Loading ...

Play interactive tourEdit tour

Analysis Report http://documentacion.60dias.es/lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA

Overview

General Information

Sample URL:http://documentacion.60dias.es/lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA
Analysis ID:383854
Infos:

Most interesting Screenshot:

Detection

Score:25
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Injects files into Windows application
Contains capabilities to detect virtual machines
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Potential browser exploit detected (process start blacklist hit)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Tries to load missing DLLs

Classification

Analysis Advice

Sample searches for specific file, try point organization specific fake files to the analysis machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior



Startup

  • System is w10x64
  • iexplore.exe (PID: 4272 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)
    • iexplore.exe (PID: 6020 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4272 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)
    • unarchiver.exe (PID: 4608 cmdline: 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip' MD5: DB55139D9DD29F24AE8EA8F0E5606901)
      • 7za.exe (PID: 5188 cmdline: 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip' MD5: 77E556CDFDC5C592F5C46DB4127C6F4C)
        • conhost.exe (PID: 1968 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • cmd.exe (PID: 5736 cmdline: 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 3096 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
        • EXCEL.EXE (PID: 5732 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /dde MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\
Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 4x nop then jmp 0296099Bh
Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 4x nop then jmp 0296099Ah
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Windows\SysWOW64\unarchiver.exe
Source: global trafficHTTP traffic detected: GET /lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: documentacion.60dias.esConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /1120024_ESD.zip HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateConnection: Keep-AliveHost: cloud.60dias.es
Source: unknownDNS traffic detected: queries for: documentacion.60dias.es
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.aadrm.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.cortana.ai
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.diagnostics.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.office.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.onedrive.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://augloop.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://augloop.office.com/v2
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cdn.entity.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://clients.config.office.net/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://config.edge.skype.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cortana.ai
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cortana.ai/api
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://cr.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dev.cortana.ai
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://devnull.onenote.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://directory.services.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://graph.ppe.windows.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://graph.windows.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://graph.windows.net/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://lifecycle.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://login.microsoftonline.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://login.windows.local
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://management.azure.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://management.azure.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://messaging.office.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ncus.contentsync.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://officeapps.live.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://onedrive.live.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://outlook.office.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://outlook.office365.com/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://powerlift.acompli.net
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://settings.outlook.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://staging.cortana.ai
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://tasks.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://webshell.suite.office.com
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://wus2.contentsync.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drString found in binary or memory: https://www.odwebp.svc.ms
Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 6_2_029602A8
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sfc.dll
Source: classification engineClassification label: sus25.evad.win@14/14@2/2
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\HighJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1968:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3096:120:WilError_01
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Temp\~DFDAD61727858C742C.TMPJump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dll
Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
Source: C:\Program Files\internet explorer\iexplore.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4272 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Windows\SysWOW64\unarchiver.exe 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
Source: C:\Windows\SysWOW64\7za.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx'
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /dde
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4272 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Windows\SysWOW64\unarchiver.exe 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx'
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /dde
Source: C:\Program Files\internet explorer\iexplore.exeAutomated click: Run
Source: C:\Program Files\internet explorer\iexplore.exeAutomated click: Run
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll
Source: C:\Windows\SysWOW64\cmd.exeRegistry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 3564Thread sleep count: 177 > 30
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 3564Thread sleep time: -88500s >= -30000s
Source: C:\Windows\SysWOW64\unarchiver.exeLast function: Thread delayed
Source: C:\Windows\SysWOW64\unarchiver.exeLast function: Thread delayed
Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 6_2_00E9B042 GetSystemInfo,
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\
Source: C:\Windows\SysWOW64\unarchiver.exeMemory allocated: page read and write | page guard

HIPS / PFW / Operating System Protection Evasion:

barindex
Injects files into Windows applicationShow sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEInjected file: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx was created by C:\Windows\SysWOW64\7za.exe
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEInjected file: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx was created by C:\Windows\SysWOW64\7za.exe
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx'
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /dde
Source: unarchiver.exe, 00000006.00000002.476739953.0000000001390000.00000002.00000001.sdmpBinary or memory string: Program Manager
Source: unarchiver.exe, 00000006.00000002.476739953.0000000001390000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
Source: unarchiver.exe, 00000006.00000002.476739953.0000000001390000.00000002.00000001.sdmpBinary or memory string: Progman
Source: unarchiver.exe, 00000006.00000002.476739953.0000000001390000.00000002.00000001.sdmpBinary or memory string: Progmanlock
Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\SysWOW64\unarchiver.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsShared Modules1DLL Side-Loading1Process Injection112Masquerading1OS Credential DumpingQuery Registry1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution1Boot or Logon Initialization ScriptsDLL Side-Loading1Virtualization/Sandbox Evasion2LSASS MemorySecurity Software Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothIngress Tool Transfer1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Disable or Modify Tools1Security Account ManagerVirtualization/Sandbox Evasion2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection112NTDSProcess Discovery1Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information1LSA SecretsFile and Directory Discovery2SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonDLL Side-Loading1Cached Domain CredentialsSystem Information Discovery14VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 383854 URL: http://documentacion.60dias... Startdate: 08/04/2021 Architecture: WINDOWS Score: 25 7 iexplore.exe 6 70 2->7         started        process3 9 unarchiver.exe 5 7->9         started        11 iexplore.exe 27 7->11         started        dnsIp4 14 cmd.exe 7 2 9->14         started        16 7za.exe 9 9->16         started        28 cloud.60dias.es 46.25.57.74, 49708, 49709, 80 VODAFONE_ESES Spain 11->28 30 r.mailjet.com 35.241.186.140, 49706, 49707, 80 GOOGLEUS United States 11->30 32 documentacion.60dias.es 11->32 process5 file6 19 EXCEL.EXE 22 22 14->19         started        22 conhost.exe 14->22         started        26 C:\Users\user\AppData\Local\...\Resumen.xlsx, Microsoft 16->26 dropped 24 conhost.exe 16->24         started        process7 signatures8 34 Injects files into Windows application 19->34

