Loading ...

Play interactive tourEdit tour

Windows Analysis Report plan-1637276620.xlsm

Overview

General Information

Sample Name:plan-1637276620.xlsm
Analysis ID:438318
MD5:4d44784f088b8dd2ac0a6cbf2b809eab
SHA1:7d01c190b2e73c860a9aed904729c6466230bd26
SHA256:c63e0b01a696a077a5709b8aa4d4d600344fc1ddba624cbd67c6f37f271d97ac
Infos:

Most interesting Screenshot:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Excel documents contains an embedded macro which executes code when the document is opened

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 7120 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • splwow64.exe (PID: 4292 cmdline: C:\Windows\splwow64.exe 12288 MD5: 8D59B31FF375059E3C32B17BF31A76D5)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.aadrm.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.cortana.ai
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.office.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.onedrive.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://augloop.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cdn.entity.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://clients.config.office.net/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://config.edge.skype.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cortana.ai
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cortana.ai/api
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://cr.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dev.cortana.ai
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://devnull.onenote.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://directory.services.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://graph.windows.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://graph.windows.net/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://lifecycle.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://login.windows.local
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://management.azure.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://management.azure.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://messaging.office.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ncus.contentsync.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://officeapps.live.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://onedrive.live.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://outlook.office.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://outlook.office365.com/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://settings.outlook.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://staging.cortana.ai
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://tasks.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://wus2.contentsync.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: workbook.xmlBinary string: 1" sheetId="16" state="hidden" r:id="rId1"/><sheet name="Sheet" sheetId="19" r:id="rId2"/><sheet name="Sheet1" sheetId="4" r:id="rId3"/><sheet name="Sheet2" sheetId="12" r:id="rId4"/><sheet name="Sheet4" sheetId="10" state="hidden" r:id="rId5"/><sheet name="Sheet5" sheetId="11" state="hidden" r:id="rId6"/><sheet name="Sheet6" sheetId="15" state="hidden" r:id="rId7"/><sheet name="Sheet7" sheetId="14" state="hidden" r:id="rId8"/></sheets><definedNames><definedName name="_xlnm.Auto_Open">Sheet6!$AJ$9</definedName></definedNames><calcPr calcId="122211"/></workbook>
Source: classification engineClassification label: clean0.winXLSM@3/3@0/0
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{434E303B-6F37-4CC5-9FF8-9E404F84FA59} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: plan-1637276620.xlsmInitial sample: OLE zip file path = xl/media/image1.png
Source: plan-1637276620.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting1Path InterceptionProcess Injection1Masquerading1OS Credential DumpingVirtualization/Sandbox Evasion1Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsVirtualization/Sandbox Evasion1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection1Security Account ManagerSystem Information Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Scripting1NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 438318 Sample: plan-1637276620.xlsm Startdate: 22/06/2021 Architecture: WINDOWS Score: 0 5 EXCEL.EXE 20 18 2->5         started        process3 7 splwow64.exe 5->7         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
plan-1637276620.xlsm2%VirustotalBrowse

