Loading ...

Play interactive tourEdit tour

Windows Analysis Report Compensation-54975366-09272021.xls

Overview

General Information

Sample Name:Compensation-54975366-09272021.xls
Analysis ID:493017
MD5:ad92ec6582db6a96102e47dc7ba25e29
SHA1:496757d5b32f14856239db015acd8335a25bdb2d
SHA256:8103f50856a1a1e89ba885dd264bc5779cf74c8e837b556653bc6c410e019c0f
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Multi AV Scanner detection for domain / URL
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Yara detected hidden Macro 4.0 in Excel
Potential document exploit detected (unknown TCP traffic)
Tries to load missing DLLs
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Potential document exploit detected (performs DNS queries)
IP address seen in connection with other malware

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 5040 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • regsvr32.exe (PID: 2460 cmdline: regsvr32 -silent ..\Drezd.red MD5: 426E7499F6A7346F0410DEAD0805586B)
    • regsvr32.exe (PID: 4480 cmdline: regsvr32 -silent ..\Drezd1.red MD5: 426E7499F6A7346F0410DEAD0805586B)
    • regsvr32.exe (PID: 4576 cmdline: regsvr32 -silent ..\Drezd2.red MD5: 426E7499F6A7346F0410DEAD0805586B)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
Compensation-54975366-09272021.xlsJoeSecurity_HiddenMacroYara detected hidden Macro 4.0 in ExcelJoe Security

    Sigma Overview

    System Summary:

    barindex
    Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
    Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: regsvr32 -silent ..\Drezd.red, CommandLine: regsvr32 -silent ..\Drezd.red, CommandLine|base64offset|contains: ,, Image: C:\Windows\SysWOW64\regsvr32.exe, NewProcessName: C:\Windows\SysWOW64\regsvr32.exe, OriginalFileName: C:\Windows\SysWOW64\regsvr32.exe, ParentCommandLine: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 5040, ProcessCommandLine: regsvr32 -silent ..\Drezd.red, ProcessId: 2460

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for domain / URLShow sources
    Source: http://185.183.96.67/Virustotal: Detection: 7%Perma Link
    Source: http://185.250.148.213/Virustotal: Detection: 6%Perma Link
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll

    Software Vulnerabilities:

    barindex
    Document exploit detected (process start blacklist hit)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe
    Document exploit detected (UrlDownloadToFile)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
    Source: global trafficTCP traffic: 192.168.2.4:49756 -> 190.14.37.178:80
    Source: global trafficDNS query: name: clientconfig.passport.net
    Source: global trafficTCP traffic: 192.168.2.4:49756 -> 190.14.37.178:80
    Source: global trafficTCP traffic: 192.168.2.4:49775 -> 185.183.96.67:80
    Source: global trafficTCP traffic: 192.168.2.4:49791 -> 185.250.148.213:80
    Source: Joe Sandbox ViewIP Address: 185.183.96.67 185.183.96.67
    Source: Joe Sandbox ViewIP Address: 190.14.37.178 190.14.37.178
    Source: unknownTCP traffic detected without corresponding DNS query: 190.14.37.178
    Source: unknownTCP traffic detected without corresponding DNS query: 190.14.37.178
    Source: unknownTCP traffic detected without corresponding DNS query: 190.14.37.178
    Source: unknownTCP traffic detected without corresponding DNS query: 185.183.96.67
    Source: unknownTCP traffic detected without corresponding DNS query: 185.183.96.67
    Source: unknownTCP traffic detected without corresponding DNS query: 185.183.96.67
    Source: unknownTCP traffic detected without corresponding DNS query: 185.250.148.213
    Source: unknownTCP traffic detected without corresponding DNS query: 185.250.148.213
    Source: unknownTCP traffic detected without corresponding DNS query: 185.250.148.213
    Source: Compensation-54975366-09272021.xlsString found in binary or memory: http://185.183.96.67/
    Source: Compensation-54975366-09272021.xlsString found in binary or memory: http://185.250.148.213/
    Source: Compensation-54975366-09272021.xlsString found in binary or memory: http://190.14.37.178/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.aadrm.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.cortana.ai
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.diagnostics.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.office.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.onedrive.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://augloop.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://augloop.office.com/v2
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://augloop.office.com;https://augloop-gcc.office.com;https://augloop.gov.online.office365.us;ht
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cdn.entity.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://clients.config.office.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://config.edge.skype.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cortana.ai
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cortana.ai/api
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://cr.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dev.cortana.ai
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://devnull.onenote.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://directory.services.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://graph.ppe.windows.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://graph.windows.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://graph.windows.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://lifecycle.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://login.microsoftonline.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://login.windows.local
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://management.azure.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://management.azure.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://messaging.office.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ncus.contentsync.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ncus.pagecontentsync.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://officeapps.live.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://onedrive.live.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://osi.office.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office365.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office365.com/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://pages.store.office.com/review/query
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://powerlift.acompli.net
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://roaming.edog.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://settings.outlook.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://staging.cortana.ai
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://store.office.com/addinstemplate
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://tasks.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://webshell.suite.office.com
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://wus2.contentsync.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://wus2.pagecontentsync.
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: 8F1C1CDD-A965-428A-9384-8100063EB692.0.drString found in binary or memory: https://www.odwebp.svc.ms
    Source: unknownDNS traffic detected: queries for: clientconfig.passport.net

