5.161.200.29
Source: Joe Sandbox ViewJA3 fingerprint: 258a5a1e95b8a911872bae9081526644
Source: Joe Sandbox ViewJA3 fingerprint: 091f51a7a1c3a4504a224cc081ce9cee
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /rules/officeclicktorun.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule170146v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120201v19s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v9s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: st3.pro
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: Primary1741772328918960900_EEC15AEF-746D-4BB8-A1A0-5C834676808A.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/flatfontassets.pkg
Source: Primary1741772328918960900_EEC15AEF-746D-4BB8-A1A0-5C834676808A.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/rawguids/37327920121
Source: Purchase Inquiry.xla.xlsx, 26840000.0.drString found in binary or memory: https://st3.pro/s6zpy2l?&anatomy=rustic&buffet=resonant&copyright=imaginary&snail
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49763 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.25:49762 version: TLS 1.2
Source: Purchase Inquiry.xla.xlsxOLE indicator, VBA macros: true
Source: Purchase Inquiry.xla.xlsxStream path 'MBD0028D785/\x1Ole' : https://st3.pro/s6zpy2l?&anatomy=rustic&buffet=resonant&copyright=imaginary&snailXB^[^AdSiloP~2[,EfDn&U~34r7.&ejF,cX+VZ4iTpc$PYm}sOo:0}$U@y5PjE]O@^4k^e78s"}iACnvH62aiRDgRKCZmd5pdCZhINJtaU2ymIE10hsK3moiY3MAh2mNziV1UptQCio7TcyMVaHXOUApAVNiyif6uKJ7rn86HgP81MHavNNOlVvGA01Xcm5tAAmgbsQ0xcj43sK8ukO4b5kyujxztqLZDQBYx62osq3aEooyWKz0z1lSGtWfofQS14peBqjwFRqI9NfsUSriKEOymXvFejIZ00k7btXVoO7yV3368a)h1JPX~NuO*a\
Source: 26840000.0.drStream path 'MBD0028D785/\x1Ole' : https://st3.pro/s6zpy2l?&anatomy=rustic&buffet=resonant&copyright=imaginary&snailXB^[^AdSiloP~2[,EfDn&U~34r7.&ejF,cX+VZ4iTpc$PYm}sOo:0}$U@y5PjE]O@^4k^e78s"}iACnvH62aiRDgRKCZmd5pdCZhINJtaU2ymIE10hsK3moiY3MAh2mNziV1UptQCio7TcyMVaHXOUApAVNiyif6uKJ7rn86HgP81MHavNNOlVvGA01Xcm5tAAmgbsQ0xcj43sK8ukO4b5kyujxztqLZDQBYx62osq3aEooyWKz0z1lSGtWfofQS14peBqjwFRqI9NfsUSriKEOymXvFejIZ00k7btXVoO7yV3368a)h1JPX~NuO*a\
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'purchase inquiry.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal48.winXLSX@4/13@2/2
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Purchase Inquiry.xla.xlsxJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{EEC15AEF-746D-4BB8-A1A0-5C834676808A} - OProcSessId.datJump to behavior
Source: Purchase Inquiry.xla.xlsxOLE indicator, Workbook stream: true
Source: 26840000.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: Purchase Inquiry.xla.xlsxVirustotal: Detection: 26%
Source: Purchase Inquiry.xla.xlsxReversingLabs: Detection: 23%
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx"
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: Purchase Inquiry.xla.xlsxStatic file information: File size 1528320 > 1048576
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: 26840000.0.drInitial sample: OLE indicators vbamacros = False
Source: Purchase Inquiry.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Purchase Inquiry.xla.xlsxStream path 'MBD0028D784/MBD0028CC1A/Workbook' entropy: 7.99807027604 (max. 8.0)
Source: Purchase Inquiry.xla.xlsxStream path 'Workbook' entropy: 7.99918830317 (max. 8.0)
Source: 26840000.0.drStream path 'MBD0028D784/MBD0028CC1A/Workbook' entropy: 7.99807027604 (max. 8.0)
Source: 26840000.0.drStream path 'Workbook' entropy: 7.99905190178 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 724Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts3
Exploitation for Client Execution
1
Scripting
1
Process Injection
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture3
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Purchase Inquiry.xla.xlsx27%VirustotalBrowse
Purchase Inquiry.xla.xlsx24%ReversingLabsDocument-Excel.Exploit.CVE-2017-0199
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://st3.pro/s6zpy2l?&anatomy=rustic&buffet=resonant&copyright=imaginary&snail0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
truefalse
    high
    st3.pro
    5.161.200.29
    truefalse
      high
      a726.dscd.akamai.net
      2.22.242.9
      truefalse
        high
        s-0005.dual-s-msedge.net
        52.123.129.14
        truefalse
          high
          otelrules.svc.static.microsoft
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://otelrules.svc.static.microsoft/rules/rule120603v9s19.xmlfalse
              high
              https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
                high
                https://otelrules.svc.static.microsoft/rules/rule170146v0s19.xmlfalse
                  high
                  https://otelrules.svc.static.microsoft/rules/officeclicktorun.exe-Production-v19.bundlefalse
                    high
                    https://otelrules.svc.static.microsoft/rules/rule120201v19s19.xmlfalse
                      high
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://st3.pro/s6zpy2l?&anatomy=rustic&buffet=resonant&copyright=imaginary&snailPurchase Inquiry.xla.xlsx, 26840000.0.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      13.107.253.72
                      s-part-0044.t-0009.fb-t-msedge.netUnited States
                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                      5.161.200.29
                      st3.proGermany
                      24940HETZNER-ASDEfalse
                      Joe Sandbox version:42.0.0 Malachite
                      Analysis ID:1636038
                      Start date and time:2025-03-12 10:37:44 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 5m 33s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:defaultwindowsofficecookbook.jbs
                      Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
                      Run name:Potential for more IOCs and behavior
                      Number of analysed new started processes analysed:19
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • GSI enabled (VBA)
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:Purchase Inquiry.xla.xlsx
                      Detection:MAL
                      Classification:mal48.winXLSX@4/13@2/2
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Found application associated with file extension: .xlsx
                      • Found Word or Excel or PowerPoint or XPS Viewer
                      • Attach to Office via COM
                      • Active ActiveX Object
                      • Active ActiveX Object
                      • Scroll down
                      • Close Viewer
                      • Exclude process from analysis (whitelisted): SecurityHealthHost.exe, dllhost.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 52.109.76.240, 52.109.89.19, 52.109.89.119, 20.189.173.8, 52.109.28.46, 20.42.73.30, 52.123.129.14, 40.126.32.136, 4.245.163.56, 2.22.242.9, 2.22.242.115, 2.22.242.105
                      • Excluded domains from analysis (whitelisted): odc.officeapps.live.com, slscr.update.microsoft.com, europe.odcsm1.live.com.akadns.net, weu-azsc-000.roaming.officeapps.live.com, res-1.cdn.office.net, eur.roaming1.live.com.akadns.net, mobile.events.data.microsoft.com, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, osiprod-weu-bronze-azsc-000.westeurope.cloudapp.azure.com, onedscolprdwus07.westus.cloudapp.azure.com, dual-s-0005-office.config.skype.com, login.live.com, officeclient.microsoft.com, assets.msn.com, ecs.office.com, client.wns.windows.com, browser.events.data.msn.cn, prod.configsvc1.live.com.akadns.net, uci.cdn.office.net, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, weu-azsc-000.odc.officeapps.live.com, res-stls-prod.edgesuite.net, fe3cr.delivery.mp.microsoft.com, neu-azsc-config.officeapps.live.com, res-prod.trafficmanager.net, config.officeapps.live.com, onedscolprdeus18.eastus.cloudapp.azure.com, ecs.office.trafficmanager.net, res.cdn.office.net
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtCreateKey calls found.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtQueryAttributesFile calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      • Report size getting too big, too many NtSetValueKey calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      TimeTypeDescription
                      05:39:50API Interceptor780x Sleep call for process: splwow64.exe modified
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      13.107.253.72Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                        Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                          Quote 09052022_1.xlsxGet hashmaliciousUnknownBrowse
                            https://surveymars.com/q/78graAmKoGet hashmaliciousUnknownBrowse
                              Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                  #U5f38#U5a5c#U6cec#U5ed7#U60d7#U603d#U60ea#U661e.xlsGet hashmaliciousUnknownBrowse
                                    Nouvelle_commande9353834.xlsGet hashmaliciousUnknownBrowse
                                      R.D. Bitzer Co. Inc.xlsmGet hashmaliciousUnknownBrowse
                                        221036299-043825-sanlccjavap0004-6531.xlsGet hashmaliciousUnknownBrowse
                                          5.161.200.29Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                              Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                    Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                      Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                        COTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                                                          Nouvelle_commande9353834.xlsGet hashmaliciousUnknownBrowse
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            a726.dscd.akamai.netPurchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 2.22.242.113
                                                            Fiyat teklifi.docxGet hashmaliciousUnknownBrowse
                                                            • 2.16.164.65
                                                            PO 0059.docxGet hashmaliciousUnknownBrowse
                                                            • 2.19.11.98
                                                            expense-report.xlsxGet hashmaliciousUnknownBrowse
                                                            • 2.22.242.98
                                                            NEW__Review_202551087.svgGet hashmaliciousHTMLPhisherBrowse
                                                            • 2.22.242.88
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 2.22.242.113
                                                            Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                                                            • 2.22.242.99
                                                            20250304_150220_TA6NsGnFKBQP6WuMJfIAtA3XK3ok9HgQ.emlGet hashmaliciousUnknownBrowse
                                                            • 2.19.11.111
                                                            Non-Disclosure Agreement Contract.docxGet hashmaliciousUnknownBrowse
                                                            • 2.19.11.111
                                                            Non-Disclosure Agreement Contract.docxGet hashmaliciousUnknownBrowse
                                                            • 2.19.11.111
                                                            s-0005.dual-s-msedge.netInvoice#3121408663.emlGet hashmaliciousUnknownBrowse
                                                            • 52.123.129.14
                                                            Fiyat teklifi.docxGet hashmaliciousUnknownBrowse
                                                            • 52.123.129.14
                                                            Fiyat teklifi.docxGet hashmaliciousUnknownBrowse
                                                            • 52.123.129.14
                                                            PO 0059.docxGet hashmaliciousUnknownBrowse
                                                            • 52.123.128.14
                                                            PO 0059.docxGet hashmaliciousUnknownBrowse
                                                            • 52.123.128.14
                                                            phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                            • 52.123.128.14
                                                            phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                            • 52.123.129.14
                                                            Brian Logie shared _Newfield Construction, Inc Shared a secured Documents_ with you.emlGet hashmaliciousUnknownBrowse
                                                            • 52.123.129.14
                                                            expense-report.xlsxGet hashmaliciousUnknownBrowse
                                                            • 52.123.128.14
                                                            expense-report.xlsxGet hashmaliciousKnowBe4Browse
                                                            • 52.123.129.14
                                                            s-part-0044.t-0009.fb-t-msedge.netInv#8653763981_2sfgPaymentAdvice.svgGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.253.72