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%VirustotalBrowse
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%VirustotalBrowse
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
    high
    https://login.microsoftonline.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
      high
      https://shell.suite.office.com:14432CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
          high
          https://autodiscover-s.outlook.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
              high
              https://cdn.entity.2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                    high
                    https://powerlift.acompli.net2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v12CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                      high
                      https://cortana.ai2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                high
                                https://api.aadrm.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                      high
                                      https://cr.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControl2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                          high
                                          https://graph.ppe.windows.net2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                            high
                                            https://res.getmicrosoftkey.com/api/redemptionevents2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            unknown
                                            https://powerlift-frontdesk.acompli.net2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            • URL Reputation: safe
                                            unknown
                                            https://tasks.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                              high
                                              https://officeci.azurewebsites.net/api/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                              • 0%, Virustotal, Browse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://sr.outlook.office.net/ws/speech/recognize/assistant/work2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                high
                                                https://store.office.cn/addinstemplate2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                https://outlook.office.com/autosuggest/api/v1/init?cvid=2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                  high
                                                  https://globaldisco.crm.dynamics.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                    high
                                                    https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                      high
                                                      https://store.officeppe.com/addinstemplate2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://dev0-api.acompli.net/autodetect2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://www.odwebp.svc.ms2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://api.powerbi.com/v1.0/myorg/groups2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                        high
                                                        https://web.microsoftstream.com/video/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                          high
                                                          https://graph.windows.net2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                            high
                                                            https://dataservice.o365filtering.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://officesetup.getmicrosoftkey.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://analysis.windows.net/powerbi/api2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                              high
                                                              https://prod-global-autodetect.acompli.net/autodetect2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://outlook.office365.com/autodiscover/autodiscover.json2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                high
                                                                https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                  high
                                                                  https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                    high
                                                                    https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                      high
                                                                      https://ncus.contentsync.2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      • URL Reputation: safe
                                                                      unknown
                                                                      https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                        high
                                                                        https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                          high
                                                                          http://weather.service.msn.com/data.aspx2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                            high
                                                                            https://apis.live.net/v5.0/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                              high
                                                                              https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                high
                                                                                https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                  high
                                                                                  https://management.azure.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                    high
                                                                                    https://wus2.contentsync.2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    • URL Reputation: safe
                                                                                    unknown
                                                                                    https://incidents.diagnostics.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                      high
                                                                                      https://clients.config.office.net/user/v1.0/ios2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                        high
                                                                                        https://insertmedia.bing.office.net/odc/insertmedia2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                          high
                                                                                          https://o365auditrealtimeingestion.manage.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                            high
                                                                                            https://outlook.office365.com/api/v1.0/me/Activities2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                              high
                                                                                              https://api.office.net2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                high
                                                                                                https://incidents.diagnosticssdf.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                  high
                                                                                                  https://asgsmsproxyapi.azurewebsites.net/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                  • 0%, Virustotal, Browse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://clients.config.office.net/user/v1.0/android/policies2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                    high
                                                                                                    https://entitlement.diagnostics.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                      high
                                                                                                      https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                        high
                                                                                                        https://outlook.office.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                          high
                                                                                                          https://storage.live.com/clientlogs/uploadlocation2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                            high
                                                                                                            https://templatelogging.office.com/client/log2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office365.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                high
                                                                                                                https://webshell.suite.office.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                  high
                                                                                                                  https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                    high
                                                                                                                    https://management.azure.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                      high
                                                                                                                      https://login.windows.net/common/oauth2/authorize2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                        high
                                                                                                                        https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        • URL Reputation: safe
                                                                                                                        unknown
                                                                                                                        https://graph.windows.net/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                          high
                                                                                                                          https://api.powerbi.com/beta/myorg/imports2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                            high
                                                                                                                            https://devnull.onenote.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                              high
                                                                                                                              https://ncus.pagecontentsync.2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                high
                                                                                                                                https://messaging.office.com/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://augloop.office.com/v22CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://skyapi.live.net/Activity/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        unknown
                                                                                                                                        https://clients.config.office.net/user/v1.0/mac2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://dataservice.o365filtering.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://api.cortana.ai2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://onedrive.live.com2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://ovisualuiapp.azurewebsites.net/pbiagave/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            https://visio.uservoice.com/forums/368202-visio-on-devices2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://directory.services.2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://login.windows-ppe.net/common/oauth2/authorize2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://staging.cortana.ai2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://loki.delve.office.com/api/v1/configuration/officewin32/2CAF7AE8-289A-4F25-868B-6D2546F9329C.0.drfalse
                                                                                                                                                  high

