Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Purchase Inquiry.xla.xlsx

Overview

General Information

Sample name:Purchase Inquiry.xla.xlsx
Analysis ID:1636403
MD5:120ea9ee19eb0add09beff0a8eb55bb0
SHA1:5687e15f91cfea31ffa82da06278a6239f1f1939
SHA256:55ea07bbd700488fd6330d289f210b2da119401a9e27009472d1afec2f6c6339
Tags:xlaxlsxuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 6504 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 1392 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 5112 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 5.161.200.29, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6504, Protocol: tcp, SourceIp: 192.168.2.6, SourceIsIpv6: false, SourcePort: 49698
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.6, DestinationIsIpv6: false, DestinationPort: 49698, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6504, Protocol: tcp, SourceIp: 5.161.200.29, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-12T18:35:51.626656+010020283713Unknown Traffic192.168.2.64970013.107.253.72443TCP
2025-03-12T18:35:59.695069+010020283713Unknown Traffic192.168.2.64970113.107.253.72443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Purchase Inquiry.xla.xlsxAvira: detected
Source: Purchase Inquiry.xla.xlsxVirustotal: Detection: 26%Perma Link
Source: Purchase Inquiry.xla.xlsxReversingLabs: Detection: 42%
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 5.161.200.29:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.200.29:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.6:49700 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.6:49701 version: TLS 1.2
Source: global trafficDNS query: name: st3.pro
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49698
Source: global trafficTCP traffic: 192.168.2.6:49698 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 5.161.200.29:443 -> 192.168.2.6:49699
Source: global trafficTCP traffic: 192.168.2.6:49699 -> 5.161.200.29:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700
Source: global trafficTCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: global trafficTCP traffic: 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficTCP traffic: 13.107.253.72:443 -> 192.168.2.6:49701
Source: Joe Sandbox ViewIP Address: 13.107.253.72 13.107.253.72
Source: Joe Sandbox ViewIP Address: 5.161.200.29 5.161.200.29
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49700 -> 13.107.253.72:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49701 -> 13.107.253.72:443
Source: global trafficHTTP traffic detected: GET /s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susan HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: st3.proConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /404 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: st3.proConnection: Keep-Alive
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susan HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: st3.proConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /404 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: st3.proConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: st3.pro
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Date: Wed, 12 Mar 2025 17:35:36 GMTEtag: "1225-4lR+8o8+z0M1Iq6OMuNgxAtPjT8"Strict-Transport-Security: max-age=15552000; includeSubDomainsVary: Accept-EncodingX-Content-Type-Options: nosniffX-Dns-Prefetch-Control: offX-Download-Options: noopenX-Frame-Options: SAMEORIGINX-Powered-By: Next.jsX-Xss-Protection: 1; mode=blockConnection: closeTransfer-Encoding: chunked
Source: Purchase Inquiry.xla.xlsx, AC230000.0.drString found in binary or memory: https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanzX
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 5.161.200.29:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.200.29:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.6:49700 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.253.72:443 -> 192.168.2.6:49701 version: TLS 1.2
Source: Purchase Inquiry.xla.xlsxOLE indicator, VBA macros: true
Source: Purchase Inquiry.xla.xlsxStream path 'MBD0024421D/\x1Ole' : https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanzX6m&'8IKjSD\H4%i#\lQpw^^y%TLO}V,r#5ALB;yZOR5~\'v-Sq360<2N;t|.Ut?x?b!-E-oK.0E8UZiXCr=b,J{!YrS5YcOi54ilS11F0mN3FiT0uT706jhyIQ3pO7pOKKfd7rXFKvRaB3oS3ihxs50bWLeTch03LMKkbg850gwZhKKTFhOlZB3Vh7B0WTDDYGkUBiOMQxT5S1GrCIHa8tTF5okgtA7D2R6gV7t_#rd9${C
Source: AC230000.0.drStream path 'MBD0024421D/\x1Ole' : https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanzX6m&'8IKjSD\H4%i#\lQpw^^y%TLO}V,r#5ALB;yZOR5~\'v-Sq360<2N;t|.Ut?x?b!-E-oK.0E8UZiXCr=b,J{!YrS5YcOi54ilS11F0mN3FiT0uT706jhyIQ3pO7pOKKfd7rXFKvRaB3oS3ihxs50bWLeTch03LMKkbg850gwZhKKTFhOlZB3Vh7B0WTDDYGkUBiOMQxT5S1GrCIHa8tTF5okgtA7D2R6gV7t_#rd9${C
Source: ~DF020F36458B61FF67.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'purchase inquiry.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal56.winXLSX@4/9@2/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Purchase Inquiry.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{29BA102E-F92F-40AB-8861-E60627EEDC04} - OProcSessId.datJump to behavior
Source: Purchase Inquiry.xla.xlsxOLE indicator, Workbook stream: true
Source: AC230000.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: Purchase Inquiry.xla.xlsxVirustotal: Detection: 26%
Source: Purchase Inquiry.xla.xlsxReversingLabs: Detection: 42%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: Purchase Inquiry.xla.xlsxStatic file information: File size 1319424 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: ~DF020F36458B61FF67.TMP.0.drInitial sample: OLE indicators vbamacros = False
Source: Purchase Inquiry.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Purchase Inquiry.xla.xlsxStream path 'MBD0024421C/Package' entropy: 7.99596718293 (max. 8.0)
Source: Purchase Inquiry.xla.xlsxStream path 'Workbook' entropy: 7.97996363187 (max. 8.0)
Source: AC230000.0.drStream path 'Workbook' entropy: 7.97520176885 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 814Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts3
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media3
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture14
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Purchase Inquiry.xla.xlsx27%VirustotalBrowse
Purchase Inquiry.xla.xlsx42%ReversingLabsDocument-Excel.Exploit.CVE-2017-0199
Purchase Inquiry.xla.xlsx100%AviraEXP/CVE-2017-0199.xdjci
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanzX0%Avira URL Cloudsafe
https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susan0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    high
    s-part-0044.t-0009.fb-t-msedge.net
    13.107.253.72
    truefalse
      high
      st3.pro
      5.161.200.29
      truefalse
        high
        s-0005.dual-s-msedge.net
        52.123.128.14
        truefalse
          high
          otelrules.svc.static.microsoft
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://st3.pro/404false
              high
              https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanfalse
              • Avira URL Cloud: safe
              unknown
              https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://st3.pro/s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susanzXPurchase Inquiry.xla.xlsx, AC230000.0.drfalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                13.107.253.72
                s-part-0044.t-0009.fb-t-msedge.netUnited States
                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                5.161.200.29
                st3.proGermany
                24940HETZNER-ASDEfalse
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1636403
                Start date and time:2025-03-12 18:33:35 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 5m 48s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsofficecookbook.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:13
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • GSI enabled (VBA)
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:Purchase Inquiry.xla.xlsx
                Detection:MAL
                Classification:mal56.winXLSX@4/9@2/2
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Found application associated with file extension: .xlsx
                • Found Word or Excel or PowerPoint or XPS Viewer
                • Attach to Office via COM
                • Active ActiveX Object
                • Active ActiveX Object
                • Scroll down
                • Close Viewer
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 23.60.203.209, 52.109.28.46, 52.109.68.129, 23.199.214.10, 199.232.210.172, 20.44.10.123, 20.189.173.13, 20.42.73.31, 52.123.128.14, 40.126.32.136, 20.109.210.53
                • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, eur.roaming1.live.com.akadns.net, onedscolprdeus21.eastus.cloudapp.azure.com, onedscolprdcus05.centralus.cloudapp.azure.com, mobile.events.data.microsoft.com, roaming.officeapps.live.com, dual-s-0005-office.config.skype.com, login.live.com, frc-azsc-000.roaming.officeapps.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, c.pki.goog, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, osiprod-frc-buff-azsc-000.francecentral.cloudapp.azure.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, fe3cr.delivery.mp.microsoft.com, onedscolprdwus12.westus.cloudapp.azure.com, config.officeapps.live.com, ecs.office.trafficmana
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtCreateKey calls found.
                • Report size getting too big, too many NtOpenFile calls found.
                • Report size getting too big, too many NtQueryAttributesFile calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • Report size getting too big, too many NtReadFile calls found.
                • Report size getting too big, too many NtReadVirtualMemory calls found.
                TimeTypeDescription
                13:35:41API Interceptor874x Sleep call for process: splwow64.exe modified
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                13.107.253.72NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                  https://glee.za.com/9?ai=xd&c=E,1,FswGx5hCbuIeUVR232o9qnb3ASuBT_GXK8EnT9vfZjNfbJ5_k9gx3gTjHghh9x7WXSC6B1uqdecfudRlDIywBJrwGOqHJ_jHvGG6H4rXlyuTMMpi3A,,&typo=1Get hashmaliciousUnknownBrowse
                    REFUND STATUS.docxGet hashmaliciousUnknownBrowse
                      Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                        Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                          Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                            Quote 09052022_1.xlsxGet hashmaliciousUnknownBrowse
                              https://surveymars.com/q/78graAmKoGet hashmaliciousUnknownBrowse
                                Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                  Ref PO24777.xlsGet hashmaliciousUnknownBrowse
                                    5.161.200.29ORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                      NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                          Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                            Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                              Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                  Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                    Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                      Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        s-0005.dual-s-msedge.netORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 52.123.129.14
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 52.123.128.14
                                                        Neue Bestellung 236904.xlsGet hashmaliciousUnknownBrowse
                                                        • 52.123.129.14
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 52.123.129.14
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 52.123.128.14
                                                        Offer to Purchase.xlsGet hashmaliciousUnknownBrowse
                                                        • 52.123.129.14
                                                        NFO 12032025.msgGet hashmaliciousUnknownBrowse
                                                        • 52.123.128.14
                                                        a00f6c96-d9f8-afb1-6add-aa2447c17df9.emlGet hashmaliciousUnknownBrowse
                                                        • 52.123.129.14
                                                        4be792f3-60eb-40d6-9a49-38b2d5c6224e.emlGet hashmaliciousUnknownBrowse
                                                        • 52.123.128.14
                                                        Fw_ VN MSG 4_42_16 AM DURATION_0f0b5f5e889448e7c935c0db95b1d2a6.msgGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                        • 52.123.129.14
                                                        bg.microsoft.map.fastly.netNeue Bestellung 236904.xlsGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        B32leNmDKJ.exeGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        internalinfrastructuremainoffice-7.0.2317-windows-installer.msiGet hashmaliciousScreenConnect ToolBrowse
                                                        • 199.232.214.172
                                                        svchost.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                                        • 199.232.210.172
                                                        SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        TOUR_PACKAGE.vbeGet hashmaliciousAgentTeslaBrowse
                                                        • 199.232.210.172
                                                        Gogles-suter-x64.exeGet hashmaliciousMicroClipBrowse
                                                        • 199.232.210.172
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 199.232.214.172
                                                        s-part-0044.t-0009.fb-t-msedge.netNB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        https://simplified.com/designs/cd97e327-288b-43f7-99e7-024626ab4a8c/share?utm_content=cd97e327-288b-43f7-99e7-024626ab4a8c&utm_campaign=share&utm_medium=link&utm_source=projectlinksGet hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                        • 13.107.253.72
                                                        Z0MBI3K1NG.exeGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        https://glee.za.com/9?ai=xd&c=E,1,FswGx5hCbuIeUVR232o9qnb3ASuBT_GXK8EnT9vfZjNfbJ5_k9gx3gTjHghh9x7WXSC6B1uqdecfudRlDIywBJrwGOqHJ_jHvGG6H4rXlyuTMMpi3A,,&typo=1Get hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        REFUND STATUS.docxGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Message.emlGet hashmaliciousHTMLPhisherBrowse
                                                        • 13.107.253.72
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Inv#8653763981_2sfgPaymentAdvice.svgGet hashmaliciousHTMLPhisherBrowse
                                                        • 13.107.253.72
                                                        Remittance Advice.htmGet hashmaliciousHTMLPhisherBrowse
                                                        • 13.107.253.72
                                                        Bozza nuovo ordine 0010979742.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        st3.proORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        HETZNER-ASDEORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        9ua5N7dcBZ.exeGet hashmaliciousAmadey, RHADAMANTHYSBrowse
                                                        • 213.239.239.164
                                                        https://atechelectricalengr.com/mpd/?rim=tlczs5qdc&xyr=touz&t=nbvaz8e57bgik9d&kti=jj4jd3jmzzna7&mso=559hb800tw4jljj6zf&chh2pve49=u8Y0610YGet hashmaliciousCaptcha PhishBrowse
                                                        • 188.40.246.96
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                        • 88.198.246.242
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                        • 88.198.246.242
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                        • 88.198.246.242
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                        • 88.198.246.242
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                        • 88.198.246.242
                                                        MICROSOFT-CORP-MSN-AS-BLOCKUSORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.246.60
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Neue Bestellung 236904.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.246.60
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.246.60
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.246.67
                                                        Offer to Purchase.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.246.60
                                                        9ua5N7dcBZ.exeGet hashmaliciousAmadey, RHADAMANTHYSBrowse
                                                        • 104.40.149.189
                                                        Speccy64.exeGet hashmaliciousUnknownBrowse
                                                        • 13.90.213.204
