Loading ...

Play interactive tourEdit tour

Analysis Report document-47-2637.xls

Overview

General Information

Sample Name:document-47-2637.xls
Analysis ID:432926
MD5:92dcc47a1a044fc3a2328ec6eef3918b
SHA1:6f9266a6c0b702cbaa0a3583df5c8cd1357eae35
SHA256:ac4b99079b1ceb11db593097e421de9d9092765feedc23a3ab8ef912b292c988
Tags:xls
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Checks if browser processes are running
Contains functionality to compare user and computer (likely to detect sandboxes)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Found abnormal large hidden Excel 4.0 Macro sheet
Sigma detected: Microsoft Office Product Spawning Windows Shell
Allocates a big amount of memory (probably used for heap spraying)
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Uses code obfuscation techniques (call, push, ret)

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 6968 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • cmd.exe (PID: 7156 cmdline: 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • conhost.exe (PID: 6172 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nnAzot.exe (PID: 4600 cmdline: 'C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe' C:\aZ8ThU0Y\ERdZMUem GdPT AuMr7 MD5: CE639EB63B7C1C1EC94651B65CCEC383)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe, CommandLine: 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6968, ProcessCommandLine: 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe, ProcessId: 7156

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: document-47-2637.xlsVirustotal: Detection: 26%Perma Link
Source: document-47-2637.xlsMetadefender: Detection: 22%Perma Link
Source: document-47-2637.xlsReversingLabs: Detection: 15%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: unknownHTTPS traffic detected: 198.244.146.96:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: Binary string: extexport.pdbGCTL source: nnAzot.exe, 00000005.00000000.666770148.0000000001151000.00000020.00020000.sdmp, nnAzot.exe.2.dr
Source: Binary string: extexport.pdb source: nnAzot.exe, nnAzot.exe.2.dr

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\cmd.exe
Source: excel.exeMemory has grown: Private usage: 1MB later: 79MB
Source: global trafficDNS query: name: webhub365.com
Source: global trafficTCP traffic: 192.168.2.4:49736 -> 198.244.146.96:443
Source: global trafficTCP traffic: 192.168.2.4:49736 -> 198.244.146.96:443
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownDNS traffic detected: queries for: webhub365.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.aadrm.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.cortana.ai
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.office.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.onedrive.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://augloop.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cdn.entity.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://clients.config.office.net/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://config.edge.skype.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cortana.ai
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cortana.ai/api
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://cr.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dev.cortana.ai
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://devnull.onenote.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://directory.services.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://graph.windows.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://graph.windows.net/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://lifecycle.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://login.windows.local
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://management.azure.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://management.azure.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://messaging.office.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ncus.contentsync.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://officeapps.live.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://onedrive.live.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://outlook.office.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://outlook.office365.com/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://settings.outlook.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://staging.cortana.ai
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://tasks.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://wus2.contentsync.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownHTTPS traffic detected: 198.244.146.96:443 -> 192.168.2.4:49736 version: TLS 1.2

E-Banking Fraud:

barindex
Checks if browser processes are runningShow sources
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: GetModuleFileNameW,PathFindFileNameW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,StrStrIW,_wcsicmp,_wcsicmp,StrCmpICW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp, IEXPLORE.EXE
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: GetModuleFileNameW,PathFindFileNameW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,StrStrIW,_wcsicmp,_wcsicmp,StrCmpICW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp, microsoftedge.exe
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: GetModuleFileNameW,PathFindFileNameW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,StrStrIW,_wcsicmp,_wcsicmp,StrCmpICW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp, microsoftedgecp.exe
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: GetModuleFileNameW,PathFindFileNameW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,StrStrIW,_wcsicmp,_wcsicmp,StrCmpICW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp, microsoftedgesh.exe

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable Editing" and then click "Enable Content". Sheet1 before,2,9,2,sheet i 'I Ready O Type her
Source: Screenshot number: 4Screenshot OCR: Enable Content". Sheet1 before,2,9,2,sheet i 'I Ready O Type here to search Ki E a a g xg P
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: document-47-2637.xlsInitial sample: CALL
Found abnormal large hidden Excel 4.0 Macro sheetShow sources
Source: document-47-2637.xlsInitial sample: Sheet size: 14533
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01156EB1
Source: Joe Sandbox ViewDropped File: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe 2D2EAD13B2796AD58D070DC1FD36961866F25E1E436661C760A879EAC35982F9
Source: classification engineClassification label: mal84.bank.expl.evad.winXLS@6/9@1/1
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6172:120:WilError_01
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{1744F764-0162-4D2E-BD56-CB64A386D406} - OProcSessId.datJump to behavior
Source: document-47-2637.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: document-47-2637.xlsVirustotal: Detection: 26%
Source: document-47-2637.xlsMetadefender: Detection: 22%
Source: document-47-2637.xlsReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe 'C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe' C:\aZ8ThU0Y\ERdZMUem GdPT AuMr7
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe 'C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe' C:\aZ8ThU0Y\ERdZMUem GdPT AuMr7
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: Binary string: extexport.pdbGCTL source: nnAzot.exe, 00000005.00000000.666770148.0000000001151000.00000020.00020000.sdmp, nnAzot.exe.2.dr
Source: Binary string: extexport.pdb source: nnAzot.exe, nnAzot.exe.2.dr
Source: document-47-2637.xlsInitial sample: OLE indicators vbamacros = False
Source: document-47-2637.xlsInitial sample: OLE indicators encrypted = True
Source: nnAzot.exe.2.drStatic PE information: 0xA55DB0F5 [Fri Nov 30 21:19:49 2057 UTC]
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01159865 push ecx; ret
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeJump to dropped file
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01153367 LoadLibraryExW,LoadLibraryExW,LoadLibraryExW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetLastError,
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: document-47-2637.xlsStream path 'Workbook' entropy: 7.97723236264 (max. 8.0)

