Loading ...

Play interactive tourEdit tour

Analysis Report SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls

Overview

General Information

Sample Name:SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls
Analysis ID:320546
MD5:66de86a7d9ba80c175fe166a81d25c4d
SHA1:8c0dcef8ad7aeb1e77bc8a18f19d270af61c94e3
SHA256:bc3b0df0a90971d83f87af531671216d238ce21b6272aa2758b178cbb1320276

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected password protected xls with embedded macros
Potential document exploit detected (performs DNS queries)
Unable to load, office file is protected or invalid

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 4120 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsJoeSecurity_PasswordProtectedXlsWithEmbeddedMacrosYara detected password protected xls with embedded macrosJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsReversingLabs: Detection: 10%
    Source: global trafficDNS query: name: cdn.onenote.net
    Source: unknownDNS traffic detected: queries for: cdn.onenote.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.aadrm.com/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.diagnostics.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.office.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.onedrive.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://augloop.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://augloop.office.com/v2
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://autodiscover-s.outlook.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cdn.entity.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://clients.config.office.net/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://config.edge.skype.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cortana.ai
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://cr.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://devnull.onenote.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://directory.services.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://graph.ppe.windows.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://graph.windows.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://graph.windows.net/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://lifecycle.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://login.microsoftonline.com/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://login.windows.local
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://management.azure.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://management.azure.com/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://messaging.office.com/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ncus-000.contentsync.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ncus-000.pagecontentsync.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://officeapps.live.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://onedrive.live.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://outlook.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://outlook.office365.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://powerlift.acompli.net
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://settings.outlook.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://store.office.com/addinstemplate
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://tasks.office.com
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://templatelogging.office.com/client/log
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://wus2-000.contentsync.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://wus2-000.pagecontentsync.
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: 9A117202-9EA1-4504-99F4-F46D76CBF970.0.drString found in binary or memory: https://www.odwebp.svc.ms
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow title found: password 12
    Source: classification engineClassification label: mal52.expl.winXLS@1/1@1/0
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{72638EDE-078F-4946-8656-9B24236DD500} - OProcSessId.datJump to behavior
    Source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsOLE indicator, Workbook stream: true
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsReversingLabs: Detection: 10%
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
    Source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsInitial sample: OLE indicators vbamacros = False
    Source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xlsInitial sample: OLE indicators encrypted = True
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

    HIPS / PFW / Operating System Protection Evasion:

    barindex
    Yara detected password protected xls with embedded macrosShow sources
    Source: Yara matchFile source: SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls, type: SAMPLE

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsExploitation for Client Execution1Path InterceptionPath InterceptionMasquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls10%ReversingLabs