    System Summary:

    barindex
    Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
    Source: Screenshot number: 4Screenshot OCR: Enable editing" in the yellow bar 19 above. 20 example of notification 21 22 ( 0 pRoTEcmwARNNG T
    Source: Document image extraction number: 0Screenshot OCR: Enable editing" in the yellow bar above. example of notification ( 0 PROTECTEDWARNING This file o
    Source: Document image extraction number: 0Screenshot OCR: Enable Content" to perform Microsoft Excel Decryption Core to start the decryption of the document.
    Source: Document image extraction number: 0Screenshot OCR: Enable Macros ) Why I can not open this document? - You are using iOS or Android device. Please us
    Source: Document image extraction number: 1Screenshot OCR: Enable editing" in the yellow bar above. example of notification ( 0 pRoTEcTmwARNNG Thisfileorigi
    Source: Document image extraction number: 1Screenshot OCR: Enable Content" to perform Microsoft Excel Decryption Core to start the decryption of the document.
    Source: Document image extraction number: 1Screenshot OCR: Enable Macros ) Why I can not open this document? - You are using iOS or Android device. Please us
    Source: Screenshot number: 8Screenshot OCR: Enable editing" in the yellow bar above. example of notification ( 0 pRoTEcmwARNNG Thisfileorigin
    Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
    Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
    Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
    Source: Compensation-54975366-09272021.xlsOLE, VBA macro line: Sub auto_open()
    Source: Compensation-54975366-09272021.xlsOLE, VBA macro line: Sub auto_close()
    Source: Compensation-54975366-09272021.xlsOLE, VBA macro line: Private m_openAlreadyRan As Boolean
    Source: Compensation-54975366-09272021.xlsOLE, VBA macro line: Private Sub saWorkbook_Opensa()
    Source: Compensation-54975366-09272021.xlsOLE indicator, VBA macros: true
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
    Source: Compensation-54975366-09272021.xlsOLE indicator, Workbook stream: true
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd1.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd2.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd1.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -silent ..\Drezd2.red
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{7DDABEE7-1A70-44F9-9707-05657180FFEE} - OProcSessId.datJump to behavior
    Source: classification engineClassification label: mal72.expl.winXLS@7/3@1/3
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEWindow found: window name: SysTabControl32
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

    HIPS / PFW / Operating System Protection Evasion:

    barindex
    Yara detected hidden Macro 4.0 in ExcelShow sources
    Source: Yara matchFile source: Compensation-54975366-09272021.xls, type: SAMPLE