Malware Analysis System Evasion:

barindex
Contains functionality to compare user and computer (likely to detect sandboxes)Show sources
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: GetModuleFileNameW,PathFindFileNameW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,StrStrIW,_wcsicmp,_wcsicmp,StrCmpICW,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,_wcsicmp,
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01156EB1 GetCurrentThreadId,IsDebuggerPresent,OutputDebugStringW,
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01159910 GetProcessHeap,HeapFree,
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01159380 SetUnhandledExceptionFilter,
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_011596D1 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01159583 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,
Source: C:\aZ8ThU0Y\ERdZMUem\nnAzot.exeCode function: 5_2_01158F20 GetVersionExA,

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting2Application Shimming1Process Injection2Masquerading1OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel12Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsApplication Shimming1Disable or Modify Tools1LSASS MemorySecurity Software Discovery12Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Extra Window Memory Injection1Process Injection2Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Scripting2NTDSFile and Directory Discovery1Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information11LSA SecretsSystem Information Discovery4SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonTimestomp1Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup ItemsExtra Window Memory Injection1DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
document-47-2637.xls26%VirustotalBrowse
document-47-2637.xls23%MetadefenderBrowse
document-47-2637.xls15%ReversingLabsDocument-Office.Trojan.Heuristic

Dropped Files

SourceDetectionScannerLabelLink
C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe0%MetadefenderBrowse
C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe0%ReversingLabs

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
webhub365.com0%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%VirustotalBrowse
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
webhub365.com
198.244.146.96
truefalseunknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
    high
    https://login.microsoftonline.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
      high
      https://shell.suite.office.com:14439C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
          high
          https://autodiscover-s.outlook.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
              high
              https://cdn.entity.9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                    high
                    https://powerlift.acompli.net9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v19C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                      high
                      https://cortana.ai9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                high
                                https://api.aadrm.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                      high
                                      https://cr.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControl9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                          high
                                          https://graph.ppe.windows.net9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                            high
                                            https://res.getmicrosoftkey.com/api/redemptionevents9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            unknown
                                            https://powerlift-frontdesk.acompli.net9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            unknown
                                            https://tasks.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                              high
                                              https://officeci.azurewebsites.net/api/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                              • 0%, Virustotal, Browse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://sr.outlook.office.net/ws/speech/recognize/assistant/work9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                high
                                                https://store.office.cn/addinstemplate9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://outlook.office.com/autosuggest/api/v1/init?cvid=9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                  high
                                                  https://globaldisco.crm.dynamics.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                    high
                                                    https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                      high
                                                      https://store.officeppe.com/addinstemplate9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://dev0-api.acompli.net/autodetect9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://www.odwebp.svc.ms9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://api.powerbi.com/v1.0/myorg/groups9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                        high
                                                        https://web.microsoftstream.com/video/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                          high
                                                          https://graph.windows.net9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                            high
                                                            https://dataservice.o365filtering.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://officesetup.getmicrosoftkey.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://analysis.windows.net/powerbi/api9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                              high
                                                              https://prod-global-autodetect.acompli.net/autodetect9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://outlook.office365.com/autodiscover/autodiscover.json9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                high
                                                                https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                  high
                                                                  https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                    high
                                                                    https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                      high
                                                                      https://ncus.contentsync.9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      unknown
                                                                      https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                        high
                                                                        https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                          high
                                                                          http://weather.service.msn.com/data.aspx9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                            high
                                                                            https://apis.live.net/v5.0/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                              high
                                                                              https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                high
                                                                                https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                  high
                                                                                  https://management.azure.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                    high
                                                                                    https://wus2.contentsync.9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    unknown
                                                                                    https://incidents.diagnostics.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                      high
                                                                                      https://clients.config.office.net/user/v1.0/ios9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                        high
                                                                                        https://insertmedia.bing.office.net/odc/insertmedia9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                          high
                                                                                          https://o365auditrealtimeingestion.manage.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                            high
                                                                                            https://outlook.office365.com/api/v1.0/me/Activities9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                              high
                                                                                              https://api.office.net9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                high
                                                                                                https://incidents.diagnosticssdf.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                  high
                                                                                                  https://asgsmsproxyapi.azurewebsites.net/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                  • 0%, Virustotal, Browse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://clients.config.office.net/user/v1.0/android/policies9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                    high
                                                                                                    https://entitlement.diagnostics.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                      high
                                                                                                      https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                        high
                                                                                                        https://outlook.office.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                          high
                                                                                                          https://storage.live.com/clientlogs/uploadlocation9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                            high
                                                                                                            https://templatelogging.office.com/client/log9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office365.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                high
                                                                                                                https://webshell.suite.office.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                  high
                                                                                                                  https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                    high
                                                                                                                    https://management.azure.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                      high
                                                                                                                      https://login.windows.net/common/oauth2/authorize9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                        high
                                                                                                                        https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        unknown
                                                                                                                        https://graph.windows.net/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                          high
                                                                                                                          https://api.powerbi.com/beta/myorg/imports9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                            high
                                                                                                                            https://devnull.onenote.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                              high
                                                                                                                              https://ncus.pagecontentsync.9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                high
                                                                                                                                https://messaging.office.com/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://augloop.office.com/v29C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://skyapi.live.net/Activity/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        unknown
                                                                                                                                        https://clients.config.office.net/user/v1.0/mac9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://dataservice.o365filtering.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://api.cortana.ai9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://onedrive.live.com9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://ovisualuiapp.azurewebsites.net/pbiagave/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            https://visio.uservoice.com/forums/368202-visio-on-devices9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://directory.services.9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://login.windows-ppe.net/common/oauth2/authorize9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://staging.cortana.ai9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://loki.delve.office.com/api/v1/configuration/officewin32/9C265DD6-ED91-4AAE-9C37-56E57236292F.0.drfalse
                                                                                                                                                  high