                                                                                                                                                  Contacted IPs

                                                                                                                                                  No contacted IP infos

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:438318
                                                                                                                                                  Start date:22.06.2021
                                                                                                                                                  Start time:13:33:24
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 4m 56s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Sample file name:plan-1637276620.xlsm
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:16
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:CLEAN
                                                                                                                                                  Classification:clean0.winXLSM@3/3@0/0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xlsm
                                                                                                                                                  Warnings:
                                                                                                                                                  Show All
                                                                                                                                                  • Max analysis timeout: 220s exceeded, the analysis took too long
                                                                                                                                                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 131.253.33.200, 13.107.22.200, 104.42.151.234, 13.88.21.125, 52.109.32.63, 52.109.8.24, 52.109.8.25, 20.82.209.183, 104.43.193.48, 20.54.104.15, 40.112.88.60, 20.54.7.98, 173.222.108.226, 173.222.108.210, 20.50.102.62, 80.67.82.211, 80.67.82.235
                                                                                                                                                  • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, prod-w.nexus.live.com.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, au-bg-shim.trafficmanager.net, www.bing.com, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, ctldl.windowsupdate.com, a767.dscg3.akamai.net, consumerrp-displaycatalog-aks2aks-europe.md.mp.microsoft.com.akadns.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, skypedataprdcolcus15.cloudapp.net, dual-a-0001.dc-msedge.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus16.cloudapp.net, skypedataprdcolwus15.cloudapp.net, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net, neu-consumerrp-displaycatalog-aks2aks-europe.md.mp.microsoft.com.akadns.net

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  TimeTypeDescription
                                                                                                                                                  13:34:24API Interceptor20x Sleep call for process: splwow64.exe modified

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  No context

                                                                                                                                                  Domains

                                                                                                                                                  No context

                                                                                                                                                  ASN

                                                                                                                                                  No context

                                                                                                                                                  JA3 Fingerprints

                                                                                                                                                  No context

                                                                                                                                                  Dropped Files

                                                                                                                                                  No context

                                                                                                                                                  Created / dropped Files

                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2CAF7AE8-289A-4F25-868B-6D2546F9329C
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):134914
                                                                                                                                                  Entropy (8bit):5.367807218977918
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:vcQIKNgeBXA3gBwlpQ9DQW+z7Y34ZliKWXboOidX5E6LWME9:vEQ9DQW+zvXO1
                                                                                                                                                  MD5:0D48EA4DD74C64C5A1C57AD28FFBCABF
                                                                                                                                                  SHA1:B1734754C9B1D84A250FA2B1D238F49707A55A17
                                                                                                                                                  SHA-256:D09E1FCDBF132DBE299FBE0909F3B446B008B32EEEAC756898747BF845C31050
                                                                                                                                                  SHA-512:A7A4531B0237FD5211DAA23F5B4747A8A8B36B93BD3F8E4C76BF6BC7AF26FC16FC1AA5EE801A298DDCAD2DC60EDD62C950A200EBE48052FB87A516CF7A004F6D
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-06-22T11:34:20">.. Build: 16.0.14221.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\DF8B976F.png
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:PNG image data, 1133 x 589, 8-bit/color RGB, non-interlaced
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):75711
                                                                                                                                                  Entropy (8bit):7.915372969602997
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:gxJQVyZEbrMj34410mHyL9c988gHhX8jCNnKfl5ncT:7br0o45GUgHhX8jC9yST
                                                                                                                                                  MD5:8296338A43942E3107802E3062AC1270
                                                                                                                                                  SHA1:46E67A586ED8A961AF7FD03140547C1CB2BAC227
                                                                                                                                                  SHA-256:BE5F61F2AE8E4C9F9ADBCE5EC33D4C01A331734FFC5818AA8E45CF60456C5ABD
                                                                                                                                                  SHA-512:C2179050A009C990CBFE6EA45E44AA6307AAC938E3EA523D31713F657E09131B07ACEBB31FC353C5A23E7D6323C4EC01736CFF092ACA1D49B58E71A07F1171AD
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: .PNG........IHDR...m...M......p......sRGB.........gAMA......a.....pHYs..........o.d....IDATx^......g......q.|.....<...'r....-^..c.If.,ffX1K.[....Z....V.LO5L..J+...z.]]u..>.==.......................Q..........(.......p.t........8.:.............................g@G........3............Q..........(.......p.t........8.:.............................g@G........3............Q..........(.......p.t......j.7ZP...:...0S....z5T........).WU=j.*.$H.B.P.)l.6Q..'.l..7..k..J.o..._....6..{C...r.|2W.[a...m.BI.?...5......D....4;B...@b.HiP.jfj}@.S9..E.*J...O..BA5.e:...q!.SP....w....(..._.,..I.|a.7+>.........A#......3v..37......w(..j...C.R..H3.f.Q....0....h~...)aM..).vQ.1..+J@Q.....Oa+...!5.e.b...V..|..d../.......vC..&..=9...n.....^6-.tRj...O..{j.e.N....o..~..^.......#!...T...C.#.>.E,[.,......E....h~B.Y./....(2.......(...`....~w#.%..R..{........N.Z....k]8>..dW..^s....U...9...W.e...]...W...i.{u.>.s.,L.>1..)....f..b..Z.nai$.Q.."...W2.......Q...G...z....Ea......
                                                                                                                                                  C:\Users\user\Desktop\~$plan-1637276620.xlsm
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):165
                                                                                                                                                  Entropy (8bit):1.6081032063576088
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3:RFXI6dtt:RJ1
                                                                                                                                                  MD5:7AB76C81182111AC93ACF915CA8331D5
                                                                                                                                                  SHA1:68B94B5D4C83A6FB415C8026AF61F3F8745E2559
                                                                                                                                                  SHA-256:6A499C020C6F82C54CD991CA52F84558C518CBD310B10623D847D878983A40EF
                                                                                                                                                  SHA-512:A09AB74DE8A70886C22FB628BDB6A2D773D31402D4E721F9EE2F8CCEE23A569342FEECF1B85C1A25183DD370D1DFFFF75317F628F9B3AA363BBB60694F5362C7
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:high, very likely benign file
                                                                                                                                                  Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