                                                        Speccy64.exeGet hashmaliciousUnknownBrowse
                                                        • 13.90.213.204
                                                        pid.kvai.exeGet hashmaliciousUnknownBrowse
                                                        • 204.79.197.203
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        6271f898ce5be7dd52b0fc260d0662b3ORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Neue Bestellung 236904.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        Offer to Purchase.xlsGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxGet hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        https://crypt.single-sign-on.password.land/Xd3QvSWJuTlhiVW04UGxPbkxoejhHVU80SU05YXVvd2Q1ZnhDMFVkN2RYQnRPM00wZ1ZhT0xuR3l5d2NvbW9vME00MURTS1lmdEwwSmdwcEtLaTJSZFpkbDd3dnJGVmdCcUNzMngxN2NOOTd0ZHhHZTJaQzN2K1ZtZ0NBanJFQXFYQk5MU2ZBT2VteUtFTkVubWtHYkVLNkNncmJpUnBOL3RLWXp2N25BTUltZ0RGcUViZnExV3pYY3BlN2kwOGhHd2hrYnR0MmVPME1pMlpCWG9PQ0JVd1RvMWd2Mi0tK2NtTUtPVmpHMWdhOENYQi0tNFkxM1RaaTIxS0pqSVk4MHhlWGFUZz09?cid=2442051797Get hashmaliciousKnowBe4Browse
                                                        • 5.161.200.29
                                                        http://def.ball-strike-up.shop/Get hashmaliciousUnknownBrowse
                                                        • 5.161.200.29
                                                        a0e9f5d64349fb13191bc781f81f42e1ORDEM DE COMPRA.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        NB NT19901102W.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Neue Bestellung 236904.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        SWIFT COPY.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Purchase Inquiry.xla.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Offer to Purchase.xlsGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        Q6EK7dte4N.exeGet hashmaliciousLummaC StealerBrowse
                                                        • 13.107.253.72
                                                        x1D44JHWDf.exeGet hashmaliciousLummaC StealerBrowse
                                                        • 13.107.253.72
                                                        M1gP5m86Gn.exeGet hashmaliciousLummaC StealerBrowse
                                                        • 13.107.253.72
                                                        SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxGet hashmaliciousUnknownBrowse
                                                        • 13.107.253.72
                                                        No context
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):118
                                                        Entropy (8bit):3.5700810731231707
                                                        Encrypted:false
                                                        SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                                                        MD5:573220372DA4ED487441611079B623CD
                                                        SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                                                        SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                                                        SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                                                        Malicious:false
                                                        Reputation:high, very likely benign file
                                                        Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):784
                                                        Entropy (8bit):2.7137690747287806
                                                        Encrypted:false
                                                        SSDEEP:24:YIrNvpKAzLRwcfHGF8AJp9WtAZRJ5poIHWI:YmbfzLmc88AJtfJ52IHV
                                                        MD5:09F73B3902CD3D88E04312787956B654
                                                        SHA1:A6C275F1A65DB02D8A752C614C27E88326447C41
                                                        SHA-256:72971990E5DC57AC8F4F27701158F6DC16E235814EA17DECA95E59CF5F60BC26
                                                        SHA-512:6A68530BA4D4413B587E340CF871162036B6AC60AC0F969C07C70967C3102ADDE3C895BA6F1E2590D9D0C98C253ADFA33CA84E65106C3B56F506FE0E06F0ADA9
                                                        Malicious:false
                                                        Reputation:moderate, very likely benign file
                                                        Preview:3.7.4.6.3.7.6.,.1.1.9.6.3.7.8.,.1.7.8.8.6.5.8.,.2.5.5.0.5.0.8.8.,.1.2.5.,.1.1.9.,.3.0.0.4.9.2.6.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.2.3.7.1.6.5.1.,.6.5.4.0.2.1.5.,.2.4.6.0.9.2.5.8.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.2.7.1.5.3.4.9.7.,.6.3.7.1.6.9.4.,.5.9.2.2.3.4.2.3.,.5.7.9.9.9.6.6.1.,.1.5.6.1.9.5.8.,.6.3.0.6.3.0.9.9.,.2.7.3.6.0.0.9.5.,.5.8.4.2.5.8.6.0.,.6.3.6.4.3.3.7.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.0.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.3.,.1.0.6.9.5.5.2.,.1.6.5.7.4.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.3.5.2.5.8.7.,.1.7.7.1.6.5.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.3.2.0.5.9.2.7.6.7.,.
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:Composite Document File V2 Document, Cannot read section info
                                                        Category:dropped
                                                        Size (bytes):1536
                                                        Entropy (8bit):1.2684092785569034
                                                        Encrypted:false
                                                        SSDEEP:6:rl912N0xs+CFfvDX+lG8ElCl5XCB9Xh9X:rl3lKFXDXanMClJCb7
                                                        MD5:7AFD65FB6FB56C22D60C8D4737E71639
                                                        SHA1:278648666058223028B4D5B0D13028EB28D4A2D7
                                                        SHA-256:94B954BD539139605C2CFD4404E9807285DACC24C6DA1FF0F9A4CCF70B594935
                                                        SHA-512:3A5E6C11B0D72E5B104A4F0FBCF0A453E61E9AB5B45B1D6C81803DEE343D114F0BB6C1914F2C0D382AF9093A3547F80384AC559633B9723B9F4BC155D8FAB7C1
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):16384
                                                        Entropy (8bit):0.06007693391688613
                                                        Encrypted:false
                                                        SSDEEP:3:xRy//lvEXKRjgEAJnOb0lvlllrAm8wtYXFqLSLcEX/:wlnAJMellhAm8wtU2WcE
                                                        MD5:1918207FF423F809365029941FF9D32F
                                                        SHA1:CE5CEF48FDF1F67CBB30317A93C250C290EFF8C6
                                                        SHA-256:56D76D4386B6234BCAE9BB895BA87EEDA21103D2468B0E77CE80CA524CE167F8
                                                        SHA-512:44A1C064A3C1A6029DCC8652B34DD74B783ED3657B4EA209243A02749D96521C192011FBDDE556D8FB4E5E4A0DFC9193D41334632C8FE5D08FB847E6D8D27202
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):512
                                                        Entropy (8bit):0.0
                                                        Encrypted:false
                                                        SSDEEP:3::
                                                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                        Malicious:false
                                                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 17:35:58 2025, Security: 1
                                                        Category:dropped
                                                        Size (bytes):54784
                                                        Entropy (8bit):7.7335414036003645
                                                        Encrypted:false
                                                        SSDEEP:1536:Ft+kNM9AKPrFzF8gN5muRMP4+7by+x56x0P6xwi9XMK:KkNYTFpZN5b+7bC0tG8
                                                        MD5:498248B9DBFA425F38B24A3B08BC4C8D
                                                        SHA1:CAD3723F30C09F653BFD7DA7DA492EFDA6BE38EC
                                                        SHA-256:A7368FC5BBC98D8CD20005F04824B51A850782A2C68365290382C188C4FAD7E9