                                                            Remittance Advice.htmGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.253.72
                                                            Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Quote 09052022_1.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Denise Salvano shared _Kerry Ingredients Flooring Standards_ with you.emlGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            o1.svgGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.253.72
                                                            https://surveymars.com/q/78graAmKoGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            st3.proPurchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            COTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            COTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            HETZNER-ASDEPurchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 5.161.200.29
                                                            Transferencia 6997900002017937.exeGet hashmaliciousFormBookBrowse
                                                            • 144.76.229.203
                                                            Quotation.exeGet hashmaliciousFormBookBrowse
                                                            • 144.76.229.203
                                                            resgod.arm.elfGet hashmaliciousMiraiBrowse
                                                            • 46.4.110.17
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 88.198.246.242
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 88.198.246.242
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 88.198.246.242
                                                            SecuriteInfo.com.Variant.Genie.8DN.315.18074.27911.exeGet hashmaliciousFormBookBrowse
                                                            • 144.76.229.203
                                                            MICROSOFT-CORP-MSN-AS-BLOCKUSPurchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.246.40
                                                            PURCHASE-ORDER-SINCOAUTOMATION-PO3223090781-Ref 6421SINCO-AUTOMATION.exeGet hashmaliciousFormBookBrowse
                                                            • 204.79.197.203
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.246.76
                                                            resgod.mpsl.elfGet hashmaliciousMiraiBrowse
                                                            • 20.62.103.71
                                                            https://mail.kb4.io/XVUFBTUdUVGF0Q2J1L0tCNTE2U2RMZGVqSDkyR244RFhYSFNPTFU0N3FJRHZ1Vmw5OVdITjQ0aFgvUENQQVF6Y0VWOHhnTnRKM3VHUktPL21ZZHdtcWRaV3EwYWhKd3hVOCtibzFaN2phbkVVQzMxY2xma3h3K2NKb3pWUnEyUXVDWWNsNmtxV0dKVWZjOExIcUFlNnlXUkpvcDlzTlBhNzNCaHNvRzBwZlF0M21CQmJhR2hVUEprN2JmeWtkNThkMVRMbVN3dGx4NWViNUZMejUxaVVjWlhCaWxuT1pBPT0tLVpQV0ZwSVl5K0dCSlpNNVctLWQ3aGk1dFRjMXBtUDJRQ09QakI3M1E9PQ==?cid=2440816513Get hashmaliciousKnowBe4Browse
                                                            • 13.107.246.60
                                                            https://inv18993383.cloudfaxservice.de/MSovS?e=amatuer_script_kiddys@pwned.comGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.246.60
                                                            TEDGRQXB.exeGet hashmaliciousVidarBrowse
                                                            • 204.79.197.203
                                                            pCFcu1ilGhGet hashmaliciousUnknownBrowse
                                                            • 40.69.147.202
                                                            phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                            • 13.89.179.8
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            258a5a1e95b8a911872bae9081526644Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            expense-report.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Quote 09052022_1.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            #U5f38#U5a5c#U6cec#U5ed7#U60d7#U603d#U60ea#U661e.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            .xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            COTA#U00c7#U00c3O.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            840.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            091f51a7a1c3a4504a224cc081ce9ceeRef PO24777.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            https://kwikkopyegypt.com/wp-admin/mail.verify/interface.root/login.php/inbox.html#jake.totam@southwark.anglican.orgGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.253.72
                                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            Purchase Order.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            VALPESA7809034mex_2025.xlsGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            AccountFactuur8472.xlsmGet hashmaliciousKnowBe4Browse
                                                            • 13.107.253.72
                                                            https://sites.google.com/view/wzxoiedued/homeGet hashmaliciousHTMLPhisherBrowse
                                                            • 13.107.253.72
                                                            transferencia HSBC.xla.xlsxGet hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            https://aircarecolorado.com/index.php?tab=jl_magic_tabs_m_th_current_week_gix1Get hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            https://aircarecolorado.com/Get hashmaliciousUnknownBrowse
                                                            • 13.107.253.72
                                                            No context
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):118
                                                            Entropy (8bit):3.5700810731231707
                                                            Encrypted:false
                                                            SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                                                            MD5:573220372DA4ED487441611079B623CD
                                                            SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                                                            SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                                                            SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                                                            Malicious:false
                                                            Reputation:high, very likely benign file
                                                            Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):20971520
                                                            Entropy (8bit):8.112143835430977E-5
                                                            Encrypted:false
                                                            SSDEEP:3:Tuekk9NJtHFfs1XsExe/t:qeVJ8
                                                            MD5:AFDEAC461EEC32D754D8E6017E845D21
                                                            SHA1:5D0874C19B70638A0737696AEEE55BFCC80D7ED8
                                                            SHA-256:3A96B02F6A09F6A6FAC2A44A5842FF9AEB17EB4D633E48ABF6ADDF6FB447C7E2
                                                            SHA-512:CAB6B8F9FFDBD80210F42219BAC8F1124D6C0B6995C5128995F7F48CED8EF0F2159EA06A2CD09B1FDCD409719F94A7DB437C708D3B1FDA01FDC80141A4595FC7
                                                            Malicious:false
                                                            Reputation:moderate, very likely benign file
                                                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):20971520
                                                            Entropy (8bit):0.0
                                                            Encrypted:false
                                                            SSDEEP:3::
                                                            MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                            SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                            SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                            SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                            Malicious:false
                                                            Reputation:high, very likely benign file
                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:ASCII text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):71
                                                            Entropy (8bit):4.3462513114457515
                                                            Encrypted:false
                                                            SSDEEP:3:Tuekk9NJtHFfs1XsExen:qeVJ8u
                                                            MD5:8F4510F128F81A8BAF2A345D00F7E30C
                                                            SHA1:8C711E6C484881ECDC83B6BDAC41C7A19EDE9C37
                                                            SHA-256:15AA8B35FC5F139EF0B0FBC641CAA862AED19674625B81D1DC63467BC0AAFED9
                                                            SHA-512:78695E5E2337703757903B8452E31A98F860022B04972651212C3004FEBE29017380A8BCA9FCCFD935DE00D8BD73AA556C30A3CEA5FC76E7ADF7E7763D68E78F
                                                            Malicious:false
                                                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:ASCII text, with very long lines (28774), with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):20971520
                                                            Entropy (8bit):0.2159635623589193
                                                            Encrypted:false
                                                            SSDEEP:1536:Q72tM46YK/q44ARYzWyB+SRHOj0yoYZwHBclgIzanTiniNiImdXNHkge2shUEGTo:oeMZjnYzX+uHAucij+/ppanPBlhAi+P
                                                            MD5:6A804D3BB6A8EC69B8720F41BC9F0DFE
                                                            SHA1:3013346E6BFAC8B557BC3D4ED4804A42971CD966
                                                            SHA-256:E14A9FFD5906A920840F7D16B629EF7403F81B74C2B83050B68CA430F18A2FF4
                                                            SHA-512:A40D13B9111906DCCF07A2D4EF41806D3E338078C8E521EC04788CBAE4E2375E3B74E45B25201B7F3694341D4BFD506B6A2624B518CC7A39A0EEB1E20B11457A
                                                            Malicious:false
                                                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..03/12/2025 09:38:48.943.EXCEL (0x1E58).0x1EB4.Microsoft Excel.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Experimentation.FeatureQueryBatched","Flags":33777005812056321,"InternalSequenceNumber":17,"Time":"2025-03-12T09:38:48.943Z","Data.Sequence":0,"Data.Count":128,"Data.Features":"[ { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.TrackCPSWrites\", \"V\" : false, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:38:48.6931675Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.CPSMaxWrites\", \"V\" : 2, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:38:48.6931675Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Word.UAEOnSafeModeEnabled\", \"V\" : true, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:38:48.6931675Z\", \"C\" : \"\", \"Q\" : 7.0, \"M\" : 0, \"F\" : 5, \"G\" : \"Opt\" }, { \"ID\" : 1, \"
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):20971520
                                                            Entropy (8bit):0.0
                                                            Encrypted:false
                                                            SSDEEP:3::
                                                            MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                            SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                            SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                            SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                            Malicious:false
                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:ASCII text, with very long lines (28783), with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):256585
                                                            Entropy (8bit):5.137079185905358
                                                            Encrypted:false
                                                            SSDEEP:1536:Df0ql9yoXYzyRQhB7z2Lg/LVLCjjrmb/TwXGKEQEa19gstMQpETNnlWKBujycOpz:L5l1RQbKLgjAI2anPBlhGw3YI
                                                            MD5:C68DFE22B7B7B27CB9B0633D6BB13AC5
                                                            SHA1:B5C852A2B8A7F09B0A2065A6A6FBBE87957ECD8A
                                                            SHA-256:95BF9A08F21AF036BDDDFDCCF0997893405106E328382BA3AE4EB831D871C03F
                                                            SHA-512:B90335636B8718E26A13A80C76655B2DC509F1F6399A75A093AAEAE3EDCE6FF91028D7A2903D4BBDA725D43C484C488454BEBC88FEC227008CC5478E7D44B966