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
http://documentacion.60dias.es/lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA0%VirustotalBrowse
http://documentacion.60dias.es/lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA0%Avira URL Cloudsafe

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
cloud.60dias.es
46.25.57.74
truefalse
    high
    r.mailjet.com
    35.241.186.140
    truefalse
      high
      documentacion.60dias.es
      unknown
      unknownfalse
        high

        URLs from Memory and Binaries

        NameSourceMaliciousAntivirus DetectionReputation
        https://api.diagnosticssdf.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
          high
          https://login.microsoftonline.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
            high
            https://shell.suite.office.com:1443375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
              high
              https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                high
                https://autodiscover-s.outlook.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                  high
                  https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                    high
                    https://cdn.entity.375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://api.addins.omex.office.net/appinfo/query375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                      high
                      https://clients.config.office.net/user/v1.0/tenantassociationkey375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                        high
                        https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                          high
                          https://powerlift.acompli.net375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://rpsticket.partnerservices.getmicrosoftkey.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://lookup.onenote.com/lookup/geolocation/v1375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                            high
                            https://cortana.ai375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                            • URL Reputation: safe
                            • URL Reputation: safe
                            • URL Reputation: safe
                            • URL Reputation: safe
                            unknown
                            https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                              high
                              https://cloudfiles.onenote.com/upload.aspx375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                high
                                https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                  high
                                  https://entitlement.diagnosticssdf.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                    high
                                    https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                      high
                                      https://api.aadrm.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      unknown
                                      https://ofcrecsvcapi-int.azurewebsites.net/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                        high
                                        https://api.microsoftstream.com/api/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                          high
                                          https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                            high
                                            https://cr.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                              high
                                              https://portal.office.com/account/?ref=ClientMeControl375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                high
                                                https://ecs.office.com/config/v2/Office375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                  high
                                                  https://graph.ppe.windows.net375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                    high
                                                    https://res.getmicrosoftkey.com/api/redemptionevents375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://powerlift-frontdesk.acompli.net375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://tasks.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                      high
                                                      https://officeci.azurewebsites.net/api/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://sr.outlook.office.net/ws/speech/recognize/assistant/work375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                        high
                                                        https://store.office.cn/addinstemplate375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://outlook.office.com/autosuggest/api/v1/init?cvid=375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                          high
                                                          https://globaldisco.crm.dynamics.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                            high
                                                            https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                              high
                                                              https://store.officeppe.com/addinstemplate375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://dev0-api.acompli.net/autodetect375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://www.odwebp.svc.ms375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://api.powerbi.com/v1.0/myorg/groups375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                high
                                                                https://web.microsoftstream.com/video/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                  high
                                                                  https://graph.windows.net375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                    high
                                                                    https://dataservice.o365filtering.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://officesetup.getmicrosoftkey.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://analysis.windows.net/powerbi/api375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                      high
                                                                      https://prod-global-autodetect.acompli.net/autodetect375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      unknown
                                                                      https://outlook.office365.com/autodiscover/autodiscover.json375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                        high
                                                                        https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                          high
                                                                          https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                            high
                                                                            https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                              high
                                                                              https://ncus.contentsync.375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                high
                                                                                https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                  high
                                                                                  http://weather.service.msn.com/data.aspx375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                    high
                                                                                    https://apis.live.net/v5.0/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    unknown
                                                                                    https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                      high
                                                                                      https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                        high
                                                                                        https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                          high
                                                                                          https://management.azure.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                            high
                                                                                            https://wus2.contentsync.375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            https://incidents.diagnostics.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                              high
                                                                                              https://clients.config.office.net/user/v1.0/ios375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                high
                                                                                                https://insertmedia.bing.office.net/odc/insertmedia375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                  high
                                                                                                  https://o365auditrealtimeingestion.manage.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                    high
                                                                                                    https://outlook.office365.com/api/v1.0/me/Activities375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                      high
                                                                                                      https://api.office.net375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                        high
                                                                                                        https://incidents.diagnosticssdf.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                          high
                                                                                                          https://asgsmsproxyapi.azurewebsites.net/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          https://clients.config.office.net/user/v1.0/android/policies375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                            high
                                                                                                            https://entitlement.diagnostics.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                              high
                                                                                                              https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                high
                                                                                                                https://outlook.office.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                  high
                                                                                                                  https://storage.live.com/clientlogs/uploadlocation375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                    high
                                                                                                                    https://templatelogging.office.com/client/log375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                      high
                                                                                                                      https://outlook.office365.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                        high
                                                                                                                        https://webshell.suite.office.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                          high
                                                                                                                          https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                            high
                                                                                                                            https://management.azure.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                              high
                                                                                                                              https://login.windows.net/common/oauth2/authorize375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                high
                                                                                                                                https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://graph.windows.net/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                  high
                                                                                                                                  https://api.powerbi.com/beta/myorg/imports375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                    high
                                                                                                                                    https://devnull.onenote.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                      high
                                                                                                                                      https://ncus.pagecontentsync.375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      unknown
                                                                                                                                      https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                        high
                                                                                                                                        https://messaging.office.com/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                          high
                                                                                                                                          https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                            high
                                                                                                                                            https://augloop.office.com/v2375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                              high
                                                                                                                                              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                high
                                                                                                                                                https://skyapi.live.net/Activity/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://clients.config.office.net/user/v1.0/mac375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://dataservice.o365filtering.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://api.cortana.ai375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://onedrive.live.com375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://ovisualuiapp.azurewebsites.net/pbiagave/375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                    • Avira URL Cloud: safe
                                                                                                                                                    unknown
                                                                                                                                                    https://visio.uservoice.com/forums/368202-visio-on-devices375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://directory.services.375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      unknown
                                                                                                                                                      https://login.windows-ppe.net/common/oauth2/authorize375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://staging.cortana.ai375DF51C-7AC3-4B35-ADE9-1C422A5A55E3.12.drfalse
                                                                                                                                                        • URL Reputation: safe
                                                                                                                                                        • URL Reputation: safe
                                                                                                                                                        • URL Reputation: safe
                                                                                                                                                        unknown