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    SourceDetectionScannerLabelLink
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://wus2-000.contentsync.0%URL Reputationsafe
    https://wus2-000.contentsync.0%URL Reputationsafe
    https://wus2-000.contentsync.0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://wus2-000.pagecontentsync.0%URL Reputationsafe
    https://wus2-000.pagecontentsync.0%URL Reputationsafe
    https://wus2-000.pagecontentsync.0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
    https://ncus-000.contentsync.0%URL Reputationsafe
    https://ncus-000.contentsync.0%URL Reputationsafe
    https://ncus-000.contentsync.0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    cdn.onenote.net
    unknown
    unknownfalse
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      https://api.diagnosticssdf.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
        high
        https://login.microsoftonline.com/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
          high
          https://shell.suite.office.com:14439A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
            high
            https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
              high
              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                high
                https://cdn.entity.9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                • URL Reputation: safe
                • URL Reputation: safe
                • URL Reputation: safe
                unknown
                https://api.addins.omex.office.net/appinfo/query9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                  high
                  https://wus2-000.contentsync.9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://clients.config.office.net/user/v1.0/tenantassociationkey9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                    high
                    https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                      high
                      https://powerlift.acompli.net9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://rpsticket.partnerservices.getmicrosoftkey.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://lookup.onenote.com/lookup/geolocation/v19A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                        high
                        https://cortana.ai9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                          high
                          https://cloudfiles.onenote.com/upload.aspx9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                            high
                            https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                              high
                              https://entitlement.diagnosticssdf.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                high
                                https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                  high
                                  https://api.aadrm.com/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  unknown
                                  https://ofcrecsvcapi-int.azurewebsites.net/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                    high
                                    https://api.microsoftstream.com/api/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                      high
                                      https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                        high
                                        https://cr.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                          high
                                          https://portal.office.com/account/?ref=ClientMeControl9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                            high
                                            https://ecs.office.com/config/v2/Office9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                              high
                                              https://graph.ppe.windows.net9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                high
                                                https://res.getmicrosoftkey.com/api/redemptionevents9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://powerlift-frontdesk.acompli.net9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://tasks.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                  high
                                                  https://officeci.azurewebsites.net/api/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://sr.outlook.office.net/ws/speech/recognize/assistant/work9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                    high
                                                    https://store.office.cn/addinstemplate9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://wus2-000.pagecontentsync.9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://outlook.office.com/autosuggest/api/v1/init?cvid=9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                      high
                                                      https://globaldisco.crm.dynamics.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                        high
                                                        https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                          high
                                                          https://store.officeppe.com/addinstemplate9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://dev0-api.acompli.net/autodetect9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://www.odwebp.svc.ms9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://api.powerbi.com/v1.0/myorg/groups9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                            high
                                                            https://web.microsoftstream.com/video/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                              high
                                                              https://graph.windows.net9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                high
                                                                https://dataservice.o365filtering.com/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://officesetup.getmicrosoftkey.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://analysis.windows.net/powerbi/api9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                  high
                                                                  https://prod-global-autodetect.acompli.net/autodetect9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://outlook.office365.com/autodiscover/autodiscover.json9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                    high
                                                                    https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                      high
                                                                      https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                        high
                                                                        https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                          high
                                                                          https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                            high
                                                                            https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                              high
                                                                              http://weather.service.msn.com/data.aspx9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                high
                                                                                https://apis.live.net/v5.0/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                  high
                                                                                  https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                    high
                                                                                    https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                      high
                                                                                      https://management.azure.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                        high
                                                                                        https://outlook.office365.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                          high
                                                                                          https://incidents.diagnostics.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                            high
                                                                                            https://clients.config.office.net/user/v1.0/ios9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                              high
                                                                                              https://insertmedia.bing.office.net/odc/insertmedia9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                high
                                                                                                https://o365auditrealtimeingestion.manage.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                  high
                                                                                                  https://outlook.office365.com/api/v1.0/me/Activities9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                    high
                                                                                                    https://api.office.net9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                      high
                                                                                                      https://incidents.diagnosticssdf.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                        high
                                                                                                        https://asgsmsproxyapi.azurewebsites.net/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                        • Avira URL Cloud: safe
                                                                                                        unknown
                                                                                                        https://clients.config.office.net/user/v1.0/android/policies9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                          high
                                                                                                          https://entitlement.diagnostics.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                            high
                                                                                                            https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                              high
                                                                                                              https://autodiscover-s.outlook.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                  high
                                                                                                                  https://templatelogging.office.com/client/log9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                        high
                                                                                                                        https://ncus-000.contentsync.9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        unknown
                                                                                                                        https://login.windows.net/common/oauth2/authorize9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/imports9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                high
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v29A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/mac9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devices9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorize9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://loki.delve.office.com/api/v1/configuration/officewin32/9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://onedrive.live.com/embed?9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://augloop.office.com9A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA29A117202-9EA1-4504-99F4-F46D76CBF970.0.drfalse
                                                                                                                                                          high