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting2DLL Side-Loading1Process Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsExploitation for Client Execution22Boot or Logon Initialization ScriptsDLL Side-Loading1Disable or Modify Tools1LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection1Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Scripting2NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDLL Side-Loading1LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    No Antivirus matches

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    clientconfig.passport.net0%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    https://roaming.edog.0%URL Reputationsafe
    https://cdn.entity.0%URL Reputationsafe
    https://powerlift.acompli.net0%URL Reputationsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://cortana.ai0%URL Reputationsafe
    https://api.aadrm.com/0%URL Reputationsafe
    https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
    https://officeci.azurewebsites.net/api/0%URL Reputationsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://dataservice.o365filtering.com/0%URL Reputationsafe
    https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
    https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://apis.live.net/v5.0/0%URL Reputationsafe
    http://190.14.37.178/0%VirustotalBrowse
    http://190.14.37.178/0%Avira URL Cloudsafe
    https://wus2.contentsync.0%URL Reputationsafe
    http://185.183.96.67/8%VirustotalBrowse
    http://185.183.96.67/0%Avira URL Cloudsafe
    https://asgsmsproxyapi.azurewebsites.net/0%URL Reputationsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
    https://ncus.pagecontentsync.0%URL Reputationsafe
    http://185.250.148.213/7%VirustotalBrowse
    http://185.250.148.213/0%Avira URL Cloudsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://dataservice.o365filtering.com0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    clientconfig.passport.net
    unknown
    unknowntrueunknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://api.diagnosticssdf.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
      high
      https://login.microsoftonline.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
        high
        https://shell.suite.office.com:14438F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
          high
          https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
            high
            https://autodiscover-s.outlook.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
              high
              https://roaming.edog.8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
              • URL Reputation: safe
              unknown
              https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                high
                https://cdn.entity.8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                • URL Reputation: safe
                unknown
                https://api.addins.omex.office.net/appinfo/query8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                  high
                  https://clients.config.office.net/user/v1.0/tenantassociationkey8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                    high
                    https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                      high
                      https://powerlift.acompli.net8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://rpsticket.partnerservices.getmicrosoftkey.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://lookup.onenote.com/lookup/geolocation/v18F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                        high
                        https://cortana.ai8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                          high
                          https://cloudfiles.onenote.com/upload.aspx8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                            high
                            https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                              high
                              https://entitlement.diagnosticssdf.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                high
                                https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                  high
                                  https://api.aadrm.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  https://ofcrecsvcapi-int.azurewebsites.net/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                    high
                                    https://api.microsoftstream.com/api/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                      high
                                      https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                        high
                                        https://cr.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                          high
                                          https://portal.office.com/account/?ref=ClientMeControl8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                            high
                                            https://graph.ppe.windows.net8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptionevents8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.net8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                • URL Reputation: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/work8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplate8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplate8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetect8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.ms8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groups8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                            high
                                                            https://graph.windows.net8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/api8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetect8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.json8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspx8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                    high
                                                                                    https://management.azure.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                      high
                                                                                      https://outlook.office365.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                        high
                                                                                        http://190.14.37.178/Compensation-54975366-09272021.xlsfalse
                                                                                        • 0%, Virustotal, Browse
                                                                                        • Avira URL Cloud: safe
                                                                                        unknown
                                                                                        https://wus2.contentsync.8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        https://incidents.diagnostics.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                          high
                                                                                          https://clients.config.office.net/user/v1.0/ios8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                            high
                                                                                            https://insertmedia.bing.office.net/odc/insertmedia8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                              high
                                                                                              http://185.183.96.67/Compensation-54975366-09272021.xlstrue
                                                                                              • 8%, Virustotal, Browse
                                                                                              • Avira URL Cloud: safe
                                                                                              unknown
                                                                                              https://o365auditrealtimeingestion.manage.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                high
                                                                                                https://outlook.office365.com/api/v1.0/me/Activities8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                  high
                                                                                                  https://api.office.net8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                    high
                                                                                                    https://incidents.diagnosticssdf.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                      high
                                                                                                      https://asgsmsproxyapi.azurewebsites.net/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                      • URL Reputation: safe
                                                                                                      unknown
                                                                                                      https://clients.config.office.net/user/v1.0/android/policies8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                        high
                                                                                                        https://entitlement.diagnostics.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                          high
                                                                                                          https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                            high
                                                                                                            https://substrate.office.com/search/api/v2/init8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                  high
                                                                                                                  https://outlook.office365.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                    high
                                                                                                                    https://webshell.suite.office.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                      high
                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                        high
                                                                                                                        https://substrate.office.com/search/api/v1/SearchHistory8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                          high
                                                                                                                          https://management.azure.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                              high
                                                                                                                              https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://graph.windows.net/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                high
                                                                                                                                https://api.powerbi.com/beta/myorg/imports8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://devnull.onenote.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://ncus.pagecontentsync.8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://messaging.office.com/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                          high
                                                                                                                                          http://185.250.148.213/Compensation-54975366-09272021.xlstrue
                                                                                                                                          • 7%, Virustotal, Browse
                                                                                                                                          • Avira URL Cloud: safe
                                                                                                                                          unknown
                                                                                                                                          https://augloop.office.com/v28F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com8F1C1CDD-A965-428A-9384-8100063EB692.0.drfalse
                                                                                                                                                  high