                                                                                                                                                        Contacted IPs

                                                                                                                                                        • No. of IPs < 25%
                                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                                        • 75% < No. of IPs

                                                                                                                                                        Public

                                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                        35.241.186.140
                                                                                                                                                        r.mailjet.comUnited States
                                                                                                                                                        15169GOOGLEUSfalse
                                                                                                                                                        46.25.57.74
                                                                                                                                                        cloud.60dias.esSpain
                                                                                                                                                        12430VODAFONE_ESESfalse

                                                                                                                                                        General Information

                                                                                                                                                        Joe Sandbox Version:31.0.0 Emerald
                                                                                                                                                        Analysis ID:383854
                                                                                                                                                        Start date:08.04.2021
                                                                                                                                                        Start time:11:15:54
                                                                                                                                                        Joe Sandbox Product:CloudBasic
                                                                                                                                                        Overall analysis duration:0h 5m 31s
                                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                                        Report type:light
                                                                                                                                                        Cookbook file name:browseurl.jbs
                                                                                                                                                        Sample URL:http://documentacion.60dias.es/lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA
                                                                                                                                                        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                        Number of analysed new started processes analysed:31
                                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                                        Technologies:
                                                                                                                                                        • HCA enabled
                                                                                                                                                        • EGA enabled
                                                                                                                                                        • AMSI enabled
                                                                                                                                                        Analysis Mode:default
                                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                                        Detection:SUS
                                                                                                                                                        Classification:sus25.evad.win@14/14@2/2
                                                                                                                                                        EGA Information:
                                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                                        HCA Information:
                                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                                        • Number of executed functions: 0
                                                                                                                                                        • Number of non-executed functions: 0
                                                                                                                                                        Cookbook Comments:
                                                                                                                                                        • Adjust boot time
                                                                                                                                                        • Enable AMSI
                                                                                                                                                        Warnings:
                                                                                                                                                        Show All
                                                                                                                                                        • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, BackgroundTransferHost.exe, ielowutil.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                        • TCP Packets have been reduced to 100
                                                                                                                                                        • Excluded IPs from analysis (whitelisted): 23.54.113.53, 52.255.188.83, 40.88.32.150, 52.147.198.201, 104.83.120.32, 95.100.54.203, 152.199.19.161, 52.109.76.68, 52.109.8.23, 20.82.210.154, 52.109.8.24, 13.64.90.137, 23.10.249.43, 23.10.249.26, 13.88.21.125, 20.54.26.129
                                                                                                                                                        • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, arc.msn.com.nsatc.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e11290.dspg.akamaiedge.net, iecvlist.microsoft.com, e12564.dspb.akamaiedge.net, skypedataprdcoleus15.cloudapp.net, go.microsoft.com, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, ie9comview.vo.msecnd.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, skypedataprdcoleus16.cloudapp.net, ris.api.iris.microsoft.com, skypedataprdcoleus17.cloudapp.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, go.microsoft.com.edgekey.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net, cs9.wpc.v0cdn.net
                                                                                                                                                        • Report size exceeded maximum capacity and may have missing behavior information.