                                                        SHA-512:0BC24F48884BBC7234468C51B96E4860CC7C7BFD0FA34E31C26F6566D45A5F8458C705CEC46BE65AD1737394B6D656EDD81B0EC443A622944510169206213570
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................h...........g...'................................................................................................... ...!..."...#...$...%...&.......(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f.......i...........................................................................
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):26
                                                        Entropy (8bit):3.95006375643621
                                                        Encrypted:false
                                                        SSDEEP:3:ggPYV:rPYV
                                                        MD5:187F488E27DB4AF347237FE461A079AD
                                                        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                                        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                                        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                                        Malicious:false
                                                        Preview:[ZoneTransfer]....ZoneId=0
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 17:35:58 2025, Security: 1
                                                        Category:dropped
                                                        Size (bytes):54784
                                                        Entropy (8bit):7.7335414036003645
                                                        Encrypted:false
                                                        SSDEEP:1536:Ft+kNM9AKPrFzF8gN5muRMP4+7by+x56x0P6xwi9XMK:KkNYTFpZN5b+7bC0tG8
                                                        MD5:498248B9DBFA425F38B24A3B08BC4C8D
                                                        SHA1:CAD3723F30C09F653BFD7DA7DA492EFDA6BE38EC
                                                        SHA-256:A7368FC5BBC98D8CD20005F04824B51A850782A2C68365290382C188C4FAD7E9
                                                        SHA-512:0BC24F48884BBC7234468C51B96E4860CC7C7BFD0FA34E31C26F6566D45A5F8458C705CEC46BE65AD1737394B6D656EDD81B0EC443A622944510169206213570
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................h...........g...'................................................................................................... ...!..."...#...$...%...&.......(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f.......i...........................................................................
                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):165
                                                        Entropy (8bit):1.610853976637159
                                                        Encrypted:false
                                                        SSDEEP:3:iXFQLjLlAWFd:97
                                                        MD5:CA2C2DB316A89F044206082EEB3A366E
                                                        SHA1:B1B7DFF94B991B26093AA29BF3793DDE245412E1
                                                        SHA-256:12393F1035745AD02C149920E37AFFE459CD0448A2AFEE25C1FABA8060758FF7
                                                        SHA-512:66BC8C779431737A3FA00AF7697C299BC473B6FD22D48914986821DA7C0AB90554D32F7F2B471EAB5410F9C0DE7E076F4D6DEDDCCE1948818F7781DAE9EDEBE7
                                                        Malicious:true
                                                        Preview:.user ..e.n.g.i.n.e.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 12 02:28:33 2025, Security: 1
                                                        Entropy (8bit):7.982759589945521
                                                        TrID:
                                                        • Microsoft Excel sheet (30009/1) 47.99%
                                                        • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                                                        • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                                                        File name:Purchase Inquiry.xla.xlsx
                                                        File size:1'319'424 bytes
                                                        MD5:120ea9ee19eb0add09beff0a8eb55bb0
                                                        SHA1:5687e15f91cfea31ffa82da06278a6239f1f1939
                                                        SHA256:55ea07bbd700488fd6330d289f210b2da119401a9e27009472d1afec2f6c6339
                                                        SHA512:50e5192956b7bd7dae3e8eee7a8fa550f5f34db4eea37aaa87595fe36e64383d94f3629c658892abf4ccbd4f0a80d52d2fa71218c07b1fb218c0d7145e3f59bc
                                                        SSDEEP:24576:cJJlEM2sTVgyawU1CGO7oaomhapQs7ANo+9npaJ0/6CYJY:SJt5xaP/O7oarhMB7Yz9paJ0/e
                                                        TLSH:F8552328BBC01B0BC4DF99B84D92D662C0368DDABE56E1573398738D383657A978331D
                                                        File Content Preview:........................>......................................................................................................................................................................................................................................
                                                        Icon Hash:35e58a8c0c8a85b9
                                                        Document Type:OLE
                                                        Number of OLE Files:1
                                                        Has Summary Info:
                                                        Application Name:Microsoft Excel
                                                        Encrypted Document:True
                                                        Contains Word Document Stream:False
                                                        Contains Workbook/Book Stream:True
                                                        Contains PowerPoint Document Stream:False
                                                        Contains Visio Document Stream:False
                                                        Contains ObjectPool Stream:False
                                                        Flash Objects Count:0
                                                        Contains VBA Macros:True
                                                        Code Page:1252
                                                        Author:
                                                        Last Saved By:
                                                        Create Time:2006-09-16 00:00:00
                                                        Last Saved Time:2025-03-12 02:28:33
                                                        Creating Application:Microsoft Excel
                                                        Security:1
                                                        Document Code Page:1252
                                                        Thumbnail Scaling Desired:False
                                                        Contains Dirty Links:False
                                                        Shared Document:False
                                                        Changed Hyperlinks:False
                                                        Application Version:786432
                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                                                        VBA File Name:Sheet1.cls
                                                        Stream Size:977
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                                                        Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 44 f7 a3 14 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                        Attribute VB_Name = "Sheet1"
                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                        Attribute VB_GlobalNameSpace = False
                                                        Attribute VB_Creatable = False
                                                        Attribute VB_PredeclaredId = True
                                                        Attribute VB_Exposed = True
                                                        Attribute VB_TemplateDerived = False
                                                        Attribute VB_Customizable = True
                                                        