                                                            Malicious:false
                                                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..03/12/2025 09:40:09.822.EXCEL (0x13E8).0x708.Microsoft Excel.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Experimentation.FeatureQueryBatched","Flags":33777005812056321,"InternalSequenceNumber":17,"Time":"2025-03-12T09:40:09.822Z","Data.Sequence":0,"Data.Count":128,"Data.Features":"[ { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.TrackCPSWrites\", \"V\" : false, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:40:09.5568694Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.CPSMaxWrites\", \"V\" : 2, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:40:09.5568694Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Word.UAEOnSafeModeEnabled\", \"V\" : true, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-03-12T09:40:09.5568694Z\", \"C\" : \"\", \"Q\" : 8.0, \"M\" : 0, \"F\" : 5, \"G\" : \"Opt\" }, { \"ID\" : 1, \"N
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):339968
                                                            Entropy (8bit):7.538491807624486
                                                            Encrypted:false
                                                            SSDEEP:6144:Lk3hbdlylKsgwyzcTbWhZFVE+WaxHAknDiULPQF4AxrnyiaznE4FktxU21VJrVbR:0Wa4uAxryiCnBOtxU21VJrVtdnZpzN
                                                            MD5:E5154D52872CFDB4A62200708ED8982B
                                                            SHA1:428C0740E2BBC8F7445959C168822BB6323FA7C2
                                                            SHA-256:05543E393992924925BF3255711E08147AC8CB229CDD2C861C936B4AC10D2987
                                                            SHA-512:2AD1E865078045CBCC8AC950C22F70ADDEF6BE12DB19DEB97C13FF7269CD3B721BB86753D9BE20EB0952B7FC241E6D14132DF8B9A1DD8F63CC862340D2DEDF46
                                                            Malicious:false
                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):512
                                                            Entropy (8bit):0.0
                                                            Encrypted:false
                                                            SSDEEP:3::
                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                            Malicious:false
                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 09:40:06 2025, Security: 1
                                                            Category:dropped
                                                            Size (bytes):1439232
                                                            Entropy (8bit):7.9608896384879655
                                                            Encrypted:false
                                                            SSDEEP:24576:641dNCBYVJZ/LwLvFew8vatCtU4cJxRpcVnP/NICq0UgI3PZJSvMPbiEDiQTe5Rr:fdNKeJxLwLvFe92MYjRmVP/NtPI/ZMkN
                                                            MD5:AD558962E0C48331AE9F5F7CD19B26A9
                                                            SHA1:436DB45BBD2890D94EA646E53EB3E68ABABD37DA
                                                            SHA-256:444630B41AABE27AB3D9A9254A8817317ADDC7D35C87D4AF9985E54E8BAC20BF
                                                            SHA-512:F0E1D19F9C84B1A960B07249BB964D5B4FC569F260318808B3E120FBDBE39EACDF103ECC86772D41589228FC61E77252DACE6D8FB4C62E5731BC3DEDD988E556
                                                            Malicious:false
                                                            Preview:......................>.......................................................................r...s...t...u...v...w...x...y...z...{...|.......l.......n.......p.......................................................................................................................................................................................................................................................................................................................................................................q................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:ASCII text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):26
                                                            Entropy (8bit):3.95006375643621
                                                            Encrypted:false
                                                            SSDEEP:3:ggPYV:rPYV
                                                            MD5:187F488E27DB4AF347237FE461A079AD
                                                            SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                                            SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                                            SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                                            Malicious:false
                                                            Preview:[ZoneTransfer]....ZoneId=0
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 09:40:06 2025, Security: 1
                                                            Category:dropped
                                                            Size (bytes):1439232
                                                            Entropy (8bit):7.9608896384879655
                                                            Encrypted:false
                                                            SSDEEP:24576:641dNCBYVJZ/LwLvFew8vatCtU4cJxRpcVnP/NICq0UgI3PZJSvMPbiEDiQTe5Rr:fdNKeJxLwLvFe92MYjRmVP/NtPI/ZMkN
                                                            MD5:AD558962E0C48331AE9F5F7CD19B26A9
                                                            SHA1:436DB45BBD2890D94EA646E53EB3E68ABABD37DA
                                                            SHA-256:444630B41AABE27AB3D9A9254A8817317ADDC7D35C87D4AF9985E54E8BAC20BF
                                                            SHA-512:F0E1D19F9C84B1A960B07249BB964D5B4FC569F260318808B3E120FBDBE39EACDF103ECC86772D41589228FC61E77252DACE6D8FB4C62E5731BC3DEDD988E556
                                                            Malicious:false
                                                            Preview:......................>.......................................................................r...s...t...u...v...w...x...y...z...{...|.......l.......n.......p.......................................................................................................................................................................................................................................................................................................................................................................q................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                                                            Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            File Type:data
                                                            Category:dropped
                                                            Size (bytes):165
                                                            Entropy (8bit):1.4377382811115937
                                                            Encrypted:false
                                                            SSDEEP:3:EVANFN:EqfN
                                                            MD5:359140EB88A757E2BBEF2F7D32DCC4E5
                                                            SHA1:FD16035441ADF907BBFC594A96470C202E265067
                                                            SHA-256:42CDE461F058A0C6F6C5A69BD1D21114CD55929011C77BCB9A025B9CA43ED71F
                                                            SHA-512:9ADF6AC24E55AA161D2FFA1AC3BBBF03A7028DEFD8E1722FA52CAF7C730F7CF8AAE2073A50FD8AA004AF46E9A578A3B8088DD89415368E64E1916367CE126741
                                                            Malicious:true
                                                            Preview:.user ..M.e.r.c.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                            File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 03:48:39 2025, Security: 1
                                                            Entropy (8bit):7.9274991132918435
                                                            TrID:
                                                            • Microsoft Excel sheet (30009/1) 47.99%
                                                            • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                                                            • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                                                            File name:Purchase Inquiry.xla.xlsx
                                                            File size:1'528'320 bytes
                                                            MD5:0c37ce3722d5c40f455a85337c2755a0
                                                            SHA1:7d103a5ac1acc8b50a1a94330d012c42360ce9d2
                                                            SHA256:8a1fbda779334255e8bd64158f0fa7cb7e203921f8701e60f1c8ab7a8c2f1a54
                                                            SHA512:8f8bdcf910eec2a44fb8f5569218f2a5695be62320ed8ae76f1aeb91baed678602fbce52a0873250a607dd303d9fb991cab364a88abde4732c8b920bdee3d711
                                                            SSDEEP:24576:n41dNCBYVJZ/qwLvFew8vatCtU4cJxRpcVnP/NICq0UgI3PZJSvMPbiXQ0SMrD11:QdNKeJxqwLvFe92MYjRmVP/NtPI/ZMka
                                                            TLSH:D0652305FB168B12D41A13384DE78AA41736FC80ABB24B0B739CF3493E72EB45A57765
                                                            File Content Preview:........................>.......................................................................l...m...n...o...p...q...r...s...t...u...v.......o.......q.......s.......u......................................................................................
                                                            Icon Hash:35e58a8c0c8a85b9
                                                            Document Type:OLE
                                                            Number of OLE Files:1
                                                            Has Summary Info:
                                                            Application Name:Microsoft Excel
                                                            Encrypted Document:True
                                                            Contains Word Document Stream:False
                                                            Contains Workbook/Book Stream:True
                                                            Contains PowerPoint Document Stream:False
                                                            Contains Visio Document Stream:False
                                                            Contains ObjectPool Stream:False
                                                            Flash Objects Count:0
                                                            Contains VBA Macros:True
                                                            Code Page:1252
                                                            Author:
                                                            Last Saved By:
                                                            Create Time:2006-09-16 00:00:00
                                                            Last Saved Time:2025-03-12 03:48:39
                                                            Creating Application:Microsoft Excel
                                                            Security:1
                                                            Document Code Page:1252
                                                            Thumbnail Scaling Desired:False
                                                            Contains Dirty Links:False
                                                            Shared Document:False
                                                            Changed Hyperlinks:False
                                                            Application Version:786432
                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                                                            VBA File Name:Sheet1.cls
                                                            Stream Size:977
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0
                                                            Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 1e a4 81 ad 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                            Attribute VB_Name = "Sheet1"
                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                            Attribute VB_GlobalNameSpace = False
                                                            Attribute VB_Creatable = False
                                                            Attribute VB_PredeclaredId = True
                                                            Attribute VB_Exposed = True
                                                            Attribute VB_TemplateDerived = False
                                                            Attribute VB_Customizable = True
                                                            