                                                                                                                                                  Static File Info

                                                                                                                                                  General

                                                                                                                                                  File type:Microsoft Excel 2007+
                                                                                                                                                  Entropy (8bit):7.835274324451968
                                                                                                                                                  TrID:
                                                                                                                                                  • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
                                                                                                                                                  • ZIP compressed archive (8000/1) 16.67%
                                                                                                                                                  File name:plan-1637276620.xlsm
                                                                                                                                                  File size:93191
                                                                                                                                                  MD5:4d44784f088b8dd2ac0a6cbf2b809eab
                                                                                                                                                  SHA1:7d01c190b2e73c860a9aed904729c6466230bd26
                                                                                                                                                  SHA256:c63e0b01a696a077a5709b8aa4d4d600344fc1ddba624cbd67c6f37f271d97ac
                                                                                                                                                  SHA512:09c221b8d32ff3a0cb092789103d54ef64b1dffa92a1cdb7047436c6d9e578ee505457d327a55f1dac5f6b2bcd934c80b025b92b50da12ecdc3187e86efa6b69
                                                                                                                                                  SSDEEP:1536:aY2xJQVyZEbrMj34410mHyL9c988gHhX8jCNnKfl5ncW3SLBT0Ca:aYRbr0o45GUgHhX8jC9ySWCLBI
                                                                                                                                                  File Content Preview:PK..........!.!=J.............[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                  File Icon