                                                                                                                                                        Simulations

                                                                                                                                                        Behavior and APIs

                                                                                                                                                        No simulations

                                                                                                                                                        Joe Sandbox View / Context

                                                                                                                                                        IPs

                                                                                                                                                        No context

                                                                                                                                                        Domains

                                                                                                                                                        No context

                                                                                                                                                        ASN

                                                                                                                                                        No context

                                                                                                                                                        JA3 Fingerprints

                                                                                                                                                        No context

                                                                                                                                                        Dropped Files

                                                                                                                                                        No context

                                                                                                                                                        Created / dropped Files

                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{92649B59-9896-11EB-90E4-ECF4BB862DED}.dat
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:Microsoft Word Document
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):32344
                                                                                                                                                        Entropy (8bit):1.7980570991053986
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:48:IweGcprSjGwpLMG/ap8pGIpcR1GvnZpvR3GoVqp9RnGo4RpmR9DloGWfV9R9eGWW:rCZeZO2bWRytRUfRwRMR9DlyR93ZQ9r2
                                                                                                                                                        MD5:BAFD8CE7F977A127DC8DF7735B1FA0C6
                                                                                                                                                        SHA1:8EBCA182E78BDB7ED3464EC451BE93039DE349E3
                                                                                                                                                        SHA-256:9CE7CC4D97F8975D382421392E41BBAA21916CCAD99FEE0312E4B1BE921590C5
                                                                                                                                                        SHA-512:11C9728DC6F15B569427290FFB33B42689CDB735EF7D9E14B242DE312902F25E37A19BE858DE3CED889247C66971708130A635B7379FF3A51068358E62CADC61
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{92649B5B-9896-11EB-90E4-ECF4BB862DED}.dat
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:Microsoft Word Document
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):19032
                                                                                                                                                        Entropy (8bit):1.5986672568827065
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:48:IwKGcprPjGwpa/G4pQbGrapbSVGQpBFFpUGHHpcFFb7TGUpQFFdTQGcpm:ruZlQR6PBSfjFFpL2FFbV6FF+g
                                                                                                                                                        MD5:55408A616D032EC2BAEBC67F8A46B1BC
                                                                                                                                                        SHA1:5C5BFA2BE177EB83FE16BB8D1298E15651583CD9
                                                                                                                                                        SHA-256:8EFB6611392217B99A0130C2E26A5BBEC212CB5439BB1A07A8D7ED389F206953
                                                                                                                                                        SHA-512:5D03C12567A944C7E4EF0E480DCC277E692C7FD88AA0F44E3ADEBA2CBD78E6472AEF79B9B0AA4D45388615561F9A37162DD7D903E2C56E6399CFCEA2CD6D9C6A
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\375DF51C-7AC3-4B35-ADE9-1C422A5A55E3
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                        File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):133170
                                                                                                                                                        Entropy (8bit):5.371017531842203
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:1536:zcQIeNquBXA3gBwqpQ9DQW+zAM34ZldpKWXboOilXNErLdME9:PVQ9DQW+zTXiJ
                                                                                                                                                        MD5:C35AD0D78A2E5A001BE2183BA5E728F0
                                                                                                                                                        SHA1:23A7BF04785B54A19496C7ED5BAB49DEFE4B71EE
                                                                                                                                                        SHA-256:C00A40FE675BB59EEA14C338C3378A18DE0F7291F18A19BFAB1CEBEA9C57A39C
                                                                                                                                                        SHA-512:8C028E59B6A4D338F086191C0774BD800C6BA02D284539C195BD8FC8FC68F9360D36DB14B363C6AC10A95CD3895913EBB7D728FDB9136829F73EE9CCC8CAE4DC
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-04-08T09:17:18">.. Build: 16.0.13925.30526-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip.cseatb3.partial
                                                                                                                                                        Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):618388
                                                                                                                                                        Entropy (8bit):7.997979479925072
                                                                                                                                                        Encrypted:true
                                                                                                                                                        SSDEEP:12288:xpbcp5ibSs09nTD3yKLCokobE3T4Yu4B2bqi3ITb6r1n6JrA:Db85TD3LCoo3T8qI26NP
                                                                                                                                                        MD5:82A8C1FEDF90AE88314025CFFE5B7C8D
                                                                                                                                                        SHA1:196CBE3301460F6801D0B1E9838A4CB8A4D637BB
                                                                                                                                                        SHA-256:FB60A4714CCFDD1A695C195EBFDC08020BA2D7362FEAC1C11024E20855440B7E
                                                                                                                                                        SHA-512:E0A2AF07643E48C4DDF14DFD011F15F34BC291D2EA8E7402E0E9D96BE31170C1223AED8F1C56D30D4A64642280D57FEF803A038DE590DF23990E64C66BA4ED09
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: PK...........R................1120024_ESD/PK...........R................1120024_ESD/Factures/PK...........R2.O..>..E...L...1120024_ESD/Factures/1 Factures . COCA-COLA EUROPEAN PARTNERS FRANCE SAS.pdf..P....:x......l....-......e...-...w...!X. .=..|{........so.S..Y..k....=5.W..e...ac...'.bcp..9.],.1..9..<........99y899.....?._6.''.I>..G.Z.....:..y^.!..y>.tQj../O[.....cjyY.[A<..r.2.....P....../Z....%yy......S....oJ...........u.............$...H..Q.....b..4.......G..........W=....o?....K...B.8K.{.i.nn.9....g..|...0...........,.Z.........].....NQQl.l.+g...*......#.....K...b..x..~..h.?..hYyR.q...Psh[.zRs(8..XI.-....o.;.....p.... .j..7'5....?.y..P.......'=.?.......pr.Ss..9z..&.Y.?'"m.q.......3v...8.D.4..EL.........y...o?.V[..0.Y)5Y)el.I}V..{..f./.%1...H.pb....%..%.($.K..|...[..b'..w..Z'c..`.......4.o...........r.....3.|.....y)...f..Z..Z.4.........^....1%.'.t...?.}{.p.#oxN..*OkuI.)[.=...~....^e..j......F.[.7.z...../....$].6..8...y}y@.....W.;......Gza...P-......
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip.cseatb3.partial:Zone.Identifier