                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                                                        VBA File Name:Sheet2.cls
                                                        Stream Size:977
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D ) . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                                                        Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 44 f7 29 17 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                        Attribute VB_Name = "Sheet2"
                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                        Attribute VB_GlobalNameSpace = False
                                                        Attribute VB_Creatable = False
                                                        Attribute VB_PredeclaredId = True
                                                        Attribute VB_Exposed = True
                                                        Attribute VB_TemplateDerived = False
                                                        Attribute VB_Customizable = True
                                                        

                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                                                        VBA File Name:Sheet3.cls
                                                        Stream Size:977
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0
                                                        Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 44 f7 e3 c8 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                        Attribute VB_Name = "Sheet3"
                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                        Attribute VB_GlobalNameSpace = False
                                                        Attribute VB_Creatable = False
                                                        Attribute VB_PredeclaredId = True
                                                        Attribute VB_Exposed = True
                                                        Attribute VB_TemplateDerived = False
                                                        Attribute VB_Customizable = True
                                                        

                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                                                        VBA File Name:ThisWorkbook.cls
                                                        Stream Size:985
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                                                        Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 44 f7 a8 0d 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                        Attribute VB_Name = "ThisWorkbook"
                                                        Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                                        Attribute VB_GlobalNameSpace = False
                                                        Attribute VB_Creatable = False
                                                        Attribute VB_PredeclaredId = True
                                                        Attribute VB_Exposed = True
                                                        Attribute VB_TemplateDerived = False
                                                        Attribute VB_Customizable = True
                                                        