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  198.244.146.96
                                                                                                                                                  webhub365.comUnited States
                                                                                                                                                  18630RIDLEYSD-NETUSfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:432926
                                                                                                                                                  Start date:10.06.2021
                                                                                                                                                  Start time:23:38:13
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 4m 51s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:light
                                                                                                                                                  Sample file name:document-47-2637.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:19
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal84.bank.expl.evad.winXLS@6/9@1/1
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:
                                                                                                                                                  • Successful, ratio: 100% (good quality ratio 86.3%)
                                                                                                                                                  • Quality average: 69.6%
                                                                                                                                                  • Quality standard deviation: 34.3%
                                                                                                                                                  HCA Information:Failed
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer
                                                                                                                                                  Warnings:
                                                                                                                                                  Show All
                                                                                                                                                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 204.79.197.200, 13.107.21.200, 52.147.198.201, 23.211.6.115, 52.109.76.68, 52.109.12.22, 52.109.8.25, 40.88.32.150, 20.50.102.62, 20.54.104.15, 20.54.7.98, 20.54.26.129, 13.107.4.50, 20.82.210.154, 92.122.213.194, 92.122.213.247
                                                                                                                                                  • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, a1449.dscg2.akamai.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, e12564.dspb.akamaiedge.net, skypedataprdcoleus15.cloudapp.net, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, elasticShed.au.au-msedge.net, img-prod-cms-rt-microsoft-com.akamaized.net, au-bg-shim.trafficmanager.net, www.bing.com, Edge-Prod-FRAr4a.env.au.au-msedge.net, dual-a-0001.a-msedge.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, ctldl.windowsupdate.com, c-0001.c-msedge.net, consumerrp-displaycatalog-aks2aks-europe.md.mp.microsoft.com.akadns.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, afdap.au.au-msedge.net, skypedataprdcoleus16.cloudapp.net, ris.api.iris.microsoft.com, au.au-msedge.net, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, au.c-0001.c-msedge.net, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net, neu-consumerrp-displaycatalog-aks2aks-europe.md.mp.microsoft.com.akadns.net
                                                                                                                                                  • Not all processes where analyzed, report is missing behavior information

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  198.244.146.96document-47-2637.xlsGet hashmaliciousBrowse

                                                                                                                                                    Domains

                                                                                                                                                    No context

                                                                                                                                                    ASN

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    RIDLEYSD-NETUSdocument-47-2637.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96

                                                                                                                                                    JA3 Fingerprints

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    37f463bf4616ecd445d4a1937da06e19Fax_Doc#01_5.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    wa71myDkbQ.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    Current-Status-062021-81197.xlsbGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    logo.png.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    3F97s4aQjB.xlsxGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    WcCEh3daIE.xlsGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    ATT00005.htmGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    kxjeAvsg1v.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    VSA75RUmYZ.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    iX22xMeXIc.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    QWkt5w3cO2.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    #U260e#Ufe0f Zeppelin.com AudioMessage_259-55.HTMGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    vTtOheCXBQ.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    6b6zVfqxbk.xlsbGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    Check 57549.HtmlGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    audit-78958169.xlsbGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    Docc.htmlGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    askinstall39.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    Lista e porosive.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96
                                                                                                                                                    askinstall39.exeGet hashmaliciousBrowse
                                                                                                                                                    • 198.244.146.96

                                                                                                                                                    Dropped Files

                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                    C:\aZ8ThU0Y\ERdZMUem\nnAzot.exedocument-37-1849.xlsGet hashmaliciousBrowse