                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                                                            VBA File Name:Sheet2.cls
                                                            Stream Size:977
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                                                            Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 1e a4 35 ea 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                            Attribute VB_Name = "Sheet2"
                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                            Attribute VB_GlobalNameSpace = False
                                                            Attribute VB_Creatable = False
                                                            Attribute VB_PredeclaredId = True
                                                            Attribute VB_Exposed = True
                                                            Attribute VB_TemplateDerived = False
                                                            Attribute VB_Customizable = True
                                                            

                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                                                            VBA File Name:Sheet3.cls
                                                            Stream Size:977
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                                                            Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 1e a4 46 90 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                            Attribute VB_Name = "Sheet3"
                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                            Attribute VB_GlobalNameSpace = False
                                                            Attribute VB_Creatable = False
                                                            Attribute VB_PredeclaredId = True
                                                            Attribute VB_Exposed = True
                                                            Attribute VB_TemplateDerived = False
                                                            Attribute VB_Customizable = True
                                                            

                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                                                            VBA File Name:ThisWorkbook.cls
                                                            Stream Size:985
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                                                            Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 1e a4 a4 4e 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                            Attribute VB_Name = "ThisWorkbook"
                                                            Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                                            Attribute VB_GlobalNameSpace = False
                                                            Attribute VB_Creatable = False
                                                            Attribute VB_PredeclaredId = True
                                                            Attribute VB_Exposed = True
                                                            Attribute VB_TemplateDerived = False
                                                            Attribute VB_Customizable = True
                                                            