                                                                                                                                                          Contacted IPs

                                                                                                                                                          No contacted IP infos

                                                                                                                                                          General Information

                                                                                                                                                          Joe Sandbox Version:31.0.0 Red Diamond
                                                                                                                                                          Analysis ID:320546
                                                                                                                                                          Start date:19.11.2020
                                                                                                                                                          Start time:14:21:30
                                                                                                                                                          Joe Sandbox Product:CloudBasic
                                                                                                                                                          Overall analysis duration:0h 3m 53s
                                                                                                                                                          Hypervisor based Inspection enabled:false
                                                                                                                                                          Report type:light
                                                                                                                                                          Sample file name:SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls
                                                                                                                                                          Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                          Run name:Potential for more IOCs and behavior
                                                                                                                                                          Number of analysed new started processes analysed:21
                                                                                                                                                          Number of new started drivers analysed:0
                                                                                                                                                          Number of existing processes analysed:0
                                                                                                                                                          Number of existing drivers analysed:0
                                                                                                                                                          Number of injected processes analysed:0
                                                                                                                                                          Technologies:
                                                                                                                                                          • HCA enabled
                                                                                                                                                          • EGA enabled
                                                                                                                                                          • HDC enabled
                                                                                                                                                          • AMSI enabled
                                                                                                                                                          Analysis Mode:default
                                                                                                                                                          Analysis stop reason:Timeout
                                                                                                                                                          Detection:MAL
                                                                                                                                                          Classification:mal52.expl.winXLS@1/1@1/0
                                                                                                                                                          Cookbook Comments:
                                                                                                                                                          • Adjust boot time
                                                                                                                                                          • Enable AMSI
                                                                                                                                                          • Found application associated with file extension: .xls
                                                                                                                                                          • Changed system and user locale, location and keyboard layout to Italian - Italy
                                                                                                                                                          • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                          • Attach to Office via COM
                                                                                                                                                          • Scroll down
                                                                                                                                                          • Close Viewer
                                                                                                                                                          Warnings:
                                                                                                                                                          Show All
                                                                                                                                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                          • Excluded IPs from analysis (whitelisted): 104.42.151.234, 52.109.32.27, 52.109.88.39, 104.43.193.48, 52.109.8.25, 51.132.208.181, 104.84.56.60, 23.14.92.88, 23.14.92.27, 20.54.26.129, 104.108.60.202, 104.123.31.226, 51.11.168.160, 2.16.106.105, 2.16.106.113, 51.104.144.132
                                                                                                                                                          • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, prod-w.nexus.live.com.akadns.net, arc.msn.com.nsatc.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e15275.g.akamaiedge.net, a1449.dscg2.akamai.net, arc.msn.com, cdn.onenote.net.edgekey.net, wildcard.weather.microsoft.com.edgekey.net, audownload.windowsupdate.nsatc.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, tile-service.weather.microsoft.com, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, skypedataprdcolcus15.cloudapp.net, ris.api.iris.microsoft.com, umwatsonrouting.trafficmanager.net, config.officeapps.live.com, e1553.dspg.akamaiedge.net, skypedataprdcolwus16.cloudapp.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                          • VT rate limit hit for: /opt/package/joesandbox/database/analysis/320546/sample/SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls

                                                                                                                                                          Simulations

                                                                                                                                                          Behavior and APIs

                                                                                                                                                          No simulations

                                                                                                                                                          Joe Sandbox View / Context

                                                                                                                                                          IPs

                                                                                                                                                          No context

                                                                                                                                                          Domains

                                                                                                                                                          No context

                                                                                                                                                          ASN

                                                                                                                                                          No context

                                                                                                                                                          JA3 Fingerprints

                                                                                                                                                          No context

                                                                                                                                                          Dropped Files

                                                                                                                                                          No context

                                                                                                                                                          Created / dropped Files

                                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9A117202-9EA1-4504-99F4-F46D76CBF970
                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                          File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                          Category:dropped
                                                                                                                                                          Size (bytes):129952
                                                                                                                                                          Entropy (8bit):5.378315015594326
                                                                                                                                                          Encrypted:false
                                                                                                                                                          SSDEEP:1536:pcQceNWiA3gZwLpQ9DQW+zAUH34ZldpKWXboOilXPErLL8TT:jmQ9DQW+zBX8u
                                                                                                                                                          MD5:5415095E50480ADD9F231767F987AFA2
                                                                                                                                                          SHA1:9426458D50397B697133055E46445FD1A2C057AB
                                                                                                                                                          SHA-256:95743C94995233DBC0AB7F21927DA0979ADF10C46CD22BAB3852BF469095FB72
                                                                                                                                                          SHA-512:F0B550E4B281AD837901C0FEC9BC7CDB2762C9FB8F8D19A99E3D205565918A02D65C3A2792CDDFDDEA49366126B591436D10EB8AF73684C0A551E724709830EA
                                                                                                                                                          Malicious:false
                                                                                                                                                          Reputation:low
                                                                                                                                                          Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2020-11-19T13:22:32">.. Build: 16.0.13517.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:

                                                                                                                                                          Static File Info

                                                                                                                                                          General

                                                                                                                                                          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: bOpMKmUlXbBbmg, Last Saved By: administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Nov 18 22:00:31 2020, Last Saved Time/Date: Wed Nov 18 23:17:00 2020, Security: 1
                                                                                                                                                          Entropy (8bit):7.6578858889050165
                                                                                                                                                          TrID:
                                                                                                                                                          • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                          • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                          File name:SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls
                                                                                                                                                          File size:418304
                                                                                                                                                          MD5:66de86a7d9ba80c175fe166a81d25c4d
                                                                                                                                                          SHA1:8c0dcef8ad7aeb1e77bc8a18f19d270af61c94e3
                                                                                                                                                          SHA256:bc3b0df0a90971d83f87af531671216d238ce21b6272aa2758b178cbb1320276
                                                                                                                                                          SHA512:c7b1885f70898bf90e677962c595df8d6d1a7b840a9c14647957726c59f67c4b8073c1a2289143dca6e92b58ec9f32e574b6f365c5315500c7eee3eeec6bd8a6
                                                                                                                                                          SSDEEP:12288:t6Qtw5NtDtkd1zsRXSqUXVIF/MZX3BhAOepArPmHQeq:G5bpY1zstSNXuVKX4OepArMJq
                                                                                                                                                          File Content Preview:........................>......................./...........................(...)...*...+...,...-..............................................................................................................................................................