                                                                                                                                                      Created / dropped Files

                                                                                                                                                      C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9C265DD6-ED91-4AAE-9C37-56E57236292F
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):134922
                                                                                                                                                      Entropy (8bit):5.369107251625446
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:1536:KcQIKNEeBXA3gBwlpQ9DQW+z7534ZliKWXboOilX5ENLWME9:aEQ9DQW+ziXOe
                                                                                                                                                      MD5:4885913667B0E212E6E83C9B74AF771A
                                                                                                                                                      SHA1:EFFDDE591047639F3DCF4034807D9F37A35426FE
                                                                                                                                                      SHA-256:59756C811635EBF4C1F1794D57FC4A758E1A7A93DA0F74FDCC66C1C83AE0ABAC
                                                                                                                                                      SHA-512:ACF822176355AAFEF2A04265976B9BC65BCEC067604B359FD50B468112E85B7EB68BA17BF1EAC626D7F78B08DE190D0CE6474136F9DDF84A9BA2F2B39C245D65
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-06-10T21:39:04">.. Build: 16.0.14209.30527-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                      C:\Users\user\AppData\Local\Temp\3FA40000
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:data
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):68601
                                                                                                                                                      Entropy (8bit):7.6095013473066455
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:768:5X3vegIg9kOKLUwxZi4IB5/vAVk/ViuHpc2HoM3DFZXHHHHHHHHHLGAX4MOw+j8j:rkNLPHqvAk/Vi6+YDT7Hbc8hxCCVl/
                                                                                                                                                      MD5:9F3996ECBC98180FD2BCFE840C41E4CA
                                                                                                                                                      SHA1:30F402A14E8F22F3E9B72DA06E2419537E511281
                                                                                                                                                      SHA-256:CCA5AA32910672FE42CB13FF0207E8E15602E3FF67D3C29044221C8718331128
                                                                                                                                                      SHA-512:7B3BFD8DD34674EC9E988A5EDB4FB4C5028C72C6862A634BE362A56F6F86AAD3799FFA4FB088649EC24CFE57188A1CF7E5C16BD17B1FAC599146C05369797A9A
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: .TKo.0.....0t.l.;.....>.].u?...X.^..6....4} .W..[6.=H.....m.1......D4.U../z....)...5...k$q>.v2.[G...z1...IIj@....#..d.L..A-a...dr&U..}ns....%.....j.7N.E\..b..h..BP.r/&............^.p.n]u..{h0...u._.D.z+....r&.....o..u...)..}...0Iq..B...;.*.+...9..8<.T.$...?$..Y..s.P.....:..AW2g..I]....?kd..+zD&.CY..gZiF.).-...uC:.<@B.''n./7.{.N.T,.....o....m.M!.......K..t...S6...}..S..?....7.z....t........PK..........!...<............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................MO.0...H.......BKwAH.
                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 17:12:41 2019, mtime=Thu Jun 10 20:39:07 2021, atime=Thu Jun 10 20:39:06 2021, length=12288, window=hide
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):904
                                                                                                                                                      Entropy (8bit):4.672568751401007
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:12:8oSCXUVduCH2KOeLR4miS68+WrjAZ/DYbDJp5SeuSeL44t2Y+xIBjKZm:85i1S1AZbcDJpP7aB6m
                                                                                                                                                      MD5:CB5861A7C65B698B00B963BDB3A65EAE
                                                                                                                                                      SHA1:30BD2B243AA0913959069D2B7E81E0631BCE55B7
                                                                                                                                                      SHA-256:11D2C94BA62AD8C8224DC0C70E330801DA0020DE457F2180FF905886F5EE79A9
                                                                                                                                                      SHA-512:632645EBBCB2F6B0CE3F46EF41DC8CD4E71AD18704BE52E47B33CE5B0F94C89053BD3A4BDAFBFBDF68A48F8BAB4952A725FEC40CBBE21025F551D49086AB4D3A
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: L..................F.............-....U.A^...%Q.A^...0......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R.....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q|<..user.<.......N...R.....#J......................Z.j.o.n.e.s.....~.1......R...Desktop.h.......N...R......Y..............>.....v..D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......123716...........!a..%.H.VZAj...m<...............!a..%.H.VZAj...m<..........................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-47-2637.LNK
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 06:35:53 2020, mtime=Thu Jun 10 20:39:07 2021, atime=Thu Jun 10 20:39:07 2021, length=92672, window=hide
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):2170
                                                                                                                                                      Entropy (8bit):4.721481944923777
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:24:8MyEmiQGNAobv1DJpf7aB6myMyEmiQGNAobv1DJpf7aB6m:8Mgi1Go7PQB6pMgi1Go7PQB6
                                                                                                                                                      MD5:5940923A2A431724DABE37F3633871D0
                                                                                                                                                      SHA1:2509A2D6150538B6B238C22023F6A4C1CAD3BCF6
                                                                                                                                                      SHA-256:AD29413158F192C2C3425D01B987D4B547FC1F2CE05F1C97AF92962DB2F5279B
                                                                                                                                                      SHA-512:481B7908EFDD5174A8FBA30AD8AC57D77F2789DBEEE832EBA99CF834A515E189DF36E5260442671E28088A0C91668D82A25BBDB936E467163BF5C2355B087726
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: L..................F.... ...ig.S....W.Z.A^..W.Z.A^...j...........................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...R.....................:......;..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Q|<..user.<.......N...R.....#J......................Z.j.o.n.e.s.....~.1.....>Q}<..Desktop.h.......N...R......Y..............>.......1.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....v.2..h...R. .DOCUME~1.XLS..Z......>Q{<.R......V.....................m..d.o.c.u.m.e.n.t.-.4.7.-.2.6.3.7...x.l.s.......Z...............-.......Y...........>.S......C:\Users\user\Desktop\document-47-2637.xls..+.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.d.o.c.u.m.e.n.t.-.4.7.-.2.6.3.7...x.l.s.........:..,.LB.)...As...`.......X.......123716...........!a..%.H.VZAj...................!a..%.H.VZAj..............................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.
                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):101
                                                                                                                                                      Entropy (8bit):4.781102818999889
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3:oyBVomMY9LRkKSd6YCZELRkKSd6YCmMY9LRkKSd6YCv:dj6Y9LaJdzgELaJdzUY9LaJdzs
                                                                                                                                                      MD5:CC574425794FB97F59C2DC249939493A
                                                                                                                                                      SHA1:8CA2DFD4C2535E0FFEB160319D2CD079758B7F8D
                                                                                                                                                      SHA-256:1D977854F9C0DDF7462B6991CA2B6026C4FFCAF52F158A2C7B81B8FBEE5E35F0
                                                                                                                                                      SHA-512:6C9C7CAFA742354DB174653D4C1CF9521AC10C67177FB2E26A85AE1267F1A45094BD1F1AE3C0B53836D5210F6083906F17C26A28A197D0CCF2F76D7447272E43
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: Desktop.LNK=0..[xls]..document-47-2637.LNK=0..document-47-2637.LNK=0..[xls]..document-47-2637.LNK=0..
                                                                                                                                                      C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):22