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  185.183.96.67
                                                                                                                                                  unknownNetherlands
                                                                                                                                                  60117HSAEfalse
                                                                                                                                                  190.14.37.178
                                                                                                                                                  unknownPanama
                                                                                                                                                  52469OffshoreRacksSAPAfalse
                                                                                                                                                  185.250.148.213
                                                                                                                                                  unknownRussian Federation
                                                                                                                                                  48430FIRSTDC-ASRUfalse

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:33.0.0 White Diamond
                                                                                                                                                  Analysis ID:493017
                                                                                                                                                  Start date:29.09.2021
                                                                                                                                                  Start time:09:08:17
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 7m 13s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:light
                                                                                                                                                  Sample file name:Compensation-54975366-09272021.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:21
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal72.expl.winXLS@7/3@1/3
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Changed system and user locale, location and keyboard layout to English - United States
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer
                                                                                                                                                  Warnings:
                                                                                                                                                  Show All
                                                                                                                                                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 23.203.80.193, 96.16.150.73, 20.82.210.154, 23.211.6.115, 52.109.76.68, 52.109.8.23, 93.184.221.240, 20.54.110.249, 40.112.88.60, 20.82.209.183, 80.67.82.211, 80.67.82.235, 20.50.102.62
                                                                                                                                                  • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, a1449.dscg2.akamai.net, arc.msn.com, wu.azureedge.net, e11290.dspg.akamaiedge.net, e13551.dscg.akamaiedge.net, msagfx.live.com-6.edgekey.net, e12564.dspb.akamaiedge.net, authgfx.msa.akadns6.net, go.microsoft.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, arc.trafficmanager.net, nexus.officeapps.live.com, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, wu.ec.azureedge.net, wu-shim.trafficmanager.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, ctldl.windowsupdate.com, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, ris.api.iris.microsoft.com, store-images.s-microsoft.com, config.officeapps.live.com, go.microsoft.com.edgekey.net, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                                                                                                                                                  • Report size getting too big, too many NtSetInformationFile calls found.

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  185.183.96.67#Qbot downloader.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67/44466.8890891204.dat
                                                                                                                                                  Compensation-2308017-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67/44466.7516903935.dat
                                                                                                                                                  Compensation-1730406737-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67/44466.7022844907.dat
                                                                                                                                                  190.14.37.178xls.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44467.7495993056.dat
                                                                                                                                                  Compensation-1214892625-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44467.5523376157.dat
                                                                                                                                                  Compensation-2100058996-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44467.4314974537.dat
                                                                                                                                                  Compensation-1657705079-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44466.9668618056.dat
                                                                                                                                                  Compensation-1214892625-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44466.9633799768.dat
                                                                                                                                                  #Qbot downloader.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44466.8890891204.dat
                                                                                                                                                  Compensation-2308017-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44466.7516903935.dat
                                                                                                                                                  Compensation-1730406737-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 190.14.37.178/44466.7022844907.dat