                                                                                                                                                          File Icon

                                                                                                                                                          Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                          Static OLE Info

                                                                                                                                                          General

                                                                                                                                                          Document Type:OLE
                                                                                                                                                          Number of OLE Files:1

                                                                                                                                                          OLE File "SecuriteInfo.com.Macro.Trojan-Downloader.Encrypted.A.xls"

                                                                                                                                                          Indicators

                                                                                                                                                          Has Summary Info:True
                                                                                                                                                          Application Name:Microsoft Excel
                                                                                                                                                          Encrypted Document:True
                                                                                                                                                          Contains Word Document Stream:False
                                                                                                                                                          Contains Workbook/Book Stream:True
                                                                                                                                                          Contains PowerPoint Document Stream:False
                                                                                                                                                          Contains Visio Document Stream:False
                                                                                                                                                          Contains ObjectPool Stream:
                                                                                                                                                          Flash Objects Count:
                                                                                                                                                          Contains VBA Macros:False

                                                                                                                                                          Summary

                                                                                                                                                          Code Page:1252
                                                                                                                                                          Author:bOpMKmUlXbBbmg
                                                                                                                                                          Last Saved By:administrator
                                                                                                                                                          Create Time:2020-11-18 22:00:31
                                                                                                                                                          Last Saved Time:2020-11-18 23:17:00
                                                                                                                                                          Creating Application:Microsoft Excel
                                                                                                                                                          Security:1

                                                                                                                                                          Document Summary

                                                                                                                                                          Document Code Page:1252
                                                                                                                                                          Thumbnail Scaling Desired:False
                                                                                                                                                          Company:
                                                                                                                                                          Contains Dirty Links:False
                                                                                                                                                          Shared Document:False
                                                                                                                                                          Changed Hyperlinks:False
                                                                                                                                                          Application Version:1048576

                                                                                                                                                          Streams

                                                                                                                                                          Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                          General
                                                                                                                                                          Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                          File Type:data
                                                                                                                                                          Stream Size:4096
                                                                                                                                                          Entropy:0.839708850949
                                                                                                                                                          Base64 Encoded:False
                                                                                                                                                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . L . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F o g l i o 1 . . . . . F o g l i o 2 . . . . . F o g l i o 3 . . . . . F o g l i o 4 . . . . . E T M v d g B d
                                                                                                                                                          Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 4c 02 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 01 02 00 00
                                                                                                                                                          Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                          General
                                                                                                                                                          Stream Path:\x5SummaryInformation
                                                                                                                                                          File Type:data
                                                                                                                                                          Stream Size:4096
                                                                                                                                                          Entropy:0.327276850068
                                                                                                                                                          Base64 Encoded:False
                                                                                                                                                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . b O p M K m U l X b B b m g . . . . . . . . . . a d m i n i s t r a t o r . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . c ; . . . . @ . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                          Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 b0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 60 00 00 00 12 00 00 00 78 00 00 00 0c 00 00 00 90 00 00 00 0d 00 00 00 9c 00 00 00 13 00 00 00 a8 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 10 00 00 00
                                                                                                                                                          Stream Path: Workbook, File Type: Applesoft BASIC program data, first line number 16, Stream Size: 405135
                                                                                                                                                          General
                                                                                                                                                          Stream Path:Workbook
                                                                                                                                                          File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                          Stream Size:405135
                                                                                                                                                          Entropy:7.75501180979
                                                                                                                                                          Base64 Encoded:True
                                                                                                                                                          Data ASCII:. . . . . . . . Z O . . . . . . . . . . / . . . . . . . . . . . . . ~ . . . . . . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . M . i . c . r . o . s . o . f . t . . E . n . h . a . n . c . e . d . . C . r . y . p . t . o . g . r . a . p . h . i . c . . P . r . o . v . i . d . e . r . . v . 1 . . . 0 . . . . . . . D . I r " . . . v f \\ . W p . . . . . . . . t . . - . . . 1 . . . . . . . . . . m . . . 7 F V - . ! . ) . # . . . . . . . . . . . . . . . . . . \\ . p . . . . . 7 . * . ` . / .
                                                                                                                                                          Data Raw:09 08 10 00 00 06 05 00 5a 4f cd 07 c9 00 02 00 06 08 00 00 2f 00 c8 00 01 00 04 00 02 00 0c 00 00 00 7e 00 00 00 0c 00 00 00 00 00 00 00 01 68 00 00 04 80 00 00 80 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 4d 00 69 00 63 00 72 00 6f 00 73 00 6f 00 66 00 74 00 20 00 45 00 6e 00 68 00 61 00 6e 00 63 00 65 00 64 00 20 00 43 00 72 00 79 00 70 00 74 00 6f 00 67 00 72 00 61 00 70 00