                                                                                                                                                      Entropy (8bit):2.9808259362290785
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                      MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                      SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                      SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                      SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:high, very likely benign file
                                                                                                                                                      Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                      C:\Users\user\Desktop\00B40000
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):117445
                                                                                                                                                      Entropy (8bit):7.924149420001192
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3072:UfgagkFMp1lsZaVV6zBiA2AiuLKli2LKefgag2:0xFCLPVV+BiA2Ai0uicDd
                                                                                                                                                      MD5:40F42EC6AF84151ABC504FB591A42BD4
                                                                                                                                                      SHA1:13504B444A7127A12C99F75D389D8BE78F607811
                                                                                                                                                      SHA-256:4342F4D6263F70D2BEC42C6D8CC1E6F23811C416265FBBF688D8D2F1AA2C5BFF
                                                                                                                                                      SHA-512:52B8B4DACF29DDA70A1C63FA16F7B6D9363DC852FC9D2C4BD381DBB8C6694A131CD5D19697B45293BD5E07CA399A422EED48FDD48D7B0177C1398086F9344451
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: ........T8........../.............+.F|..14.l.0..e.i...t...y...$......O~..m.........T8........../.6...........+.F|..14.l.0..e.i...t...y...$......O~..m............f....\.p...'...0...u.........0.... d..o3......+...#uN'.wd..^.J.9v!..z.+....+k,l.%<....>t...'..........h...T:.x..5..B.....a....j....=....]......O.....6..................!....Nr=.......1.[...9.F^....@.........].".....................^1...V...D?..vQ.....Y...........O.1......(G.Z.!.AP[..:=9.LY;....~].1....{.t.D9..j...y..z.`t.......;.1...[sN5..)......2.H\........k....1.....4=(R...x.......`.0.,..g.61.*.B.y/.v\.2^<..[!.1......Y..........O.O..(.1......*)..U.c-..3.nxt"..I...p1....w!0..@....].*....:s.,|O.T.>1.....4L.0{....s.e.h.)}....O.$}.1...'.OA<Z.....E...K....._xL...1....L...[..j.qm..^..1...O....a#.1.....!...^..(.1.FP.;...........1....dK.;.....B.r....wb....9.b.1...=..i.x.Q.x:.....(./.. L^..1......>Z..I.....Z.s...x[.}..vX..1...5..}%.gY...$.....:.....'1..R.1....JX!............c.3.,.*.m+..5.1...
                                                                                                                                                      C:\Users\user\Desktop\4F850000
                                                                                                                                                      Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                      Category:modified
                                                                                                                                                      Size (bytes):99740
                                                                                                                                                      Entropy (8bit):7.929925379753235
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:1536:n6hF9uwbh8+yV1jngo7mfk9mjhjAefouRA+VkV43RBVCOG6hFouT:nWuihUJngIQjAehZVkqbsjuT
                                                                                                                                                      MD5:BA34233274FF56530F9141B9F5B5FF43
                                                                                                                                                      SHA1:974F24CCD4BEE89423AF7B4ABB09537605AFD1A3
                                                                                                                                                      SHA-256:D79872EFE978946ADD8D6DD0848835F0A365B69F588C0FA52F744B88FC1D10F7
                                                                                                                                                      SHA-512:A27822A9DE321CE36E0BA71AEF683CCF429F43B9DBA216E086EBF186A8A037AE2DA45C0E97CCA5F6C240FE43DF173668DCA673CA6957F371C8BA42653461B8FF
                                                                                                                                                      Malicious:false
                                                                                                                                                      Reputation:low
                                                                                                                                                      Preview: ........T8........../...........X.-...f..7.........E..54...rI.89B\.".....Q+........T8........../.6.........X.-...f..7.........E..54...rI.89B\.".....Q+..........ut....\.p.!...8em.....W..4.W?..[S`..L.b%A...sH/.#.;.*8.Z..^.'.y..;."C["....mE....g...o_../T...h4)N.g..6....`...^MJ..#B.....a.........=...........&....9w....Gh.....f..........zT=....a.5..i...u.y.i@..........".........g.....Y.....\1.....S.b2#J...A.k.t..\.?P.tx...o.1...]...k..U.-.).%4.@a...*/..D..1... ~v....^|]..4.2b....x..3..1....uR....Z.A.T..=..Q.J."[.*Lf..1....u....NR....!.-..-.".8.uH7.XQ~1.*.x'..v..lU.*c\...s..O.'l.0...{.".2:...j<6w1.....DI....R.T..5.K....X.|5..C<..1....A@..."..|....r.$6T..(Hk[v3&|.1......{.=.P.Od.QY.....S.....^`..1....W8.[..?K..'.)..(...Q..}1..... ....g.H...1....r.....',..1....*.2.Z..\..jw.w..".."..Yu.0K.1.........l'%...,..z.L../N@>.C.~bW1........G.._.e.7|.g.c:c.Y='....,1......1.....p^.7d}.@(.....&....1....M..t.d.".p^[+.k.2...;..b...1.....DQ q...,i...G_.[3.|.7....1...
                                                                                                                                                      C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe
                                                                                                                                                      Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):44544
                                                                                                                                                      Entropy (8bit):6.190125674423799
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:768:AAMBmP3+XxLKZ/XMsQt1TZPImKXPXtE6MayeDkX0PmfkPchaDPfsRi7P4QG64iuU:UsP3+XxLKZ/XMsQt1TZPImKXPdfDkXSZ
                                                                                                                                                      MD5:CE639EB63B7C1C1EC94651B65CCEC383
                                                                                                                                                      SHA1:B92544ED405C33F2DB64A0BCA41646CB712E246B
                                                                                                                                                      SHA-256:2D2EAD13B2796AD58D070DC1FD36961866F25E1E436661C760A879EAC35982F9
                                                                                                                                                      SHA-512:66E841C9DF0D17AB1A1C866A96769AD0F4F8329C94EDB2917648FB4FF76E7A47C479A60A0D05293136843EC5BA938B0CEB96190BEE01AE049A467BDA45CB4566
                                                                                                                                                      Malicious:true
                                                                                                                                                      Antivirus:
                                                                                                                                                      • Antivirus: Metadefender, Detection: 0%, Browse
                                                                                                                                                      • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                      Joe Sandbox View:
                                                                                                                                                      • Filename: document-37-1849.xls, Detection: malicious, Browse
                                                                                                                                                      Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......h.\D,.2.,.2.,.2.C.1.(.2.C.6.9.2.C.7./.2.C.3.=.2.,.3...2.C.;.:.2.C...-.2.C.0.-.2.Rich,.2.........PE..L.....]......................*......@.............@.......................................@...... ...................................................................+..T............................................................................text.............................. ..`.data...h...........................@....idata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................