                                                            General
                                                            Stream Path:\x1CompObj
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:114
                                                            Entropy:4.25248375192737
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                                            Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                            General
                                                            Stream Path:\x5DocumentSummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:244
                                                            Entropy:2.889430592781307
                                                            Base64 Encoded:False
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                                                            General
                                                            Stream Path:\x5SummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:200
                                                            Entropy:3.282567433052416
                                                            Base64 Encoded:False
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . . . . . . . . . . .
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/\x1CompObj
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:114
                                                            Entropy:4.25248375192737
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                                            Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/\x5DocumentSummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:472
                                                            Entropy:4.0922508126371575
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , 4 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D Y E I N G O R D E R . . . . . ' D Y E I N G O R D E R ' ! P r i n t _ A r e a . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . .
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 34 01 00 00 f0 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/\x5SummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:21284
                                                            Entropy:3.0976303650699557
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . R . . . . . . . . . . P . . . . . . . X . . . . . . . h . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . n a h i d . . . . . . . . . . . 9 1 9 7 4 . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . % . @ . . . . F * . 6 . @ . . . . , . . . . . . . . . . G . . . . R . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . . & . . . " W M F C
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 f4 52 00 00 09 00 00 00 01 00 00 00 50 00 00 00 04 00 00 00 58 00 00 00 08 00 00 00 68 00 00 00 12 00 00 00 78 00 00 00 0b 00 00 00 90 00 00 00 0c 00 00 00 9c 00 00 00 0d 00 00 00 a8 00 00 00 13 00 00 00 b4 00 00 00 11 00 00 00 bc 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/MBD0028CC1A/\x1CompObj
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:114
                                                            Entropy:4.25248375192737
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                                            Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/MBD0028CC1A/\x5DocumentSummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:356
                                                            Entropy:3.4189844832102483
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , . . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P r o f o r m a . . . . . H o j a 2 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . . d . . . . . . . . . . . . . . . . .
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 00 01 00 00 bc 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/MBD0028CC1A/\x5SummaryInformation
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:216
                                                            Entropy:3.560552135359314
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . d . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1 9 7 4 . . . . . . . . . . . M i c r o s o f t M a c i n t o s h E x c e l . . . @ . . . . | . # . @ . . . . d . . . . . . . . . . .
                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a8 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 64 00 00 00 0c 00 00 00 88 00 00 00 0d 00 00 00 94 00 00 00 13 00 00 00 a0 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                                                            General
                                                            Stream Path:MBD0028D784/MBD0028CC1A/Workbook
                                                            CLSID:
                                                            File Type:Applesoft BASIC program data, first line number 16
                                                            Stream Size:691891
                                                            Entropy:7.998070276042251
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . . . P . ! D M A . : & . L x . T e 8 o F h v r 3 . . . . . . . . . . . . \\ . p . w \\ n . 6 i " ? @ . . . 3 D k & . S j < 1 1 . . 3 Q . . c d . H O P \\ ; o . ' > . e T B ; . . . j . A U . e . . I , . 3 . f 3 . B . . . . = a . . . ! . . . = . . . I . . . . a " @ L 6 . . . 8 S . . . G / . _ . . u . . . . d . . . . . ; . . . . ? . . . . p . . . C = . . . H E . . 3 0 . . . @ . . . o . . . . . " . . . 3 Y . . . . / . . . . . . . 1 . . . . M 8 . . - . . g , )
                                                            Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 a7 02 c3 1f d1 50 03 21 44 84 4d 41 ca de b1 d4 e1 3a 85 9f 26 ea e3 aa db e6 0d 4c 9b 78 ab 19 54 a7 65 d5 38 d1 6f 46 68 d1 76 f8 72 33 0e ac e1 00 02 00 b0 04 c1 00 02 00 ef 1c e2 00 00 00 5c 00 70 00 93 77 bf 5c f7 6e 1c e5 36 69 22 3f 40 9b a0 2e cb a5 02 86 b7 bf 33 8c b1 c7 44 d5 6b e3
                                                            General
                                                            Stream Path:MBD0028D784/Workbook
                                                            CLSID:
                                                            File Type:Applesoft BASIC program data, first line number 16
                                                            Stream Size:311865
                                                            Entropy:7.82451108578391
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . Z % 8 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . .
                                                            Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                            General
                                                            Stream Path:MBD0028D785/\x1Ole
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:954
                                                            Entropy:5.468470102348802
                                                            Base64 Encoded:False
                                                            Data ASCII:. . . . ` U . . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . t . 3 . . . p . r . o . / . s . 6 . z . p . y . 2 . l . ? . & . a . n . a . t . o . m . y . = . r . u . s . t . i . c . & . b . u . f . f . e . t . = . r . e . s . o . n . a . n . t . & . c . o . p . y . r . i . g . h . t . = . i . m . a . g . i . n . a . r . y . & . s . n . a . i . l . . . . X B . . ^ [ . . ^ . A d S i l o P ~ . . 2 [ , E f D n . U ~ 3 4 . . r 7 . & . . . . . e j F . , . c X + . . . V Z 4
                                                            Data Raw:01 00 00 02 df 60 e4 55 e4 87 0c 20 00 00 00 00 00 00 00 00 00 00 00 00 90 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b 8c 01 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 74 00 33 00 2e 00 70 00 72 00 6f 00 2f 00 73 00 36 00 7a 00 70 00 79 00 32 00 6c 00 3f 00 26 00 61 00 6e 00 61 00 74 00 6f 00 6d 00 79 00 3d 00 72 00 75 00 73 00 74 00 69 00 63 00 26 00
                                                            General
                                                            Stream Path:Workbook
                                                            CLSID:
                                                            File Type:Applesoft BASIC program data, first line number 16
                                                            Stream Size:473269
                                                            Entropy:7.999188303168195
                                                            Base64 Encoded:True
                                                            Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . x " D H g ] / . O = v ' \\ 6 8 . . T . . . . ] . . . . . . . . . . d . . . \\ . p . l r ~ . ( . Q . . - n . e . Q 8 . l ] D Z k q . . . q 5 7 K b . . D . a y . > h . ~ . . n b ~ Y ? . * w = ; . G ! x B . . . = a . . . 5 < . . . = . . . y R } [ . . . } - @ . F ~ . . . . p . . . . ( . . . . . . . . . . . . . . . . * = . . . n 6 . z # O w @ . . . > u . . . 5 " . . . & . . . . . H . . . . . . . L 1 . . . i . . . [ . . O 8 . > f $ H I 1 . . . ) V p 5 D - g 9
                                                            Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 78 e0 22 44 bc 48 a1 67 5d 2f f8 8d 1d cf 4f e1 b5 3d 76 27 d3 5c a4 cb 36 38 bb be d6 be a5 cc 0b 54 c3 f0 1e 9c 0d db b6 a8 8e 95 eb 81 a8 5d 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 a2 64 e2 00 00 00 5c 00 70 00 6c 72 7e 04 28 0f 51 04 8d df 9b 9f 2d 98 b9 6e 83 0b 65 b1 88 88 7f d6 51 38
                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                            CLSID:
                                                            File Type:ASCII text, with CRLF line terminators
                                                            Stream Size:525
                                                            Entropy:5.238808297908672
                                                            Base64 Encoded:True
                                                            Data ASCII:I D = " { 0 8 D 7 4 1 3 3 - B F 9 D - 4 3 B 3 - 8 A 5 0 - 7 5 D F 4 4 9 E 8 D 0 D } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 0 C 0 E E 9 9 7 2 9 F F 2 D F F 2
                                                            Data Raw:49 44 3d 22 7b 30 38 44 37 34 31 33 33 2d 42 46 39 44 2d 34 33 42 33 2d 38 41 35 30 2d 37 35 44 46 34 34 39 45 38 44 30 44 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:104
                                                            Entropy:3.0488640812019017
                                                            Base64 Encoded:False
                                                            Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                                                            Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:2644
                                                            Entropy:3.9950099557456626
                                                            Base64 Encoded:False
                                                            Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                                                            Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                                                            General
                                                            Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                            CLSID:
                                                            File Type:data
                                                            Stream Size:553
                                                            Entropy:6.36714007967557
                                                            Base64 Encoded:True
                                                            Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E
                                                            Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 de 91 e8 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Mar 12, 2025 10:39:40.484508991 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:40.484563112 CET443497565.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:40.484666109 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:40.485672951 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:40.485692978 CET443497565.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:43.767848015 CET443497565.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:43.767927885 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768162012 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768281937 CET443497565.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:43.768336058 CET49756443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768563032 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768608093 CET443497575.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:43.768681049 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768924952 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:43.768935919 CET443497575.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:47.003757954 CET443497575.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:47.003906965 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:47.004204035 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:47.004353046 CET443497575.161.200.29192.168.2.25
                                                            Mar 12, 2025 10:39:47.004446983 CET49757443192.168.2.255.161.200.29
                                                            Mar 12, 2025 10:39:53.539551973 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:53.539589882 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:53.539658070 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:53.540441990 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:53.540457010 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:55.749957085 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:55.750063896 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:55.811084986 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:55.811117887 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:55.811475039 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:55.843189955 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:55.884330988 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396614075 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396639109 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396680117 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396697044 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396708965 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.396740913 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.396758080 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.396758080 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.396784067 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.456978083 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.457006931 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.457063913 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.457094908 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.457165956 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.457165956 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.498140097 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.498172998 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.498229027 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.498251915 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.498270035 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.498501062 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.543490887 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.543529987 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.543576956 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.543595076 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.543627977 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.543648005 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.560897112 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.560920000 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.560972929 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.561009884 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.561027050 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.561181068 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.582837105 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.582865000 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.582927942 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.582937956 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.582982063 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.600533009 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.600604057 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.600608110 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.600644112 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.600719929 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.600720882 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.601257086 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.601274014 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.601378918 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.601391077 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.603230000 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.603271961 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.603313923 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.603341103 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.603359938 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.603382111 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.619153976 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.619183064 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.619226933 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.619251013 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.619266033 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.619330883 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.637389898 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.637415886 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.637480974 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.637507915 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.637550116 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.651525974 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.651556969 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.651597023 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.651608944 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.651624918 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.651647091 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.664172888 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.664196968 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.664241076 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.664247990 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.664287090 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.664297104 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.676135063 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.676160097 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.676229954 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.676237106 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.676335096 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.685384035 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.685409069 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.685463905 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.685470104 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.685524940 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.695565939 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.695589066 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.695663929 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.695669889 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.695709944 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.703741074 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.703764915 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.703829050 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.703835964 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.703876019 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.712737083 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.712759972 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.712810040 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.712820053 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.712851048 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.712877989 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.724315882 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.724340916 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.724404097 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.724414110 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.724455118 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.738358974 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.738380909 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.738447905 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.738456011 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.738492012 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.749097109 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.749120951 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.749180079 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.749187946 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.749253988 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.761086941 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.761109114 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.761167049 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.761174917 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.761219025 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.770359039 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.770375967 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.770423889 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.770430088 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.770471096 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.780827045 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.780844927 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.780901909 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.780911922 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.780961990 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790572882 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.790621042 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.790642023 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790648937 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.790659904 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.790687084 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790703058 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790813923 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790831089 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.790841103 CET49761443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.790847063 CET4434976113.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.941087961 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.941143990 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.941222906 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.941451073 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.941463947 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.942692995 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.942737103 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:56.942807913 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.942935944 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:56.942954063 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.684469938 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.684550047 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.686810970 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.686834097 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.687160969 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.695576906 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.737867117 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.737931967 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.739763021 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.739773989 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.740087986 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.740322113 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:58.741189957 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:58.784329891 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.076555967 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.077094078 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.077126980 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.079046011 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.079068899 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.112027884 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.112628937 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.112664938 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.113421917 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.113426924 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.226862907 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.226943970 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.227363110 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.227411985 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.227411985 CET49763443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.227433920 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.227442980 CET4434976313.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.241395950 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.241417885 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.241477013 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.241489887 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.241525888 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.241986036 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.242008924 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.242024899 CET49762443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.242031097 CET4434976213.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.576579094 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.576605082 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.576661110 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.576680899 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.576817036 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.577255011 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.577299118 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.577418089 CET49764443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.577435970 CET4434976413.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.637429953 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.637509108 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.637975931 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.638021946 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.638021946 CET49765443192.168.2.2513.107.253.72
                                                            Mar 12, 2025 10:39:59.638044119 CET4434976513.107.253.72192.168.2.25
                                                            Mar 12, 2025 10:39:59.638055086 CET4434976513.107.253.72192.168.2.25
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Mar 12, 2025 10:39:40.470310926 CET5040253192.168.2.251.1.1.1
                                                            Mar 12, 2025 10:39:40.482887030 CET53504021.1.1.1192.168.2.25
                                                            Mar 12, 2025 10:39:53.531641960 CET5040253192.168.2.251.1.1.1
                                                            Mar 12, 2025 10:39:53.538341045 CET53504021.1.1.1192.168.2.25
                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                            Mar 12, 2025 10:39:40.470310926 CET192.168.2.251.1.1.10x339dStandard query (0)st3.proA (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.531641960 CET192.168.2.251.1.1.10xa0a6Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                            Mar 12, 2025 10:38:54.285440922 CET1.1.1.1192.168.2.250x31f0No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:38:54.285440922 CET1.1.1.1192.168.2.250x31f0No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:38:54.285440922 CET1.1.1.1192.168.2.250x31f0No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:40.482887030 CET1.1.1.1192.168.2.250x339dNo error (0)st3.pro5.161.200.29A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)res-stls-prod.edgesuite.net.globalredir.akadns88.neta726.dscd.akamai.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.9A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.88A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.224A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.80A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.225A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.226A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.91A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.81A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.463681936 CET1.1.1.1192.168.2.250xaff8No error (0)a726.dscd.akamai.net2.22.242.83A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)azurefd-t-fb-prod.trafficmanager.netdual.s-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)dual.s-part-0044.t-0009.fb-t-msedge.nets-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:39:53.538341045 CET1.1.1.1192.168.2.250xa0a6No error (0)s-part-0044.t-0009.fb-t-msedge.net13.107.253.72A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)res-stls-prod.edgesuite.net.globalredir.akadns88.neta726.dscd.akamai.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.115A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.120A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.123A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.128A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.121A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.113A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.112A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.104A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:09.827518940 CET1.1.1.1192.168.2.250x34edNo error (0)a726.dscd.akamai.net2.22.242.99A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)res-stls-prod.edgesuite.net.globalredir.akadns88.neta726.dscd.akamai.netCNAME (Canonical name)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.105A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.89A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.113A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.98A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.123A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.104A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.97A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.96A (IP address)IN (0x0001)false
                                                            Mar 12, 2025 10:40:17.359143019 CET1.1.1.1192.168.2.250xfd7fNo error (0)a726.dscd.akamai.net2.22.242.131A (IP address)IN (0x0001)false
                                                            • otelrules.svc.static.microsoft
                                                            Session IDSource IPSource PortDestination IPDestination Port
                                                            0192.168.2.254976113.107.253.72443
                                                            TimestampBytes transferredDirectionData
                                                            2025-03-12 09:39:55 UTC222OUTGET /rules/officeclicktorun.exe-Production-v19.bundle HTTP/1.1
                                                            Connection: Keep-Alive
                                                            Accept-Encoding: gzip
                                                            User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)
                                                            Host: otelrules.svc.static.microsoft
                                                            2025-03-12 09:39:56 UTC472INHTTP/1.1 200 OK
                                                            Date: Wed, 12 Mar 2025 09:39:56 GMT
                                                            Content-Type: text/plain
                                                            Content-Length: 375299
                                                            Connection: close
                                                            Vary: Accept-Encoding
                                                            Cache-Control: public
                                                            Last-Modified: Mon, 10 Mar 2025 13:15:17 GMT
                                                            ETag: "0x8DD5FD59A5E100D"
                                                            x-ms-request-id: b398a86e-d01e-0065-3732-93b77a000000
                                                            x-ms-version: 2018-03-28
                                                            x-azure-ref: 20250312T093956Z-r194b7c9999vfrqphC1BN1dn5w00000002900000000030fx
                                                            x-fd-int-roxy-purgeid: 0
                                                            X-Cache: TCP_MISS
                                                            Accept-Ranges: bytes
                                                            2025-03-12 09:39:56 UTC15912INData Raw: 31 32 30 31 30 30 76 33 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 31 30 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 74 61 72 74 75 70 22 20 2f 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 32 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 52 65 73 75 6d 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 49 20 54 3d 22 33 22 20 49 3d 22 33 30 73 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20
                                                            Data Ascii: 120100v3+<?xml version="1.0" encoding="utf-8"?><R Id="120100" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryStartup" /> <A T="2" E="TelemetryResume" /> <TI T="3" I="30s" /> <R T="4" R="120100" /> <TH
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 20 49 3d 22 31 32 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 4f 66 66 69 63 65 4d 69 6e 6f 72 56 65 72 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 4f 66 66 69 63 65 56 65 72 73 69 6f 6e 4d 69 6e 6f 72 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 33 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 41 70 70 53 74 61 74 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 41 70 70 53 74 61 74 65 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 34 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 4f 66 66 69 63 65 4d 75 69 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d
                                                            Data Ascii: I="12" O="true" N="OfficeMinorVer"> <S T="1" F="OfficeVersionMinor" M="Ignore" /> </C> <C T="U32" I="13" O="true" N="AppState"> <S T="1" F="AppState" M="Ignore" /> </C> <C T="U32" I="14" O="true" N="OfficeMuiCount"> <S T="2" F=
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 32 30 36 33 38 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22
                                                            Data Ascii: "Ignore" /> </C> <C T="W" I="1" O="false"> <S T="1" F="1" M="Ignore" /> </C> <T> <S T="1" /> </T></R><$!#>120638v0+<?xml version="1.0" encoding="utf-8"?><R Id="120638" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1"
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 54 74 5d 5b 48 68 5d 5b 49 69 5d 5b 4e 6e 5d 5b 50 70 5d 5b 55 75 5d 5b 54 74 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46
                                                            Data Ascii: ="utf-8"?><R Id="120673" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <SR T="2" R="([Tt][Hh][Ii][Nn][Pp][Uu][Tt][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S T="2" F
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 22 74 72 75 65 22 20 4e 3d 22 53 65 76 65 72 69 74 79 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 55 4c 53 5f 53 65 76 65 72 69 74 79 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 35 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 4d 65 73 73 61 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 6e 74 65 78 74 44 61 74 61 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 36 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 53 51 4d 4d 61 63 68 69 6e 65 49 44 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 4d 61 63 68 69 6e 65 49 64 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20
                                                            Data Ascii: "true" N="Severity"> <S T="5" F="ULS_Severity" M="Ignore" /> </C> <C T="W" I="5" O="true" N="Message"> <S T="5" F="ContextData" M="Ignore" /> </C> <C T="W" I="6" O="true" N="SQMMachineID"> <S T="5" F="MachineId" M="Ignore" />
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 45 72 72 6f 72 4d 65 73 73 61 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 45 72 72 6f 72 4d 65 73 73 61 67 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 31 36 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 45 72 72 6f 72 44 65 74 61 69 6c 73 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 45 72 72 6f 72 44 65 74 61 69 6c 73 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 31 37 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 53 63 65 6e 61 72 69 6f 53 75 62 54 79 70 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 53 63 65 6e 61 72 69 6f 53 75 62 54 79 70 65 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e
                                                            Data Ascii: O="false" N="ErrorMessage"> <S T="2" F="ErrorMessage" /> </C> <C T="W" I="16" O="false" N="ErrorDetails"> <S T="2" F="ErrorDetails" /> </C> <C T="W" I="17" O="true" N="ScenarioSubType"> <S T="2" F="ScenarioSubType" M="Ignore" />
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4e 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                            Data Ascii: </O> </R> </O> </L> <R> <O T="AND"> <L> <O T="NE">
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4e 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 55 4c 53 5f 54 61 67 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20
                                                            Data Ascii: > </O> </L> <R> <O T="NE"> <L> <S T="1" F="ULS_Tag" />
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4e 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 55 4c 53 5f 54 61 67 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                            Data Ascii: <L> <O T="AND"> <L> <O T="NE"> <L> <S T="1" F="ULS_Tag" />
                                                            2025-03-12 09:39:56 UTC16384INData Raw: 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 45 76 65 6e 74 53 61 6d 70 6c 69 6e 67 50 6f 6c 69 63 79 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 39 31 22 20 54 3d 22 55 38 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4e 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                            Data Ascii: <L> <S T="1" F="EventSamplingPolicy" /> </L> <R> <V V="191" T="U8" /> </R> </O> </L> <R> <O T="NE"> <L>