                                                        General
                                                        Stream Path:\x1CompObj
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:114
                                                        Entropy:4.25248375192737
                                                        Base64 Encoded:True
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                                        Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                        General
                                                        Stream Path:\x5DocumentSummaryInformation
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:244
                                                        Entropy:2.889430592781307
                                                        Base64 Encoded:False
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                                                        Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                                                        General
                                                        Stream Path:\x5SummaryInformation
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:200
                                                        Entropy:3.2920681057018664
                                                        Base64 Encoded:False
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . 4 s . . . . . . . . .
                                                        Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                                                        General
                                                        Stream Path:MBD0024421C/\x1CompObj
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:99
                                                        Entropy:3.631242196770981
                                                        Base64 Encoded:False
                                                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                                                        Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                        General
                                                        Stream Path:MBD0024421C/Package
                                                        CLSID:
                                                        File Type:Microsoft Excel 2007+
                                                        Stream Size:1239758
                                                        Entropy:7.995967182931632
                                                        Base64 Encoded:True
                                                        Data ASCII:P K . . . . . . . . . . ! . . 7 : . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                        Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 c4 1b 37 3a d4 01 00 00 99 08 00 00 13 00 d4 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d0 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                        General
                                                        Stream Path:MBD0024421D/\x1Ole
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:810
                                                        Entropy:5.721957582132151
                                                        Base64 Encoded:False
                                                        Data ASCII:. . . . i e . . d . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . t . 3 . . . p . r . o . / . s . 6 . z . p . y . 2 . l . ? . & . g . a . l . l . e . o . n . = . s . k . i . n . n . y . & . r . e . c . e . s . s . = . c . a . l . m . & . d . e . c . i . m . a . l . = . u . p . t . i . g . h . t . & . c . o . n . i . f . e . r . = . y . i . e . l . d . i . n . g . & . s . u . s . a . n . . . z X 6 m . . & ' . . . 8 I K j . S D . . \\ . . H 4 . . % i # \\ l Q p w . ^ . . . ^
                                                        Data Raw:01 00 00 02 69 b4 65 1c a3 89 7f 64 00 00 00 00 00 00 00 00 00 00 00 00 b2 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b ae 01 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 74 00 33 00 2e 00 70 00 72 00 6f 00 2f 00 73 00 36 00 7a 00 70 00 79 00 32 00 6c 00 3f 00 26 00 67 00 61 00 6c 00 6c 00 65 00 6f 00 6e 00 3d 00 73 00 6b 00 69 00 6e 00 6e 00 79 00 26 00
                                                        General
                                                        Stream Path:Workbook
                                                        CLSID:
                                                        File Type:Applesoft BASIC program data, first line number 16
                                                        Stream Size:54716
                                                        Entropy:7.979963631868549
                                                        Base64 Encoded:True
                                                        Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . . . Z . o 0 0 W , ' . b X ( . C o ? ' q . . . . . . . . . . . . . . \\ . p . A . . E I l . i M D . . 6 . | . . Y ] . # n . . . D I } 0 . ^ K E " G g < ' O d 0 . 0 . v } M . i . g 0 . ( . g k . q ` T . . e . B . . . " % a . . . . . . . = . . . . L g . . . x . T | 7 . . l . . . w . . . . ) . . . . . . . . p . . . . . . . . M = . . . . / , g T . ! & L @ . . . S . . . ` . " . . . 0 . . . . . . . . # . . . i * 1 . . . . . p = 3 { " a 9 . N . 2 ! . . D . 1 . .
                                                        Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 dc 17 e4 e8 15 5a 05 a5 b4 f1 93 90 6f ec 30 bc aa 30 bc 57 2c ef e7 b6 27 d4 16 aa 99 bd 62 58 28 d7 85 c5 43 fa c9 6f 3f b5 e0 27 a2 c7 71 0b 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 9e b0 e2 00 00 00 5c 00 70 00 41 c7 2e 04 f1 45 49 c3 6c e6 1b 69 4d f2 ac 44 94 fe 0c cc 97 36 17 fe c0 7c
                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                        CLSID:
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Stream Size:535
                                                        Entropy:5.242728284402035
                                                        Base64 Encoded:True
                                                        Data ASCII:I D = " { 7 D 7 C 4 1 3 F - C C 0 A - 4 2 2 7 - A 8 A F - F A 6 E F F 1 A 7 7 7 6 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 2 F 2 D 0 F 9 5 3 F B 5 1 3 B 9 1
                                                        Data Raw:49 44 3d 22 7b 37 44 37 43 34 31 33 46 2d 43 43 30 41 2d 34 32 32 37 2d 41 38 41 46 2d 46 41 36 45 46 46 31 41 37 37 37 36 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:104
                                                        Entropy:3.0488640812019017
                                                        Base64 Encoded:False
                                                        Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                                                        Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:2644
                                                        Entropy:3.996388726204943
                                                        Base64 Encoded:False
                                                        Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                                                        Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                                                        General
                                                        Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                        CLSID:
                                                        File Type:data
                                                        Stream Size:553
                                                        Entropy:6.37141589880143
                                                        Base64 Encoded:True
                                                        Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . W . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2
                                                        Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 57 7f e8 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                        2025-03-12T18:35:51.626656+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64970013.107.253.72443TCP
                                                        2025-03-12T18:35:59.695069+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64970113.107.253.72443TCP
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Mar 12, 2025 18:35:32.011358976 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:32.011404991 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:32.011487961 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:32.011719942 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:32.011743069 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:33.689344883 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:33.689421892 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:33.693725109 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:33.693732977 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:33.693989992 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:33.694047928 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:33.694550991 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:33.740329027 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:34.171140909 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:34.171370983 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.171391964 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:34.171474934 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.180350065 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.180401087 CET443496985.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:34.180474997 CET49698443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.181698084 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.181761026 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:34.181844950 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.182053089 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:34.182076931 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.120440960 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.120513916 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.122138977 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.122155905 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.122401953 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.122452021 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.122920990 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.164319992 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.602925062 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.603054047 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.603995085 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:36.604057074 CET443496995.161.200.29192.168.2.6
                                                        Mar 12, 2025 18:35:36.604118109 CET49699443192.168.2.65.161.200.29
                                                        Mar 12, 2025 18:35:45.917999029 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:45.918037891 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:45.918104887 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:45.918617964 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:45.918627977 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.623244047 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.626530886 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.626583099 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.626656055 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:51.626689911 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.626781940 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:51.713143110 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:51.716869116 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:51.716906071 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.130681992 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.132889032 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.132930040 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.574728012 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.585774899 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.585863113 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.585894108 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.588511944 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.588530064 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.588572025 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.588584900 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.588639975 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.596245050 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.596293926 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.596348047 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.603296041 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.603409052 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.614059925 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.614603996 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.615885019 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.615914106 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.616039991 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.616050005 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.627163887 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.627196074 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.627245903 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.669178963 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.678853989 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.678867102 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.678910017 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.682172060 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.682214022 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.682231903 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.682250977 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.682296991 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.682337046 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.685508013 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.685580015 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.685611010 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.692828894 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.692873955 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.692887068 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.693305016 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.693362951 