                                                                                                                                                      Static File Info

                                                                                                                                                      General

                                                                                                                                                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Windows User, Last Saved By: Windows User, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Jun 2 14:40:34 2021, Last Saved Time/Date: Wed Jun 2 14:40:36 2021, Security: 1
                                                                                                                                                      Entropy (8bit):7.59086745125602
                                                                                                                                                      TrID:
                                                                                                                                                      • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                      • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                      File name:document-47-2637.xls
                                                                                                                                                      File size:92165
                                                                                                                                                      MD5:92dcc47a1a044fc3a2328ec6eef3918b
                                                                                                                                                      SHA1:6f9266a6c0b702cbaa0a3583df5c8cd1357eae35
                                                                                                                                                      SHA256:ac4b99079b1ceb11db593097e421de9d9092765feedc23a3ab8ef912b292c988
                                                                                                                                                      SHA512:fcd4b7c0a4e0f785604f40e0a9a4690e9b642223ee63088c6c4acfc262a18f5a79c77ab82498b422b229eaecc9a2e745b7e455c43ad2a85794e7adbac6b9bafd
                                                                                                                                                      SSDEEP:1536:Lc2ZSmXWCQnp2c90Hg+j8z3kVfKIDVzoFGUslIB54N+wl8MYBzaVt4J5aukGqu:LXZxXTQ8hHgNQNeF3V4NvuhBzaV+J5a+
                                                                                                                                                      File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                      File Icon

                                                                                                                                                      Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                      Static OLE Info

                                                                                                                                                      General

                                                                                                                                                      Document Type:OLE
                                                                                                                                                      Number of OLE Files:1

                                                                                                                                                      OLE File "document-47-2637.xls"

                                                                                                                                                      Indicators

                                                                                                                                                      Has Summary Info:True
                                                                                                                                                      Application Name:Microsoft Excel
                                                                                                                                                      Encrypted Document:True
                                                                                                                                                      Contains Word Document Stream:False
                                                                                                                                                      Contains Workbook/Book Stream:True
                                                                                                                                                      Contains PowerPoint Document Stream:False
                                                                                                                                                      Contains Visio Document Stream:False
                                                                                                                                                      Contains ObjectPool Stream:
                                                                                                                                                      Flash Objects Count:
                                                                                                                                                      Contains VBA Macros:False

                                                                                                                                                      Summary

                                                                                                                                                      Code Page:1252
                                                                                                                                                      Author:Windows User
                                                                                                                                                      Last Saved By:Windows User
                                                                                                                                                      Create Time:2021-06-02 13:40:34
                                                                                                                                                      Last Saved Time:2021-06-02 13:40:36
                                                                                                                                                      Creating Application:Microsoft Excel
                                                                                                                                                      Security:1

                                                                                                                                                      Document Summary

                                                                                                                                                      Document Code Page:1252
                                                                                                                                                      Thumbnail Scaling Desired:False
                                                                                                                                                      Company:
                                                                                                                                                      Contains Dirty Links:False
                                                                                                                                                      Shared Document:False
                                                                                                                                                      Changed Hyperlinks:False
                                                                                                                                                      Application Version:983040