                                                                                                                                                  Domains

                                                                                                                                                  No context

                                                                                                                                                  ASN

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  HSAECompensation-54975366-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  CompensationClaim-1630636598-09282021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.141.27.213
                                                                                                                                                  CompensationClaim-1033191014-09282021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.141.27.213
                                                                                                                                                  xls.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-1214892625-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-2100058996-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-1657705079-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-1214892625-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  #Qbot downloader.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-2308017-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  Compensation-1730406737-09272021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.67
                                                                                                                                                  KHI13mrm4c.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.98.2
                                                                                                                                                  Copy of Payment-228607772-09222021.xlsGet hashmaliciousBrowse
                                                                                                                                                  • 185.82.202.248
                                                                                                                                                  NJS4hNBeUR.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.198.57.68
                                                                                                                                                  rQoEGMGufv.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.45.192.203
                                                                                                                                                  5ya8R7LxXl.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.45.192.203
                                                                                                                                                  Uz2eSldsZe.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.45.192.203
                                                                                                                                                  SWIFT_COPY.htmGet hashmaliciousBrowse
                                                                                                                                                  • 194.36.191.196
                                                                                                                                                  3hTS09wZ7G.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.3
                                                                                                                                                  040ba58b824e36fc9117c1e3c8b651d9e4dc3fe12b535.exeGet hashmaliciousBrowse
                                                                                                                                                  • 185.183.96.3