                                                                                                                                                  Icon Hash:74ecd0e2f696908c

                                                                                                                                                  Network Behavior

                                                                                                                                                  Network Port Distribution

                                                                                                                                                  UDP Packets

                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                  Jun 22, 2021 13:34:06.397425890 CEST4925753192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:06.459352016 CEST53492578.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:07.452620983 CEST6238953192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:07.503133059 CEST53623898.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:13.104347944 CEST4991053192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:13.163697958 CEST53499108.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:18.693247080 CEST5585453192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:18.760987997 CEST53558548.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:20.352370024 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:20.481046915 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:20.522984028 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:20.573957920 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:21.001802921 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:21.097220898 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:22.001698017 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:22.066880941 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:23.065018892 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:23.180289030 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:23.498817921 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:23.554853916 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:24.711668968 CEST5172653192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:24.761879921 CEST53517268.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:25.110939980 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:25.180887938 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:26.342062950 CEST5679453192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:26.397329092 CEST53567948.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:27.457086086 CEST5653453192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:27.518634081 CEST53565348.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:28.567749023 CEST5662753192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:28.618249893 CEST53566278.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:29.111656904 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:29.181703091 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:31.154071093 CEST5662153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:31.214139938 CEST53566218.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:32.633635044 CEST6311653192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:32.683717012 CEST53631168.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:33.755656004 CEST6407853192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:33.808173895 CEST53640788.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:34.946288109 CEST6480153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:35.002341032 CEST53648018.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:35.182926893 CEST6172153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:35.265284061 CEST53617218.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:36.136533976 CEST5125553192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:36.195071936 CEST53512558.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:37.411890030 CEST6152253192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:37.464900970 CEST53615228.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:38.569720984 CEST5233753192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:38.631772041 CEST53523378.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:39.738118887 CEST5504653192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:39.791929007 CEST53550468.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:40.909411907 CEST4961253192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:40.971003056 CEST53496128.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:42.045912981 CEST4928553192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:42.099713087 CEST53492858.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:51.525690079 CEST5060153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:51.661621094 CEST53506018.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:52.263659000 CEST6087553192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:52.328490973 CEST53608758.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:52.436372995 CEST5644853192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:52.513638020 CEST53564488.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:52.926877975 CEST5917253192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:53.072206974 CEST53591728.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:53.547955990 CEST6242053192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:53.611747980 CEST53624208.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:54.187994957 CEST6057953192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:54.248145103 CEST53605798.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:54.929630041 CEST5018353192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:54.988626003 CEST53501838.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:55.508428097 CEST6153153192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:55.573440075 CEST53615318.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:56.421154022 CEST4922853192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:56.473294973 CEST53492288.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:57.359426022 CEST5979453192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:57.423682928 CEST53597948.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:34:57.884110928 CEST5591653192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:34:57.949631929 CEST53559168.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:00.784028053 CEST5275253192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:00.850064993 CEST53527528.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:09.812721968 CEST6054253192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:09.868340969 CEST6068953192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:09.882375956 CEST53605428.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:09.941801071 CEST53606898.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:12.846244097 CEST6420653192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:12.911854982 CEST53642068.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:43.675060987 CEST5090453192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:43.742486000 CEST53509048.8.8.8192.168.2.4
                                                                                                                                                  Jun 22, 2021 13:35:45.439239025 CEST5752553192.168.2.48.8.8.8
                                                                                                                                                  Jun 22, 2021 13:35:45.515517950 CEST53575258.8.8.8192.168.2.4

                                                                                                                                                  Code Manipulations

                                                                                                                                                  Statistics

                                                                                                                                                  CPU Usage

                                                                                                                                                  Click to jump to process

                                                                                                                                                  Memory Usage

                                                                                                                                                  Click to jump to process

                                                                                                                                                  Behavior

                                                                                                                                                  Click to jump to process

                                                                                                                                                  System Behavior

                                                                                                                                                  General

                                                                                                                                                  Start time:13:34:18
                                                                                                                                                  Start date:22/06/2021
                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                  Imagebase:0xb90000
                                                                                                                                                  File size:27110184 bytes
                                                                                                                                                  MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  General

                                                                                                                                                  Start time:13:34:24
                                                                                                                                                  Start date:22/06/2021
                                                                                                                                                  Path:C:\Windows\splwow64.exe
                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                  Commandline:C:\Windows\splwow64.exe 12288
                                                                                                                                                  Imagebase:0x7ff643fd0000
                                                                                                                                                  File size:130560 bytes
                                                                                                                                                  MD5 hash:8D59B31FF375059E3C32B17BF31A76D5
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  Disassembly

                                                                                                                                                  Reset < >