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):26
                                                                                                                                                        Entropy (8bit):3.95006375643621
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:gAWY3n:qY3n
                                                                                                                                                        MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
                                                                                                                                                        SHA1:D59FC84CDD5217C6CF74785703655F78DA6B582B
                                                                                                                                                        SHA-256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
                                                                                                                                                        SHA-512:AA1D2B1EA3C9DE3CCADB319D4E3E3276A2F27DD1A5244FE72DE2B6F94083DDDC762480482C5C2E53F803CD9E3973DDEFC68966F974E124307B5043E654443B98
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: [ZoneTransfer]..ZoneId=3..
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip:Zone.Identifier
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:very short file (no magic)
                                                                                                                                                        Category:modified
                                                                                                                                                        Size (bytes):1
                                                                                                                                                        Entropy (8bit):0.0
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:W:W
                                                                                                                                                        MD5:ECCBC87E4B5CE2FE28308FD9F2A7BAF3
                                                                                                                                                        SHA1:77DE68DAECD823BABBB58EDB1C8E14D7106E83BB
                                                                                                                                                        SHA-256:4E07408562BEDB8B60CE05C1DECFE3AD16B72230967DE01F640B7E4729B49FCE
                                                                                                                                                        SHA-512:3BAFBF08882A2D10133093A1B8433F50563B93C14ACD05B79028EB1D12799027241450980651994501423A66C276AE26C43B739BC65C4E16B10C3AF6C202AEBB
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: 3
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\1120024_ESD[1].zip
                                                                                                                                                        Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):618388
                                                                                                                                                        Entropy (8bit):7.997979479925072
                                                                                                                                                        Encrypted:true
                                                                                                                                                        SSDEEP:12288:xpbcp5ibSs09nTD3yKLCokobE3T4Yu4B2bqi3ITb6r1n6JrA:Db85TD3LCoo3T8qI26NP
                                                                                                                                                        MD5:82A8C1FEDF90AE88314025CFFE5B7C8D
                                                                                                                                                        SHA1:196CBE3301460F6801D0B1E9838A4CB8A4D637BB
                                                                                                                                                        SHA-256:FB60A4714CCFDD1A695C195EBFDC08020BA2D7362FEAC1C11024E20855440B7E
                                                                                                                                                        SHA-512:E0A2AF07643E48C4DDF14DFD011F15F34BC291D2EA8E7402E0E9D96BE31170C1223AED8F1C56D30D4A64642280D57FEF803A038DE590DF23990E64C66BA4ED09
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: PK...........R................1120024_ESD/PK...........R................1120024_ESD/Factures/PK...........R2.O..>..E...L...1120024_ESD/Factures/1 Factures . COCA-COLA EUROPEAN PARTNERS FRANCE SAS.pdf..P....:x......l....-......e...-...w...!X. .=..|{........so.S..Y..k....=5.W..e...ac...'.bcp..9.],.1..9..<........99y899.....?._6.''.I>..G.Z.....:..y^.!..y>.tQj../O[.....cjyY.[A<..r.2.....P....../Z....%yy......S....oJ...........u.............$...H..Q.....b..4.......G..........W=....o?....K...B.8K.{.i.nn.9....g..|...0...........,.Z.........].....NQQl.l.+g...*......#.....K...b..x..~..h.?..hYyR.q...Psh[.zRs(8..XI.-....o.;.....p.... .j..7'5....?.y..P.......'=.?.......pr.Ss..9z..&.Y.?'"m.q.......3v...8.D.4..EL.........y...o?.V[..0.Y)5Y)el.I}V..{..f./.%1...H.pb....%..%.($.K..|...[..b'..w..Z'c..`.......4.o...........r.....3.|.....y)...f..Z..Z.4.........^....1%.'.t...?.}{.p.#oxN..*OkuI.)[.=...~....^e..j......F.[.7.z...../....$].6..8...y}y@.....W.;......Gza...P-......
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
                                                                                                                                                        Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):89
                                                                                                                                                        Entropy (8bit):4.338690488287888
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:oVXU13FNCfzSFqH8JOGXnE13FNCfzSFZX+n:o9U1FNcvHqE1FNcyu
                                                                                                                                                        MD5:AA006BDBC1A45FFB85C77EFC79115611
                                                                                                                                                        SHA1:0DE7130D603D2FE2089BA8F35BD3B135AE0D85A4
                                                                                                                                                        SHA-256:49804E9D6724495103C54688B2A3B0B43AC0D67FF39A7AD52CF0C9562C0FE985
                                                                                                                                                        SHA-512:87FFC7367DF203A85905B2632271FBD210A037B15B9D4777C345B7580A746FAC9B18D19587B8E6CEB1FD0ACBB280467A33FE1098C63C96B046209B25D723731D
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: [2021/04/08 11:16:45.210] Latest deploy version: ..[2021/04/08 11:16:45.210] 11.211.2 ..
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\hygsnpb1.55n\unarchiver.log
                                                                                                                                                        Process:C:\Windows\SysWOW64\unarchiver.exe
                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):1732
                                                                                                                                                        Entropy (8bit):5.203432546959767
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:48:0Dy/VG0Gb0G0Gp2GrG0GpCDbGbyGRDbGcGBZG0GbG0G4G20GhGhhPVv/Lj:sWgYLSdX
                                                                                                                                                        MD5:06EED8AE46D17A9E0F69C1918F9AC38D
                                                                                                                                                        SHA1:CAF8FE2484123EFAF19E1458D7563C28CE53DFD1
                                                                                                                                                        SHA-256:5DB24CB3455BD5041E61D87D7F03358EDE5D9B672999D585EE927F4FFB795805
                                                                                                                                                        SHA-512:3D786227640929B3FB0285E6F739BD8E11F410F56D78F02B7FD6A2DE7661B6C0DB9D82AB310830C0CAC956AF55D8C994ED16D0708EE1FE3F9593E08DD7CD6D6A
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: 04/08/2021 11:17 AM: Unpack: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip..04/08/2021 11:17 AM: Tmp dir: C:\Users\user\AppData\Local\Temp\zk1enajm.gxo..04/08/2021 11:17 AM: Received from standard out: ..04/08/2021 11:17 AM: Received from standard out: 7-Zip 18.05 (x86) : Copyright (c) 1999-2018 Igor Pavlov : 2018-04-30..04/08/2021 11:17 AM: Received from standard out: ..04/08/2021 11:17 AM: Received from standard out: Scanning the drive for archives:..04/08/2021 11:17 AM: Received from standard out: 1 file, 618388 bytes (604 KiB)..04/08/2021 11:17 AM: Received from standard out: ..04/08/2021 11:17 AM: Received from standard out: Extracting archive: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip..04/08/2021 11:17 AM: Received from standard out: --..04/08/2021 11:17 AM: Received from standard out: Path = C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip..04/08/2021 11:17 AM:
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\Factures\1 Factures COCA-COLA EUROPEAN PARTNERS FRANCE SAS.pdf
                                                                                                                                                        Process:C:\Windows\SysWOW64\7za.exe
                                                                                                                                                        File Type:PDF document, version 1.7
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):630597
                                                                                                                                                        Entropy (8bit):7.995172691592337
                                                                                                                                                        Encrypted:true
                                                                                                                                                        SSDEEP:12288:qCSxF1/8vKlD08vssJv/okREdMGYIAB2byU3uTbor1nqJ7B:yXEvandHMKCwoNeB
                                                                                                                                                        MD5:AE1942278A9A157EF66F5599BB3E4AC8
                                                                                                                                                        SHA1:52F3B2101E313977B4D0F8027A68BCC5FC2ECCD8
                                                                                                                                                        SHA-256:160E8A4F9122E9B5CD1EA71174FD42F0393DA4CEE781DB5E7E6E0628F7EA1EDC
                                                                                                                                                        SHA-512:58750241EFC27BBD3846B5705C7343E75FAC7FC24A196ECF61714E283F12B1EC13C4B8C6E2C6784C3C27312135AEBD1BD1C676BA8EACBE1721628E312BC87C10
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: %PDF-1.7..%......21 0 obj..<</Title <feff005000440046005f0052006500730075006d0065006e005f0043006c00690065006e00740065> /Author <feff> /Subject <feff> /Creator <feff004d006900630072006f0073006f006600740020005200650070006f007200740069006e0067002000530065007200760069006300650073002000310030002e0030002e0030002e0030> /Producer <feff004d006900630072006f0073006f006600740020005200650070006f007200740069006e00670020005300650072007600690063006500730020005000440046002000520065006e0064006500720069006e006700200045007800740065006e00730069006f006e002000310030002e0030002e0030002e0030> /CreationDate <443a32303231303430363136333734342b303227303027> /ModDate <443a32303231303430363136333734342b303227303027> >>....endobj..22 0 obj..[0 0 595.276 841.89]..endobj..23 0 obj..<</ProcSet [/PDF /Text /ImageB /ImageC /ImageI] >>....endobj..25 0 obj..[-503 -312 1240 1026]..endobj..26 0 obj..<</Length1 597460 /Length 215028 /Filter /FlateDecode >>..stream..X...|\.?>s...E...J...].,.d.bY.eK.eK....w.....` .jB..Hk...
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx
                                                                                                                                                        Process:C:\Windows\SysWOW64\7za.exe
                                                                                                                                                        File Type:Microsoft Excel 2007+
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):14810
                                                                                                                                                        Entropy (8bit):7.2210710190002185
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:192:JNK33qTxfVz0QIBeMs1LQtayHUEsefwbo94S8ouHo8HArEblz9li+:KqjjVBf2snbo6S8oueEbh/i+
                                                                                                                                                        MD5:EC6A2AB4335324D9AC84A48D727AF309
                                                                                                                                                        SHA1:F60016CE04AD0A7E8424170DE3C8BFD2BC56014A
                                                                                                                                                        SHA-256:BBF7DC3A26976F24A7B0AAB134C731A0BF8C07D5A832F754030B28318B1ACE79
                                                                                                                                                        SHA-512:36F6947A6A4289764BE647B57F3FA2FAFFAADAAC57148749C821EF005715DDD92F3D72BF41EBD740E474F861E73A1B88AA9A39F126DD7383F46DEBC1B52A9990
                                                                                                                                                        Malicious:true
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: PK..........!.Nq.5............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0...M|......0.0.@.T...e=c.[..........$.x.nk...vvz:..."Z.Cet.zq.E.S#..'.}..c.z..(...m..hx}5.n,`D....{o.9.4.R`l,h..+..G7.V..1...voyj...;..`...dbY..qM..$..d.x...J...P..D.WZ.p...b..k0W.o...Z.j.w.]....)..D8.,J.............P.,S)H..K.@...........B.=.....y.z-.T...O.....U+.....RU)..ri;=u....%|..8.....4.y....|. .`.~S...y.h.s...7....]./.0.3J.b..E.!(..f4q.".e....}..;...y...[...............Cj........PK..........!..U0#...
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\~$Resumen.xlsx
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):165
                                                                                                                                                        Entropy (8bit):1.6081032063576088
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:RFXI6dtt:RJ1
                                                                                                                                                        MD5:7AB76C81182111AC93ACF915CA8331D5
                                                                                                                                                        SHA1:68B94B5D4C83A6FB415C8026AF61F3F8745E2559
                                                                                                                                                        SHA-256:6A499C020C6F82C54CD991CA52F84558C518CBD310B10623D847D878983A40EF
                                                                                                                                                        SHA-512:A09AB74DE8A70886C22FB628BDB6A2D773D31402D4E721F9EE2F8CCEE23A569342FEECF1B85C1A25183DD370D1DFFFF75317F628F9B3AA363BBB60694F5362C7
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\~DF7E4AA346A5DB6382.TMP
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):29989
                                                                                                                                                        Entropy (8bit):0.3303600443696975
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:24:c9lLh9lLh9lIn9lIn9lRg9lRA9lTS9lTy9lSSd9lSSd9lwFFz9lwFFz9l2FF9/94:kBqoxKAuvScS+FFMFFqFF9+FFcFFdy
                                                                                                                                                        MD5:DA1E54D46190105455BAC95FB7226435
                                                                                                                                                        SHA1:36533109E5D1CC8989ED9D81EBF19E9F7CE83131
                                                                                                                                                        SHA-256:861F5A0ED1849D46C2CFC083DD1EB1F25367DA6FCFB23EFC73AF87F933FC56C2
                                                                                                                                                        SHA-512:F7D46D2978E0F5644CD5DF4AADC05A60266A5BBCB06DB8A2CE30828EA342C18C1236E30F4498A00FF9F64536FE64919139D63FC788C920A6BBF4768AF09A9AF8
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Temp\~DFDAD61727858C742C.TMP
                                                                                                                                                        Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):12981
                                                                                                                                                        Entropy (8bit):0.44513498136721596
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:24:c9lLh9lLh9lIn9lIn9losDprF9losDpR9lWsDpxj+hnwj+9pR+9p9e:kBqoIHhxJ9G9C
                                                                                                                                                        MD5:275256C01F1FC6727BC4EB35F5B5972D
                                                                                                                                                        SHA1:D49F08ED06579E00F5670B3DB939661805959E4F
                                                                                                                                                        SHA-256:0EA5F9BDAC03F56134C811D35981FA7F6DA7A12B94CACC8923B54A302938BA3E
                                                                                                                                                        SHA-512:77D823F03DC5E5ADBEBB81504A4AB6EC3E1B759CF7B3C03AB71A65AF81519087E6B8329B7AE130F7E5D9FF924C6B4F65219276B01D090E5511BEED07BEA90E99
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................