                                                                                                                                                          Network Behavior

                                                                                                                                                          Network Port Distribution

                                                                                                                                                          UDP Packets

                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                          Nov 19, 2020 14:22:30.767960072 CET5062053192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:30.795135021 CET53506208.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:31.854453087 CET6493853192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:31.891474009 CET53649388.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:32.189357042 CET6015253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:32.246296883 CET53601528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:32.967861891 CET5754453192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:32.994967937 CET53575448.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:33.188743114 CET6015253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:33.226749897 CET53601528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:34.214438915 CET6015253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:34.249897957 CET53601528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:36.220263004 CET6015253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:36.257525921 CET53601528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:38.014018059 CET5598453192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:38.041222095 CET53559848.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:38.988238096 CET6418553192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:39.023794889 CET53641858.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:39.849150896 CET6511053192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:39.876204014 CET53651108.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:40.220809937 CET6015253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:40.256076097 CET53601528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:40.994908094 CET5836153192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:41.030278921 CET53583618.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:43.892469883 CET6349253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:43.919558048 CET53634928.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:47.841114998 CET6083153192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:47.868073940 CET53608318.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:48.725825071 CET6010053192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:48.763019085 CET53601008.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:54.273874044 CET5319553192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:54.300936937 CET53531958.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:55.275489092 CET5014153192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:55.302467108 CET53501418.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:56.093519926 CET5302353192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:56.131140947 CET53530238.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:57.305331945 CET4956353192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:57.332411051 CET53495638.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:58.262403011 CET5135253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:58.289391994 CET53513528.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:22:59.093350887 CET5934953192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:22:59.128614902 CET53593498.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:00.815629959 CET5708453192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:00.861135960 CET53570848.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:01.821779013 CET5882353192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:01.848959923 CET53588238.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:03.415399075 CET5756853192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:03.442403078 CET53575688.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:05.492049932 CET5054053192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:05.519011021 CET53505408.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:06.555135965 CET5436653192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:06.582597017 CET53543668.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:07.593278885 CET5303453192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:07.620311022 CET53530348.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:07.851814032 CET5776253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:07.891577005 CET53577628.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:08.162103891 CET5543553192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:08.206183910 CET53554358.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:20.706362009 CET5071353192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:20.706922054 CET5613253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:20.743141890 CET53507138.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:20.754509926 CET53561328.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:22.735336065 CET5898753192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:22.762392998 CET53589878.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:28.462939978 CET5657953192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:28.504091024 CET53565798.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:23:57.168675900 CET6063353192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:23:57.195882082 CET53606338.8.8.8192.168.2.3
                                                                                                                                                          Nov 19, 2020 14:24:31.111319065 CET6129253192.168.2.38.8.8.8
                                                                                                                                                          Nov 19, 2020 14:24:31.138313055 CET53612928.8.8.8192.168.2.3

                                                                                                                                                          DNS Queries

                                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                          Nov 19, 2020 14:23:20.706362009 CET192.168.2.38.8.8.80xeee5Standard query (0)cdn.onenote.netA (IP address)IN (0x0001)

                                                                                                                                                          DNS Answers

                                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                          Nov 19, 2020 14:23:20.743141890 CET8.8.8.8192.168.2.30xeee5No error (0)cdn.onenote.netcdn.onenote.net.edgekey.netCNAME (Canonical name)IN (0x0001)

                                                                                                                                                          Code Manipulations

                                                                                                                                                          Statistics

                                                                                                                                                          System Behavior

                                                                                                                                                          General

                                                                                                                                                          Start time:14:22:30
                                                                                                                                                          Start date:19/11/2020
                                                                                                                                                          Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                          Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                          Imagebase:0x360000
                                                                                                                                                          File size:27110184 bytes
                                                                                                                                                          MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                          Reputation:high

                                                                                                                                                          Disassembly

                                                                                                                                                          Reset < >