                                                                                                                                                  JA3 Fingerprints

                                                                                                                                                  No context

                                                                                                                                                  Dropped Files

                                                                                                                                                  No context

                                                                                                                                                  Created / dropped Files

                                                                                                                                                  C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8F1C1CDD-A965-428A-9384-8100063EB692
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):138701
                                                                                                                                                  Entropy (8bit):5.360734959006709
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:3cQIKNZeBdA3gBwfnQ9DQW+z2Y34Zli7nXboOidX8E6LWME9:WWQ9DQW+z6Xh1
                                                                                                                                                  MD5:BFB6C139CB3001434EA44D12EB873F0C
                                                                                                                                                  SHA1:CA2917B2A396BCA017E819739C1AE0C51BE613B6
                                                                                                                                                  SHA-256:2A7C7FA6CDBE340140DC2F5D79E816228D6D99780B1D7B73F95B0F03F972E301
                                                                                                                                                  SHA-512:429F81681847BFBFDC52B5D755724BD0F345FB6A812E7CD13C09F8CED1D59DD5C296CFD744DE45381026A3F8BF2AE6961444D8F95AF681806998FCF821D748F4
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-09-29T07:09:16">.. Build: 16.0.14522.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                  C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):170164
                                                                                                                                                  Entropy (8bit):4.359324834585441
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:fZjLzolWWpFpKKHAeedydju4HTbTuo+o5aQxJudUl9yhQL3oKmmy:f1g8WpFpKKHHedydFeo+oQLUlPoK0
                                                                                                                                                  MD5:EF67F6CE6A2BD48CB42B18638B332E12
                                                                                                                                                  SHA1:2BFD27783C973B185DB03C57FE862DA7CBC45C6A
                                                                                                                                                  SHA-256:2109F031AC76BC98CE9E65FA246ED1780267EC77DAB7F0CB987A27E9C42230B1
                                                                                                                                                  SHA-512:EA70CF706023E936BE959B1258C9158A393E84DBC5B02A187BA6EC6C0474F786087812876BE110B6CA6AA88472EABE0F318A2985B373CF7B612E1E0A31821957
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview: MSFT................Q................................$......$....... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...........h.......0...........\.......$...........P...........|.......D...........p.......8...........d.......,...........X....... ...........L...........x.......@........ ..l ... ..4!...!...!..`"..."..(#...#...#..T$...$...%...%...%..H&...&...'..t'...'..<(...(...)..h)...)..0*...*...*..\+...+..$,...,...,..P-...-......|.......D/.../...0..p0...0..81...1...2..d2...2..,3...3...3..X4...4.. 5...5...5..L6...6...7..x7...7..@8...8...9..l9...9..4:...:...:..`;...;..(<...<...<..T=...=...>...>...>..H?...?...@..t@...@..<A...A...B..hB.......l...B..........................$................................................ ...............................x...I..............T........................................... ...................................................
                                                                                                                                                  C:\Users\user\AppData\Local\Temp\VBE\RefEdit.exd
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):15676
                                                                                                                                                  Entropy (8bit):4.561298950587947
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:192:2JXxxA11DxzCOtHIT6P20eChgZjTdZ3HJV8L1I17EMBkDXrq9LwGGLVbkLdZ:az8xesT20lheZ3waE5D7qxIxkxZ
                                                                                                                                                  MD5:9C25BEAC956CCF7B11411CC7990D7343
                                                                                                                                                  SHA1:283D75B1D2CD793CFD0A4E22BD73A7AA7C0AAF6A
                                                                                                                                                  SHA-256:7CDC06C0FCA7D2EF710495F182B0E0B49F534E9DA1685EFDD66E660A9E8E3D13
                                                                                                                                                  SHA-512:A488D866335E67C135A04687D48311CF8DD33034439E9E4F334B9139A0A7A3FCA7E8BA5C7ECC5D1D9867F609457C4824BE61B4C3BDCD37816C36048CFE3AA18B
                                                                                                                                                  Malicious:false
                                                                                                                                                  Preview: MSFT................A...............................1............... ...................d...............,...............\...........H...4...........0... ...............................................................x...............................x.......................................................................................$!.......0...+........\...........U...$..$......P..................................................$!....................i.........@.+...+..+.0....P..,.........................0.....................%!..........................................H..."..................................................H.......(...................@...................P...............0.......`...............................p...X... ..................@Z:vD...f...W.........E.............F...........B........`..d......."E.............F........0..............F..........E........`.M...........CPf.........0..=.......01..)....w....<WI.......\.1Y........k...U........".......|...K..a...

                                                                                                                                                  Static File Info

                                                                                                                                                  General

                                                                                                                                                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Test, Last Saved By: Test, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Mon Sep 27 10:38:52 2021, Security: 0
                                                                                                                                                  Entropy (8bit):7.1318928216423245
                                                                                                                                                  TrID:
                                                                                                                                                  • Microsoft Excel sheet (30009/1) 47.99%
                                                                                                                                                  • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                                                                                                                                                  • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                                                                                                                                                  File name:Compensation-54975366-09272021.xls
                                                                                                                                                  File size:129024
                                                                                                                                                  MD5:ad92ec6582db6a96102e47dc7ba25e29
                                                                                                                                                  SHA1:496757d5b32f14856239db015acd8335a25bdb2d
                                                                                                                                                  SHA256:8103f50856a1a1e89ba885dd264bc5779cf74c8e837b556653bc6c410e019c0f
                                                                                                                                                  SHA512:9158bdcc33fe604a4bdfb9bec0a58ec1be95914ea3e4c551188c1703760d6b5fb7650e62a2ff91c12c64816ced9d21d9b213215e5eeca25d894050c91bc7c645
                                                                                                                                                  SSDEEP:3072:Cik3hOdsylKlgxopeiBNhZFGzE+cL2kdAnc6YehWfG+tUHKGDbpmsiinBti2JtqV:vk3hOdsylKlgxopeiBNhZF+E+W2kdAn+
                                                                                                                                                  File Content Preview:........................>.......................................................b..............................................................................................................................................................................