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.700052977 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.700172901 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.700213909 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.700227022 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.705977917 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.706039906 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.712819099 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.712889910 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.720019102 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.720082045 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.726181984 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.726200104 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.726233006 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.726269007 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.726327896 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.733046055 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.733076096 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.733252048 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.733259916 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.739681959 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.739711046 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.739729881 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.746758938 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.746773005 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.746814966 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.746833086 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.746886015 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.753372908 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.753422976 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.753469944 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.753488064 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.760129929 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.760186911 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.766982079 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.767004013 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.767076015 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.767102003 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.767366886 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.794143915 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.794164896 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.794195890 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.794214964 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.794250965 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.795497894 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.795515060 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.795563936 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.795572042 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.799673080 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.799722910 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.799770117 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.805607080 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.805643082 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.805650949 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.805658102 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.805695057 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.811147928 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.811266899 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.811302900 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.811311007 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.816745043 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.816796064 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.816868067 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.822268009 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.822372913 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.822421074 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.822428942 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.822503090 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.828048944 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.828075886 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.828126907 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.828135967 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.835423946 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.835485935 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.836766958 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.842827082 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.842880011 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.842911959 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.842959881 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.847321033 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.847398043 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.847446918 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.847457886 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.849653006 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.849684954 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.849695921 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.854301929 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.854351997 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.854366064 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.854449034 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.854566097 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.859121084 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.859141111 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.859189987 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.859208107 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.863723040 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.863756895 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.863775969 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.868221998 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.868253946 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.868274927 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.868303061 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.868366003 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.872534990 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.872569084 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.872616053 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.872626066 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.877191067 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.877229929 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.877247095 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.879362106 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.879404068 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.879412889 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.881709099 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.881726027 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.881753922 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.881762981 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.881824017 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.884042025 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.924376011 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.924436092 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:52.924454927 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:52.969796896 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:57.524825096 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:57.524858952 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:57.527376890 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:57.527425051 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:57.527519941 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:57.528599024 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:57.528613091 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:57.892656088 CET4434970013.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:57.938530922 CET49700443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:59.694988012 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:59.695069075 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:59.791506052 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:59.791527033 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:59.791917086 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:35:59.803123951 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:35:59.844325066 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181133032 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181193113 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181248903 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:36:00.181279898 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181356907 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181405067 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:36:00.181760073 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:36:00.181777954 CET4434970113.107.253.72192.168.2.6
                                                        Mar 12, 2025 18:36:00.181787968 CET49701443192.168.2.613.107.253.72
                                                        Mar 12, 2025 18:36:00.181794882 CET4434970113.107.253.72192.168.2.6
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Mar 12, 2025 18:35:31.996937990 CET5266753192.168.2.61.1.1.1
                                                        Mar 12, 2025 18:35:32.010713100 CET53526671.1.1.1192.168.2.6
                                                        Mar 12, 2025 18:35:45.909257889 CET5388353192.168.2.61.1.1.1
                                                        Mar 12, 2025 18:35:45.917016029 CET53538831.1.1.1192.168.2.6
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Mar 12, 2025 18:35:31.996937990 CET192.168.2.61.1.1.10xe030Standard query (0)st3.proA (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.909257889 CET192.168.2.61.1.1.10x7cb8Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Mar 12, 2025 18:34:43.606501102 CET1.1.1.1192.168.2.60x299eNo error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:34:43.606501102 CET1.1.1.1192.168.2.60x299eNo error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:34:43.606501102 CET1.1.1.1192.168.2.60x299eNo error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:34:46.239582062 CET1.1.1.1192.168.2.60xeb1fNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:34:46.239582062 CET1.1.1.1192.168.2.60xeb1fNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:35:32.010713100 CET1.1.1.1192.168.2.60xe030No error (0)st3.pro5.161.200.29A (IP address)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)azurefd-t-fb-prod.trafficmanager.netdual.s-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)dual.s-part-0044.t-0009.fb-t-msedge.nets-part-0044.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                        Mar 12, 2025 18:35:45.917016029 CET1.1.1.1192.168.2.60x7cb8No error (0)s-part-0044.t-0009.fb-t-msedge.net13.107.253.72A (IP address)IN (0x0001)false
                                                        • st3.pro
                                                        • otelrules.svc.static.microsoft
                                                        TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                        Mar 12, 2025 18:35:51.626689911 CET13.107.253.72443192.168.2.649700CN=otelrules.svc.static.microsoft, O=Microsoft Corporation, L=Redmond, ST=WA, C=US CN=Microsoft Azure RSA TLS Issuing CA 04, O=Microsoft Corporation, C=US CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=USCN=Microsoft Azure RSA TLS Issuing CA 04, O=Microsoft Corporation, C=US CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=USTue Feb 04 01:57:58 CET 2025 Thu Jun 08 02:00:00 CEST 2023 Thu Aug 01 14:00:00 CEST 2013Sun Aug 03 02:57:58 CEST 2025 Wed Aug 26 01:59:59 CEST 2026 Fri Jan 15 13:00:00 CET 2038771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0a0e9f5d64349fb13191bc781f81f42e1
                                                        CN=Microsoft Azure RSA TLS Issuing CA 04, O=Microsoft Corporation, C=USCN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=USThu Jun 08 02:00:00 CEST 2023Wed Aug 26 01:59:59 CEST 2026
                                                        CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=USThu Aug 01 14:00:00 CEST 2013Fri Jan 15 13:00:00 CET 2038
                                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                        0192.168.2.6496985.161.200.294436504C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        TimestampBytes transferredDirectionData
                                                        2025-03-12 17:35:33 UTC259OUTGET /s6zpy2l?&galleon=skinny&recess=calm&decimal=uptight&conifer=yielding&susan HTTP/1.1
                                                        Accept: */*
                                                        Accept-Encoding: gzip, deflate
                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                        Host: st3.pro
                                                        Connection: Keep-Alive
                                                        2025-03-12 17:35:34 UTC397INHTTP/1.1 301 Moved Permanently
                                                        Content-Length: 38
                                                        Content-Type: text/plain; charset=utf-8
                                                        Date: Wed, 12 Mar 2025 17:35:33 GMT
                                                        Location: /404
                                                        Strict-Transport-Security: max-age=15552000; includeSubDomains
                                                        Vary: Accept
                                                        X-Content-Type-Options: nosniff
                                                        X-Dns-Prefetch-Control: off
                                                        X-Download-Options: noopen
                                                        X-Frame-Options: SAMEORIGIN
                                                        X-Xss-Protection: 1; mode=block
                                                        Connection: close
                                                        2025-03-12 17:35:34 UTC38INData Raw: 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 2f 34 30 34
                                                        Data Ascii: Moved Permanently. Redirecting to /404