                                                                                                                                                        Static File Info

                                                                                                                                                        No static file info

                                                                                                                                                        Network Behavior

                                                                                                                                                        Network Port Distribution

                                                                                                                                                        TCP Packets

                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                        Apr 8, 2021 11:16:45.598014116 CEST4970680192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.598843098 CEST4970780192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.623167992 CEST804970635.241.186.140192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.623297930 CEST4970680192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.623430014 CEST804970735.241.186.140192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.623505116 CEST4970780192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.624377012 CEST4970680192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.653480053 CEST804970635.241.186.140192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.653583050 CEST4970680192.168.2.335.241.186.140
                                                                                                                                                        Apr 8, 2021 11:16:45.702773094 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:45.702894926 CEST4970980192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:45.754800081 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.754878044 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:45.755986929 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:45.767456055 CEST804970946.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.767564058 CEST4970980192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:45.805542946 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.113198042 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.113301039 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114114046 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114175081 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114188910 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114196062 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114214897 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114234924 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114238024 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114285946 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114291906 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114314079 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114332914 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114332914 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114352942 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114355087 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114368916 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114393950 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.114398956 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.114439011 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.162019014 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.162142038 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.162996054 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163014889 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163028955 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163044930 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163110018 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.163111925 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163135052 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163151979 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163181067 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.163222075 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.163243055 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163279057 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.163295984 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163314104 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.163327932 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.163383007 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164000988 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164019108 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164036036 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164052963 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164084911 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164149046 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164161921 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164180040 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164196014 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164232016 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164235115 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164289951 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164324999 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.164355040 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.164413929 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.217000961 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.217091084 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.217156887 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.217175961 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.217226028 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.217279911 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218033075 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218059063 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218081951 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218101025 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218106985 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218130112 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218149900 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218153000 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218177080 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218180895 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218199968 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218220949 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218220949 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218245029 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218277931 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218282938 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218303919 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.218324900 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.218348980 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.219218969 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.219258070 CEST4970880192.168.2.346.25.57.74
                                                                                                                                                        Apr 8, 2021 11:16:46.219341040 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.219364882 CEST804970846.25.57.74192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:46.219384909 CEST4970880192.168.2.346.25.57.74

                                                                                                                                                        UDP Packets

                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                        Apr 8, 2021 11:16:36.484261036 CEST4919953192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:36.502634048 CEST53491998.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:41.242963076 CEST5062053192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:41.255044937 CEST53506208.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:42.000739098 CEST6493853192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:42.013633013 CEST53649388.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:42.938256979 CEST6015253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:42.950680971 CEST53601528.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:43.697495937 CEST5754453192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:43.709836006 CEST53575448.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:44.381289005 CEST5598453192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:44.399533033 CEST53559848.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.512476921 CEST6418553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:45.567635059 CEST53641858.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:16:45.661859035 CEST6511053192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:16:45.700223923 CEST53651108.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:03.555087090 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:03.568342924 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:11.493500948 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:11.531224966 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:14.384684086 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:14.397803068 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:15.393539906 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:15.405638933 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:16.391710997 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:16.403861046 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:17.613603115 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:17.648869991 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:18.196985006 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:18.217010021 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:18.411365986 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:18.423696995 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:19.212413073 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:19.225439072 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:20.220112085 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:20.233474016 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:22.236047029 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:22.249509096 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:22.423382044 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:22.435080051 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:23.136368036 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:23.149138927 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:26.251995087 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:26.272689104 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:27.776779890 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:27.789551020 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:28.427350998 CEST4956353192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:28.440658092 CEST53495638.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:29.056375980 CEST5135253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:29.068584919 CEST53513528.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:29.704818964 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:29.717508078 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:32.428903103 CEST5708453192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:32.447098017 CEST53570848.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:34.634510040 CEST5882353192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:34.647030115 CEST53588238.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:35.825686932 CEST5756853192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:35.839212894 CEST53575688.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:36.587181091 CEST5054053192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:36.599050999 CEST53505408.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:37.248270035 CEST5436653192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:37.261374950 CEST53543668.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:43.687622070 CEST5303453192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:43.714468002 CEST53530348.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:55.859369993 CEST5776253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:55.872694016 CEST53577628.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:56.627619028 CEST5543553192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:56.640961885 CEST53554358.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:57.633755922 CEST5071353192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:57.647391081 CEST53507138.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:17:59.130105972 CEST5613253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:17:59.142362118 CEST53561328.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:02.511327982 CEST5898753192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:02.530046940 CEST53589878.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:03.084506989 CEST5657953192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:03.098171949 CEST53565798.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:03.727587938 CEST6063353192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:03.740763903 CEST53606338.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:04.536664963 CEST6129253192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:04.549252033 CEST53612928.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:34.107825041 CEST6361953192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:34.120258093 CEST53636198.8.8.8192.168.2.3
                                                                                                                                                        Apr 8, 2021 11:18:35.551098108 CEST6493853192.168.2.38.8.8.8
                                                                                                                                                        Apr 8, 2021 11:18:35.564466000 CEST53649388.8.8.8192.168.2.3

                                                                                                                                                        DNS Queries

                                                                                                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                        Apr 8, 2021 11:16:45.512476921 CEST192.168.2.38.8.8.80xb49dStandard query (0)documentacion.60dias.esA (IP address)IN (0x0001)
                                                                                                                                                        Apr 8, 2021 11:16:45.661859035 CEST192.168.2.38.8.8.80xf79aStandard query (0)cloud.60dias.esA (IP address)IN (0x0001)

                                                                                                                                                        DNS Answers

                                                                                                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                        Apr 8, 2021 11:16:45.567635059 CEST8.8.8.8192.168.2.30xb49dNo error (0)documentacion.60dias.esr.mailjet.comCNAME (Canonical name)IN (0x0001)
                                                                                                                                                        Apr 8, 2021 11:16:45.567635059 CEST8.8.8.8192.168.2.30xb49dNo error (0)r.mailjet.com35.241.186.140A (IP address)IN (0x0001)
                                                                                                                                                        Apr 8, 2021 11:16:45.700223923 CEST8.8.8.8192.168.2.30xf79aNo error (0)cloud.60dias.es46.25.57.74A (IP address)IN (0x0001)