                                                                                                                                                  File Icon

                                                                                                                                                  Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                  Static OLE Info

                                                                                                                                                  General

                                                                                                                                                  Document Type:OLE
                                                                                                                                                  Number of OLE Files:1

                                                                                                                                                  OLE File "Compensation-54975366-09272021.xls"

                                                                                                                                                  Indicators

                                                                                                                                                  Has Summary Info:True
                                                                                                                                                  Application Name:Microsoft Excel
                                                                                                                                                  Encrypted Document:False
                                                                                                                                                  Contains Word Document Stream:False
                                                                                                                                                  Contains Workbook/Book Stream:True
                                                                                                                                                  Contains PowerPoint Document Stream:False
                                                                                                                                                  Contains Visio Document Stream:False
                                                                                                                                                  Contains ObjectPool Stream:
                                                                                                                                                  Flash Objects Count:
                                                                                                                                                  Contains VBA Macros:True

                                                                                                                                                  Summary

                                                                                                                                                  Code Page:1251
                                                                                                                                                  Author:Test
                                                                                                                                                  Last Saved By:Test
                                                                                                                                                  Create Time:2015-06-05 18:17:20
                                                                                                                                                  Last Saved Time:2021-09-27 09:38:52
                                                                                                                                                  Creating Application:Microsoft Excel
                                                                                                                                                  Security:0

                                                                                                                                                  Document Summary

                                                                                                                                                  Document Code Page:1251
                                                                                                                                                  Thumbnail Scaling Desired:False
                                                                                                                                                  Company:
                                                                                                                                                  Contains Dirty Links:False
                                                                                                                                                  Shared Document:False
                                                                                                                                                  Changed Hyperlinks:False
                                                                                                                                                  Application Version:1048576

                                                                                                                                                  Streams with VBA

                                                                                                                                                  VBA File Name: UserForm2, Stream Size: -1
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/UserForm2
                                                                                                                                                  VBA File Name:UserForm2
                                                                                                                                                  Stream Size:-1
                                                                                                                                                  Data ASCII:
                                                                                                                                                  Data Raw:
                                                                                                                                                  VBA Code
                                                                                                                                                  VBA File Name: Module5, Stream Size: 4241
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/Module5
                                                                                                                                                  VBA File Name:Module5
                                                                                                                                                  Stream Size:4241
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 03 f0 00 00 00 a2 03 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff d0 03 00 00 9c 0d 00 00 00 00 00 00 01 00 00 00 fb 18 e3 25 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 08 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  VBA Code
                                                                                                                                                  VBA File Name: Sheet1, Stream Size: 991
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                                                                                                                                                  VBA File Name:Sheet1
                                                                                                                                                  Stream Size:991
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . 9 . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 fb 18 b4 39 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  VBA Code
                                                                                                                                                  VBA File Name: ThisWorkbook, Stream Size: 2501
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                                                                                                                                                  VBA File Name:ThisWorkbook
                                                                                                                                                  Stream Size:2501
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r S . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 82 04 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff 89 04 00 00 a9 07 00 00 00 00 00 00 01 00 00 00 fb 18 72 53 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  VBA Code
                                                                                                                                                  VBA File Name: UserForm2, Stream Size: 1182
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/UserForm2
                                                                                                                                                  VBA File Name:UserForm2
                                                                                                                                                  Stream Size:1182
                                                                                                                                                  Data ASCII:. . . . . . . . . V . . . . . . . L . . . . . . . ] . . . . . . . . . . . . . . . . . . J . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 56 03 00 00 d4 00 00 00 4c 02 00 00 ff ff ff ff 5d 03 00 00 b1 03 00 00 00 00 00 00 01 00 00 00 fb 18 b2 4a 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  VBA Code