                                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                        1192.168.2.6496995.161.200.294436504C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        TimestampBytes transferredDirectionData
                                                        2025-03-12 17:35:36 UTC188OUTGET /404 HTTP/1.1
                                                        Accept: */*
                                                        Accept-Encoding: gzip, deflate
                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                        Host: st3.pro
                                                        Connection: Keep-Alive
                                                        2025-03-12 17:35:36 UTC454INHTTP/1.1 404 Not Found
                                                        Content-Type: text/html; charset=utf-8
                                                        Date: Wed, 12 Mar 2025 17:35:36 GMT
                                                        Etag: "1225-4lR+8o8+z0M1Iq6OMuNgxAtPjT8"
                                                        Strict-Transport-Security: max-age=15552000; includeSubDomains
                                                        Vary: Accept-Encoding
                                                        X-Content-Type-Options: nosniff
                                                        X-Dns-Prefetch-Control: off
                                                        X-Download-Options: noopen
                                                        X-Frame-Options: SAMEORIGIN
                                                        X-Powered-By: Next.js
                                                        X-Xss-Protection: 1; mode=block
                                                        Connection: close
                                                        Transfer-Encoding: chunked


                                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                        2192.168.2.64970113.107.253.724436504C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        TimestampBytes transferredDirectionData
                                                        2025-03-12 17:35:59 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                                                        Connection: Keep-Alive
                                                        Accept-Encoding: gzip
                                                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                                        Host: otelrules.svc.static.microsoft
                                                        2025-03-12 17:36:00 UTC515INHTTP/1.1 200 OK
                                                        Date: Wed, 12 Mar 2025 17:35:59 GMT
                                                        Content-Type: text/xml
                                                        Content-Length: 2128
                                                        Connection: close
                                                        Vary: Accept-Encoding
                                                        Cache-Control: public, max-age=604800, immutable
                                                        Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                                        ETag: "0x8DC582BA41F3C62"
                                                        x-ms-request-id: ad8ae72e-501e-0035-354f-93c923000000
                                                        x-ms-version: 2018-03-28
                                                        x-azure-ref: 20250312T173559Z-158676c854fmg8cbhC1MNZrdzg0000000a3g000000006e1q
                                                        x-fd-int-roxy-purgeid: 0
                                                        X-Cache-Info: L1_T2
                                                        X-Cache: TCP_HIT
                                                        Accept-Ranges: bytes
                                                        2025-03-12 17:36:00 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                                                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                                                        Click to jump to process

                                                        Click to jump to process

                                                        Click to dive into process behavior distribution

                                                        Click to jump to process

                                                        Target ID:0
                                                        Start time:13:34:36
                                                        Start date:12/03/2025
                                                        Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        Wow64 process (32bit):true
                                                        Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                                                        Imagebase:0x20000
                                                        File size:53'161'064 bytes
                                                        MD5 hash:4A871771235598812032C822E6F68F19
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:false

                                                        Target ID:7
                                                        Start time:13:35:41
                                                        Start date:12/03/2025
                                                        Path:C:\Windows\splwow64.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\splwow64.exe 12288
                                                        Imagebase:0x7ff7a2380000
                                                        File size:163'840 bytes
                                                        MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:false

                                                        Target ID:10
                                                        Start time:13:36:00
                                                        Start date:12/03/2025
                                                        Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                        Wow64 process (32bit):true
                                                        Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Purchase Inquiry.xla.xlsx"
                                                        Imagebase:0x20000
                                                        File size:53'161'064 bytes
                                                        MD5 hash:4A871771235598812032C822E6F68F19
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:true

                                                        Call Graph

                                                        • Entrypoint
                                                        • Decryption Function
                                                        • Executed
                                                        • Not Executed
                                                        • Show Help
                                                        callgraph 1 Error: Graph is empty

                                                        Module: Sheet1

                                                        Declaration
                                                        LineContent
                                                        1

                                                        Attribute VB_Name = "Sheet1"

                                                        2

                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                        3

                                                        Attribute VB_GlobalNameSpace = False

                                                        4

                                                        Attribute VB_Creatable = False

                                                        5

                                                        Attribute VB_PredeclaredId = True

                                                        6

                                                        Attribute VB_Exposed = True

                                                        7

                                                        Attribute VB_TemplateDerived = False

                                                        8

                                                        Attribute VB_Customizable = True

                                                        Module: Sheet2

                                                        Declaration
                                                        LineContent
                                                        1

                                                        Attribute VB_Name = "Sheet2"

                                                        2

                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                        3

                                                        Attribute VB_GlobalNameSpace = False

                                                        4

                                                        Attribute VB_Creatable = False

                                                        5

                                                        Attribute VB_PredeclaredId = True

                                                        6

                                                        Attribute VB_Exposed = True

                                                        7

                                                        Attribute VB_TemplateDerived = False

                                                        8

                                                        Attribute VB_Customizable = True

                                                        Module: Sheet3

                                                        Declaration
                                                        LineContent
                                                        1

                                                        Attribute VB_Name = "Sheet3"

                                                        2

                                                        Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                        3

                                                        Attribute VB_GlobalNameSpace = False

                                                        4

                                                        Attribute VB_Creatable = False

                                                        5

                                                        Attribute VB_PredeclaredId = True

                                                        6

                                                        Attribute VB_Exposed = True

                                                        7

                                                        Attribute VB_TemplateDerived = False

                                                        8

                                                        Attribute VB_Customizable = True

                                                        Module: ThisWorkbook

                                                        Declaration
                                                        LineContent
                                                        1

                                                        Attribute VB_Name = "ThisWorkbook"

                                                        2

                                                        Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                                                        3

                                                        Attribute VB_GlobalNameSpace = False

                                                        4

                                                        Attribute VB_Creatable = False

                                                        5

                                                        Attribute VB_PredeclaredId = True

                                                        6

                                                        Attribute VB_Exposed = True

                                                        7

                                                        Attribute VB_TemplateDerived = False

                                                        8

                                                        Attribute VB_Customizable = True

                                                        Reset < >