32.0.0 Black Diamond
IR
404155
CloudBasic
19:04:16
04/05/2021
Outstanding-Debt-71778964-05042021.xlsm
defaultwindowsofficecookbook.jbs
Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
WINDOWS
19ad92f20025aa19a6947fa78fd142c1
70b88be09827de5d40a03bca4ac49e2a7de69ea9
f7bb7538509e6652197d8877aceac43f6370b763a323cb3990ab5991124b1941
Excel Microsoft Office Open XML Format document with Macro (57504/1) 54.50%
true
false
false
false
60
0
100
5
0
5
false
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D47D16E7-9A16-4855-BDA9-1C37DDB21F3A
false
6CBAAD565B11D337AA1BFD80182020EF
B365E6B4A0CD71A93BCD6F5ABC35456E47732B9C
DFABBEF4BAE3ECD5D2A4478470CA1E56B7B1BB11FFE59C6D2B4A175BDD17DD0D
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\B0B63ACE.jpg
false
4A425E6A5A885C0D0E2589506FD2244B
E23482422480A4720E22F311B42BD65E2F3556F8
76E685FC2035D8CF19945C6686D82054B64D0A9612853D8F428C4B4FE351C160
C:\Users\user\AppData\Local\Temp\9DC10000
false
1DA7EF76CBFC710659320C69E3ED7999
4CA06310D5E22404C181BC832E20A9D63EFAA760
3B62AAD82F675689779BF6CD0B3C7D635AD1CF9A56A9016E4B3C387EECB84CE0
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
false
02D38DC389500B3FB8099FC93BB2639F
B750968ACB94F0A8F6B2A96740124B31F28870A6
69B4EABFC741EC40E82FCEFB10F827B47036AC42215493AF990B96AFA1474222
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
false
216D8A91434F51E7150476118348A698
2F9ACFAFFB88F0B8C21AFAE2D6FE3831BC5868F6
7C3AACE271F8B3FF8C03864B0EC603801FA207E6ECEB600D969928D89E1783BC
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Outstanding-Debt-71778964-05042021.LNK
false
8E4D97628E87A4E9DE37BBFFC26B42F4
304ABF656F8F7CCDE602C29129A67CAB3DC837A8
6A7A8CE8CED172AE4735586C82851395D55992662AEF7DDF9169E273C4719E51
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
false
683442FC3BF5E8A3E13273B05CE88F11
54A91648A3C9962F42651771B16DFDF2BC17DCF9
52A36727E0B670238053CAA7AFFBABBFB10F00CD16595BBDF630D79967DEE317
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
false
7962B839183642D3CDC2F9CEBDBF85CE
2BE8F6F309962ED367866F6E70668508BC814C2D
5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
C:\Users\user\Desktop\5EC10000
false
74FACCA6B9FC5ED46704A2F4DE91A6E9
2E4707C6E76423B65A5DDB7E5D287273E47AC024
1BA03CDFA7EDD40F21F08E7E8FAB766CC3B181CB50E1AF1C81F3856923334CC0
C:\Users\user\Desktop\~$Outstanding-Debt-71778964-05042021.xlsm
true
836727206447D2C6B98C973E058460C9
D83351CF6DE78FEDE0142DE5434F9217C4F285D2
D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
91.211.91.81
5.34.179.36
45.153.229.23
Document contains an embedded VBA macro which may execute processes
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Found malicious Excel 4.0 Macro