                                                                                                                                                        HTTP Request Dependency Graph

                                                                                                                                                        • documentacion.60dias.es
                                                                                                                                                        • cloud.60dias.es

                                                                                                                                                        HTTP Packets

                                                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                        0192.168.2.34970635.241.186.14080C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                                                        Apr 8, 2021 11:16:45.624377012 CEST1062OUTGET /lnk/AVIAACm_cEQAAAAAAAAAAB6ZWikAAAAAgOgAAAAAABJ-HQBgbHJFvpOzd7scSXmYtVyi79wxlgASfcc/1/hBWVctP4hxzhfBA9nSlUsA/aHR0cDovL2Nsb3VkLjYwZGlhcy5lcy8xMTIwMDI0X0VTRC56aXA HTTP/1.1
                                                                                                                                                        Accept: text/html, application/xhtml+xml, image/jxr, */*
                                                                                                                                                        Accept-Language: en-US
                                                                                                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                                                                                                                        Accept-Encoding: gzip, deflate
                                                                                                                                                        Host: documentacion.60dias.es
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Apr 8, 2021 11:16:45.653480053 CEST1062INHTTP/1.1 302 Found
                                                                                                                                                        content-type: text/html; charset=utf-8
                                                                                                                                                        location: http://cloud.60dias.es/1120024_ESD.zip
                                                                                                                                                        date: Thu, 08 Apr 2021 09:16:45 GMT
                                                                                                                                                        content-length: 61
                                                                                                                                                        Data Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 63 6c 6f 75 64 2e 36 30 64 69 61 73 2e 65 73 2f 31 31 32 30 30 32 34 5f 45 53 44 2e 7a 69 70 22 3e 46 6f 75 6e 64 3c 2f 61 3e 2e 0a 0a
                                                                                                                                                        Data Ascii: <a href="http://cloud.60dias.es/1120024_ESD.zip">Found</a>.


                                                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                        1192.168.2.34970846.25.57.7480C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                                                        Apr 8, 2021 11:16:45.755986929 CEST1063OUTGET /1120024_ESD.zip HTTP/1.1
                                                                                                                                                        Accept: text/html, application/xhtml+xml, image/jxr, */*
                                                                                                                                                        Accept-Language: en-US
                                                                                                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                                                                                                                        Accept-Encoding: gzip, deflate
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Host: cloud.60dias.es
                                                                                                                                                        Apr 8, 2021 11:16:46.113198042 CEST1063INHTTP/1.1 200 OK
                                                                                                                                                        Content-Type: application/x-zip-compressed
                                                                                                                                                        Last-Modified: Tue, 06 Apr 2021 14:37:45 GMT
                                                                                                                                                        Accept-Ranges: bytes
                                                                                                                                                        ETag: "6eab4a68f22ad71:0"
                                                                                                                                                        Server: Microsoft-IIS/10.0
                                                                                                                                                        X-Powered-By: ASP.NET
                                                                                                                                                        Date: Thu, 08 Apr 2021 09:16:45 GMT
                                                                                                                                                        Content-Length: 618388


                                                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                        235.241.186.14080192.168.2.349707C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                                                        Apr 8, 2021 11:16:50.648386002 CEST1716INHTTP/1.1 408 Request Time-out
                                                                                                                                                        cache-control: no-cache
                                                                                                                                                        content-type: text/html
                                                                                                                                                        connection: close
                                                                                                                                                        Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                                                                                        Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>


                                                                                                                                                        Code Manipulations

                                                                                                                                                        Statistics

                                                                                                                                                        Behavior

                                                                                                                                                        Click to jump to process

                                                                                                                                                        System Behavior

                                                                                                                                                        General

                                                                                                                                                        Start time:11:16:44
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                        Commandline:'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
                                                                                                                                                        Imagebase:0x7ff677f00000
                                                                                                                                                        File size:823560 bytes
                                                                                                                                                        MD5 hash:6465CB92B25A7BC1DF8E01D8AC5E7596
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:16:44
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4272 CREDAT:17410 /prefetch:2
                                                                                                                                                        Imagebase:0x1300000
                                                                                                                                                        File size:822536 bytes
                                                                                                                                                        MD5 hash:071277CC2E3DF41EEEA8013E2AB58D5A
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:08
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Windows\SysWOW64\unarchiver.exe
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
                                                                                                                                                        Imagebase:0x560000
                                                                                                                                                        File size:10240 bytes
                                                                                                                                                        MD5 hash:DB55139D9DD29F24AE8EA8F0E5606901
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:.Net C# or VB.NET
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:09
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Windows\SysWOW64\7za.exe
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo' 'C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\1120024_ESD.zip'
                                                                                                                                                        Imagebase:0xd10000
                                                                                                                                                        File size:289792 bytes
                                                                                                                                                        MD5 hash:77E556CDFDC5C592F5C46DB4127C6F4C
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:09
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Windows\System32\conhost.exe
                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                        Imagebase:0x7ff6b2800000
                                                                                                                                                        File size:625664 bytes
                                                                                                                                                        MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:10
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\zk1enajm.gxo\1120024_ESD\xls\Resumen.xlsx'
                                                                                                                                                        Imagebase:0xa90000
                                                                                                                                                        File size:232960 bytes
                                                                                                                                                        MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:10
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Windows\System32\conhost.exe
                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                        Imagebase:0x7ff6b2800000
                                                                                                                                                        File size:625664 bytes
                                                                                                                                                        MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        General

                                                                                                                                                        Start time:11:17:16
                                                                                                                                                        Start date:08/04/2021
                                                                                                                                                        Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /dde
                                                                                                                                                        Imagebase:0x30000
                                                                                                                                                        File size:27110184 bytes
                                                                                                                                                        MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:low

                                                                                                                                                        Disassembly

                                                                                                                                                        Code Analysis

                                                                                                                                                        Reset < >