                                                                                                                                                      Streams

                                                                                                                                                      Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                      General
                                                                                                                                                      Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                      File Type:data
                                                                                                                                                      Stream Size:4096
                                                                                                                                                      Entropy:0.308022095077
                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . i . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . . . . . . . .
                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 ec 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 a5 00 00 00
                                                                                                                                                      Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                      General
                                                                                                                                                      Stream Path:\x5SummaryInformation
                                                                                                                                                      File Type:data
                                                                                                                                                      Stream Size:4096
                                                                                                                                                      Entropy:0.316312415339
                                                                                                                                                      Base64 Encoded:False
                                                                                                                                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . W i n d o w s U s e r . . . . . . . . . . . . W i n d o w s U s e r . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . . . . W . . @ . . . . . . . . W . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 b0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 60 00 00 00 12 00 00 00 78 00 00 00 0c 00 00 00 90 00 00 00 0d 00 00 00 9c 00 00 00 13 00 00 00 a8 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 10 00 00 00
                                                                                                                                                      Stream Path: Workbook, File Type: Applesoft BASIC program data, first line number 16, Stream Size: 81910
                                                                                                                                                      General
                                                                                                                                                      Stream Path:Workbook
                                                                                                                                                      File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                      Stream Size:81910
                                                                                                                                                      Entropy:7.97723236264
                                                                                                                                                      Base64 Encoded:True
                                                                                                                                                      Data ASCII:. . . . . . . . T 8 . . . . . . . . . . / . 6 . . . . . . . . j . . . _ . W > N . B . . [ . . . . . . D . G . . . . 9 s < D l . o . b . 3 . ^ K W . ~ . U . . . . . . . . . . . h . . . . . \\ . p . i . . v . / . . . . B . 7 r . n . S . $ . 4 f . 7 . U . . e . Y k . . . L Q . . o N . . . . $ a . 7 Q . . . u . s . X U . ^ . . . . . . K . C d . . . l . ? . & . C . . . . . . . . v . . . . . 4 ; / . . . . 6 4 = . . . . . . B . . . . I a . . . . D . . . . = . . . . # . c . . . . h . . . . . s R . . . . . . . . . .
                                                                                                                                                      Data Raw:09 08 10 00 00 06 05 00 54 38 cd 07 c1 c0 01 00 06 07 00 00 2f 00 36 00 01 00 01 00 01 00 02 6a df 82 8f 5f f7 57 3e 4e 18 42 a0 92 5b 1d e8 95 bd ea b2 44 89 47 13 ad c8 06 39 73 3c 44 6c 0c 6f cd 62 dc 33 7f 5e 4b 57 2e 7e e6 55 cf e1 00 02 00 b0 04 c1 00 02 00 68 a6 e2 00 00 00 5c 00 70 00 69 b6 c9 76 af 2f 14 b1 ed d6 42 f4 37 72 10 6e cc 53 fc 24 ef 34 66 18 37 82 55 80 f5 65

                                                                                                                                                      Macro 4.0 Code

                                                                                                                                                      ,!,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,l,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,?,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,L,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,!,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,x,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,mxUXwaSU= $N$84&$X$102&$K$324&$C$460&$M$83&$K$324&$N$447&$I$336&$X$102&$K$324&$X$82&$M$83&$U$271&$X$102&$V$246&$X$462,,,,,,,,,,,,,,,,,,,,,,id9nB5my= $W$367,,,,,,,,,,,,,,,,,,,,,,=$F$105(),,,,,,,,,,,,,,,,,,,,,,=RUN($K$351),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,M,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,s,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,mxUXwaSU= $H$409&$H$409&$N$84&$N$84&$N$84&$N$84&$H$409,,,,,,,,,,,,,,,,,,,,,,id9nB5my= $Y$71,,,,,,,,,,,,,,,,,,,,,,=$F$105(),,,,,,,,,,,,,,,,,,,,,,=RUN($I$385),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,3,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\,,,,,,,,,,,,,,,,,,,,,,,Z,,,,,,,,,,,,,,,,,,,,,,,,,,,,,c,,,,,,,,,,,t,,,,,,,,,,,,,,,,,,,,,,,C,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,!,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,r,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=RETURN(FORMULA.FILL(mxUXwaSU,id9nB5my))",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,d,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,q,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,/,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,F,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,I,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,n,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,6,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,E,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,mxUXwaSU= $F$204&$H$481&$K$324&$N$11&$N$11&$E$78&$I$228,,,,,,,,,,,,,,,,,,,,,,id9nB5my= $D$167,,,,,,,,,,,,,,,,,,,,,,=$F$105(),,,,,,,,,,,,,,,,,,,,,,=RUN($R$247),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,!,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

                                                                                                                                                      Network Behavior

                                                                                                                                                      Network Port Distribution

                                                                                                                                                      TCP Packets

                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                      Jun 10, 2021 23:39:07.758977890 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.814593077 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.814827919 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.815645933 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.870667934 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.871705055 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.871733904 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.871757030 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.871773958 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.871809959 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.871840000 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.871850014 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.875941038 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.876013041 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.889168978 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.948826075 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.949002028 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:07.949609995 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:39:08.047010899 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:08.129976034 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:08.130068064 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:40:23.176129103 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:23.176176071 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:23.176424026 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:40:54.416600943 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:40:54.416651011 CEST49736443192.168.2.4198.244.146.96
                                                                                                                                                      Jun 10, 2021 23:40:54.471982002 CEST44349736198.244.146.96192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:54.472306013 CEST49736443192.168.2.4198.244.146.96