                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                            1192.168.2.254976313.107.253.724437768C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            TimestampBytes transferredDirectionData
                                                            2025-03-12 09:39:58 UTC214OUTGET /rules/rule170146v0s19.xml HTTP/1.1
                                                            Connection: Keep-Alive
                                                            Accept-Encoding: gzip
                                                            User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)
                                                            Host: otelrules.svc.static.microsoft
                                                            2025-03-12 09:39:59 UTC498INHTTP/1.1 200 OK
                                                            Date: Wed, 12 Mar 2025 09:39:58 GMT
                                                            Content-Type: text/xml
                                                            Content-Length: 461
                                                            Connection: close
                                                            Cache-Control: public, max-age=604800, immutable
                                                            Last-Modified: Thu, 14 Nov 2024 16:14:57 GMT
                                                            ETag: "0x8DD04C77BDE7614"
                                                            x-ms-request-id: 22968759-101e-0065-7b1c-934088000000
                                                            x-ms-version: 2018-03-28
                                                            x-azure-ref: 20250312T093958Z-r194b7c9999dcsq2hC1BN1n9gw000000048g000000001an4
                                                            x-fd-int-roxy-purgeid: 0
                                                            X-Cache-Info: L2_T1
                                                            X-Cache: TCP_REMOTE_HIT
                                                            Accept-Ranges: bytes
                                                            2025-03-12 09:39:59 UTC461INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 37 30 31 34 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 47 72 61 70 68 69 63 73 2e 45 78 70 6f 72 74 42 75 6c 6c 65 74 42 6c 69 70 43 45 78 63 65 70 74 69 6f 6e 22 20 41 54 54 3d 22 63 66 63 66 64 62 39 31 63 36 38 63 34 33 32 39 62 62 38 62 37 63 62 37 62 61 62 62 33 63 66 37 2d 65 30 38 32 63 32 66 32 2d 65 66 31 64 2d 34 32 37 61 2d 61 63 34 64 2d 62 30 62 37 30 30 61 66 65 37 61 37 2d 37 36 35 35 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 34 38 39 66 34 22 20
                                                            Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="170146" V="0" DC="SM" EN="Office.Graphics.ExportBulletBlipCException" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="489f4"