                                                                                                                                                      UDP Packets

                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                      Jun 10, 2021 23:38:52.967205048 CEST5453153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:53.029515982 CEST53545318.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:53.091182947 CEST4971453192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:53.141277075 CEST53497148.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:53.899147034 CEST5802853192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:53.949414968 CEST53580288.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:55.018290997 CEST5309753192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:55.081427097 CEST53530978.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:55.103068113 CEST4925753192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:55.157798052 CEST53492578.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:55.968286991 CEST6238953192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:56.028430939 CEST53623898.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:38:57.970202923 CEST4991053192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:38:58.023649931 CEST53499108.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:03.437601089 CEST5585453192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:03.490520000 CEST53558548.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:04.416615009 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:04.516530991 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:04.961870909 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:05.033673048 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:05.919765949 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:05.969824076 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:06.014739037 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:06.088699102 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.061800003 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:07.120498896 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:07.696746111 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:07.756989002 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:08.098918915 CEST5172653192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:08.149171114 CEST53517268.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:08.868616104 CEST5679453192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:08.932203054 CEST53567948.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:09.108942032 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:09.161076069 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:09.714025974 CEST5653453192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:09.767750025 CEST53565348.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:10.686068058 CEST5662753192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:10.736035109 CEST53566278.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:11.658345938 CEST5662153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:11.717427969 CEST53566218.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:12.518906116 CEST6311653192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:12.569057941 CEST53631168.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:13.204545021 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:13.263603926 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:13.651770115 CEST6407853192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:13.710468054 CEST53640788.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:16.330972910 CEST6480153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:16.381169081 CEST53648018.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:17.101145983 CEST6172153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:17.154200077 CEST53617218.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:17.867068052 CEST5125553192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:17.917368889 CEST53512558.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:18.687213898 CEST6152253192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:18.740266085 CEST53615228.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:19.499142885 CEST5233753192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:19.560852051 CEST53523378.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:22.964379072 CEST5504653192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:23.028353930 CEST53550468.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:37.752346039 CEST4961253192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:37.890376091 CEST53496128.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:38.459012032 CEST4928553192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:38.692450047 CEST53492858.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:38.839421988 CEST5060153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:38.910661936 CEST53506018.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:39.287220001 CEST6087553192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:39.348902941 CEST53608758.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:39.869817972 CEST5644853192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:39.931515932 CEST53564488.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:40.743299961 CEST5917253192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:40.804954052 CEST53591728.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:41.466109991 CEST6242053192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:41.528162956 CEST53624208.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:42.488322020 CEST6057953192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:42.548993111 CEST53605798.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:43.587331057 CEST5018353192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:43.649781942 CEST53501838.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:44.450370073 CEST6153153192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:44.510262012 CEST53615318.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:45.030211926 CEST4922853192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:45.091671944 CEST53492288.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:48.179131031 CEST5979453192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:48.229815960 CEST53597948.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:58.221915960 CEST5591653192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:58.278551102 CEST5275253192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:39:58.300194025 CEST53559168.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:39:58.347940922 CEST53527528.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:00.832252026 CEST6054253192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:40:00.892834902 CEST53605428.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:34.100034952 CEST6068953192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:40:34.169770002 CEST53606898.8.8.8192.168.2.4
                                                                                                                                                      Jun 10, 2021 23:40:35.246970892 CEST6420653192.168.2.48.8.8.8
                                                                                                                                                      Jun 10, 2021 23:40:35.305468082 CEST53642068.8.8.8192.168.2.4

                                                                                                                                                      DNS Queries

                                                                                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                      Jun 10, 2021 23:39:07.696746111 CEST192.168.2.48.8.8.80x412Standard query (0)webhub365.comA (IP address)IN (0x0001)

                                                                                                                                                      DNS Answers

                                                                                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                      Jun 10, 2021 23:39:07.756989002 CEST8.8.8.8192.168.2.40x412No error (0)webhub365.com198.244.146.96A (IP address)IN (0x0001)

                                                                                                                                                      HTTPS Packets

                                                                                                                                                      TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                      Jun 10, 2021 23:39:07.875941038 CEST198.244.146.96443192.168.2.449736CN=webhub365.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Tue Jun 08 19:53:43 CEST 2021 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021Mon Sep 06 19:53:43 CEST 2021 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                      CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025
                                                                                                                                                      CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Jan 20 20:14:03 CET 2021Mon Sep 30 20:14:03 CEST 2024

                                                                                                                                                      Code Manipulations

                                                                                                                                                      Statistics

                                                                                                                                                      Behavior

                                                                                                                                                      Click to jump to process

                                                                                                                                                      System Behavior

                                                                                                                                                      General

                                                                                                                                                      Start time:23:39:03
                                                                                                                                                      Start date:10/06/2021
                                                                                                                                                      Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                      Imagebase:0xfd0000
                                                                                                                                                      File size:27110184 bytes
                                                                                                                                                      MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high

                                                                                                                                                      General

                                                                                                                                                      Start time:23:39:08
                                                                                                                                                      Start date:10/06/2021
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:'C:\Windows\System32\cmd.exe' /c copy '%ProgramFiles(x86)%\Internet Explorer\ExtExport.exe' C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe
                                                                                                                                                      Imagebase:0x11d0000
                                                                                                                                                      File size:232960 bytes
                                                                                                                                                      MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high

                                                                                                                                                      General

                                                                                                                                                      Start time:23:39:08
                                                                                                                                                      Start date:10/06/2021
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff724c50000
                                                                                                                                                      File size:625664 bytes
                                                                                                                                                      MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high

                                                                                                                                                      General

                                                                                                                                                      Start time:23:39:10
                                                                                                                                                      Start date:10/06/2021
                                                                                                                                                      Path:C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:'C:\aZ8ThU0Y\ERdZMUem\nnAzot.exe' C:\aZ8ThU0Y\ERdZMUem GdPT AuMr7
                                                                                                                                                      Imagebase:0x1150000
                                                                                                                                                      File size:44544 bytes
                                                                                                                                                      MD5 hash:CE639EB63B7C1C1EC94651B65CCEC383
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Antivirus matches:
                                                                                                                                                      • Detection: 0%, Metadefender, Browse
                                                                                                                                                      • Detection: 0%, ReversingLabs
                                                                                                                                                      Reputation:low

                                                                                                                                                      Disassembly

                                                                                                                                                      Code Analysis

                                                                                                                                                      Reset < >