                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                            2192.168.2.254976213.107.253.724437768C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            TimestampBytes transferredDirectionData
                                                            2025-03-12 09:39:58 UTC215OUTGET /rules/rule120201v19s19.xml HTTP/1.1
                                                            Connection: Keep-Alive
                                                            Accept-Encoding: gzip
                                                            User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)
                                                            Host: otelrules.svc.static.microsoft
                                                            2025-03-12 09:39:59 UTC515INHTTP/1.1 200 OK
                                                            Date: Wed, 12 Mar 2025 09:39:59 GMT
                                                            Content-Type: text/xml
                                                            Content-Length: 2781
                                                            Connection: close
                                                            Vary: Accept-Encoding
                                                            Cache-Control: public, max-age=604800, immutable
                                                            Last-Modified: Tue, 31 Dec 2024 22:07:50 GMT
                                                            ETag: "0x8DD29E791389B5C"
                                                            x-ms-request-id: 45fd41fc-001e-008d-48cb-92d91e000000
                                                            x-ms-version: 2018-03-28
                                                            x-azure-ref: 20250312T093959Z-r194b7c9999p7t4fhC1BN1kzs000000002pg0000000006d7
                                                            x-fd-int-roxy-purgeid: 0
                                                            X-Cache: TCP_HIT
                                                            X-Cache-Info: L1_T2
                                                            Accept-Ranges: bytes
                                                            2025-03-12 09:39:59 UTC2781INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 32 30 31 22 20 56 3d 22 31 39 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 73 61 67 65 2e 43 6c 69 63 6b 53 74 72 65 61 6d 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 55 73 61 67 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20
                                                            Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120201" V="19" DC="SM" EN="Office.System.SystemHealthUsage.ClickStream" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalUsage" DCa="PSU" xmlns=""> <RIS>


                                                            Session IDSource IPSource PortDestination IPDestination Port
                                                            3192.168.2.254976413.107.253.72443
                                                            TimestampBytes transferredDirectionData
                                                            2025-03-12 09:39:59 UTC199OUTGET /rules/rule120603v9s19.xml HTTP/1.1
                                                            Connection: Keep-Alive
                                                            Accept-Encoding: gzip
                                                            User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)
                                                            Host: otelrules.svc.static.microsoft
                                                            2025-03-12 09:39:59 UTC515INHTTP/1.1 200 OK
                                                            Date: Wed, 12 Mar 2025 09:39:59 GMT
                                                            Content-Type: text/xml
                                                            Content-Length: 2231
                                                            Connection: close
                                                            Vary: Accept-Encoding
                                                            Cache-Control: public, max-age=604800, immutable
                                                            Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
                                                            ETag: "0x8DC582B99C0CEBF"
                                                            x-ms-request-id: 9615f751-d01e-0017-7f27-92b035000000
                                                            x-ms-version: 2018-03-28
                                                            x-azure-ref: 20250312T093959Z-16cb5c89b7bx6nl9hC1BN1ec1g000000058g000000001ezw
                                                            x-fd-int-roxy-purgeid: 0
                                                            X-Cache-Info: L1_T2
                                                            X-Cache: TCP_HIT
                                                            Accept-Ranges: bytes
                                                            2025-03-12 09:39:59 UTC2231INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 39 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                                                            Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="9" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                                                            Session IDSource IPSource PortDestination IPDestination Port
                                                            4192.168.2.254976513.107.253.72443
                                                            TimestampBytes transferredDirectionData
                                                            2025-03-12 09:39:59 UTC199OUTGET /rules/rule120607v1s19.xml HTTP/1.1
                                                            Connection: Keep-Alive
                                                            Accept-Encoding: gzip
                                                            User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.18129; Pro)
                                                            Host: otelrules.svc.static.microsoft
                                                            2025-03-12 09:39:59 UTC491INHTTP/1.1 200 OK
                                                            Date: Wed, 12 Mar 2025 09:39:59 GMT
                                                            Content-Type: text/xml
                                                            Content-Length: 204
                                                            Connection: close
                                                            Cache-Control: public, max-age=604800, immutable
                                                            Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                            ETag: "0x8DC582BB6C8527A"
                                                            x-ms-request-id: 7cce978f-901e-008f-21f0-9067a6000000
                                                            x-ms-version: 2018-03-28
                                                            x-azure-ref: 20250312T093959Z-16cb5c89b7b9x8nwhC1BN1wvew000000079g0000000019fc
                                                            x-fd-int-roxy-purgeid: 0
                                                            X-Cache-Info: L1_T2
                                                            X-Cache: TCP_HIT
                                                            Accept-Ranges: bytes
                                                            2025-03-12 09:39:59 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                                                            Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


                                                            Click to jump to process

                                                            Click to jump to process

                                                            Click to dive into process behavior distribution

                                                            Click to jump to process

                                                            Target ID:0
                                                            Start time:05:38:48
                                                            Start date:12/03/2025
                                                            Path:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            Wow64 process (32bit):false
                                                            Commandline:"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                                                            Imagebase:0x7ff6c9560000
                                                            File size:70'082'712 bytes
                                                            MD5 hash:F9F7B6C42211B06E7AC3E4B60AA8FB77
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:moderate
                                                            Has exited:false

                                                            Target ID:10
                                                            Start time:05:39:50
                                                            Start date:12/03/2025
                                                            Path:C:\Windows\splwow64.exe
                                                            Wow64 process (32bit):false
                                                            Commandline:C:\Windows\splwow64.exe 12288
                                                            Imagebase:0x7ff6d0830000
                                                            File size:192'512 bytes
                                                            MD5 hash:AF4A7EBF6114EE9E6FBCC910EC3C96E6
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:moderate
                                                            Has exited:false

                                                            Target ID:14
                                                            Start time:05:40:09
                                                            Start date:12/03/2025
                                                            Path:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                                                            Wow64 process (32bit):false
                                                            Commandline:"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx"
                                                            Imagebase:0x7ff6c9560000
                                                            File size:70'082'712 bytes
                                                            MD5 hash:F9F7B6C42211B06E7AC3E4B60AA8FB77
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:moderate
                                                            Has exited:true

                                                            Call Graph

                                                            • Entrypoint
                                                            • Decryption Function
                                                            • Executed
                                                            • Not Executed
                                                            • Show Help
                                                            callgraph 1 Error: Graph is empty

                                                            Module: Sheet1

                                                            Declaration
                                                            LineContent
                                                            1

                                                            Attribute VB_Name = "Sheet1"

                                                            2

                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                            3

                                                            Attribute VB_GlobalNameSpace = False

                                                            4

                                                            Attribute VB_Creatable = False

                                                            5

                                                            Attribute VB_PredeclaredId = True

                                                            6

                                                            Attribute VB_Exposed = True

                                                            7

                                                            Attribute VB_TemplateDerived = False

                                                            8

                                                            Attribute VB_Customizable = True

                                                            Module: Sheet2

                                                            Declaration
                                                            LineContent
                                                            1

                                                            Attribute VB_Name = "Sheet2"

                                                            2

                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                            3

                                                            Attribute VB_GlobalNameSpace = False

                                                            4

                                                            Attribute VB_Creatable = False

                                                            5

                                                            Attribute VB_PredeclaredId = True

                                                            6

                                                            Attribute VB_Exposed = True

                                                            7

                                                            Attribute VB_TemplateDerived = False

                                                            8

                                                            Attribute VB_Customizable = True

                                                            Module: Sheet3

                                                            Declaration
                                                            LineContent
                                                            1

                                                            Attribute VB_Name = "Sheet3"

                                                            2

                                                            Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                            3

                                                            Attribute VB_GlobalNameSpace = False

                                                            4

                                                            Attribute VB_Creatable = False

                                                            5

                                                            Attribute VB_PredeclaredId = True

                                                            6

                                                            Attribute VB_Exposed = True

                                                            7

                                                            Attribute VB_TemplateDerived = False

                                                            8

                                                            Attribute VB_Customizable = True

                                                            Module: ThisWorkbook

                                                            Declaration
                                                            LineContent
                                                            1

                                                            Attribute VB_Name = "ThisWorkbook"

                                                            2

                                                            Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                                                            3

                                                            Attribute VB_GlobalNameSpace = False

                                                            4

                                                            Attribute VB_Creatable = False

                                                            5

                                                            Attribute VB_PredeclaredId = True

                                                            6

                                                            Attribute VB_Exposed = True

                                                            7

                                                            Attribute VB_TemplateDerived = False

                                                            8

                                                            Attribute VB_Customizable = True

                                                            Reset < >