                                                                                                                                                  Streams

                                                                                                                                                  Stream Path: \x1CompObj, File Type: data, Stream Size: 108
                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x1CompObj
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:108
                                                                                                                                                  Entropy:4.18849998853
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . F . . . . M i c r o s o f t E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . . 9 . q . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 20 00 00 00 1e 4d 69 63 72 6f 73 6f 66 74 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 244
                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:244
                                                                                                                                                  Entropy:2.65175227267
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                                                                                                                                                  Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00
                                                                                                                                                  Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 208
                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x5SummaryInformation
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:208
                                                                                                                                                  Entropy:3.33231709703
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . X . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . T e s t . . . . . . . . . . . . T e s t . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . x s . . . . . @ . . . . . 6 { . . . . . . . . . . . .
                                                                                                                                                  Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a0 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 58 00 00 00 12 00 00 00 68 00 00 00 0c 00 00 00 80 00 00 00 0d 00 00 00 8c 00 00 00 13 00 00 00 98 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 08 00 00 00
                                                                                                                                                  Stream Path: Workbook, File Type: Applesoft BASIC program data, first line number 16, Stream Size: 101831
                                                                                                                                                  General
                                                                                                                                                  Stream Path:Workbook
                                                                                                                                                  File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                  Stream Size:101831
                                                                                                                                                  Entropy:7.65479066874
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . Z O . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . T e s t B . . . . . a . . . . . . . . . = . . . . . . . . . . . . . . . . T h i s W o r k b o o k . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . V e 1 8 . . . . . . . X . @
                                                                                                                                                  Data Raw:09 08 10 00 00 06 05 00 5a 4f cd 07 c9 00 02 00 06 08 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 04 00 00 54 65 73 74 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 662
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Stream Size:662
                                                                                                                                                  Entropy:5.27592988154
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:I D = " { 0 0 0 0 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 0 0 0 0 0 0 0 0 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4 F } . . M o d u l e = M o d u l e 5 . . B a s e C l a s s = U s e r F o r m 2 . . H e l p F i l e = " " . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t
                                                                                                                                                  Data Raw:49 44 3d 22 7b 30 30 30 30 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 30 30 30 30 30 30 30 30 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 50 61 63 6b 61 67 65 3d 7b 41 43 39 46 32 46 39 30 2d 45 38 37
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/PROJECTlk, File Type: dBase IV DBT, blocks size 0, block length 17920, next free block index 65537, Stream Size: 30
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/PROJECTlk
                                                                                                                                                  File Type:dBase IV DBT, blocks size 0, block length 17920, next free block index 65537
                                                                                                                                                  Stream Size:30
                                                                                                                                                  Entropy:1.37215976263
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . " E . . . . . . . . . . . . . F . . . . . . . .
                                                                                                                                                  Data Raw:01 00 01 00 00 00 22 45 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/PROJECTwm, File Type: data, Stream Size: 116
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:116
                                                                                                                                                  Entropy:3.43722878834
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . M o d u l e 5 . M . o . d . u . l . e . 5 . . . U s e r F o r m 2 . U . s . e . r . F . o . r . m . 2 . . . . .
                                                                                                                                                  Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 4d 6f 64 75 6c 65 35 00 4d 00 6f 00 64 00 75 00 6c 00 65 00 35 00 00 00 55 73 65 72 46 6f 72 6d 32 00 55 00 73 00 65 00 72 00 46 00 6f 00 72 00 6d 00 32 00 00 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/UserForm2/\x1CompObj, File Type: data, Stream Size: 97
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/UserForm2/\x1CompObj
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:97
                                                                                                                                                  Entropy:3.61064918306
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . . 9 . q . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/UserForm2/\x3VBFrame, File Type: ASCII text, with CRLF line terminators, Stream Size: 302
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/UserForm2/\x3VBFrame
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Stream Size:302
                                                                                                                                                  Entropy:4.65399600072
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } U s e r F o r m 2 . . C a p t i o n = " U R L D o w n l o a d T o F i l e A " . . C l i e n t H e i g h t = 3 0 1 5 . . C l i e n t L e f t = 1 2 0 . . C l i e n t T o p = 4 6 5 . . C l i e n t W i d t h = 4 5 6 0 . . S t a r t U p P o s i t i o n = 1
                                                                                                                                                  Data Raw:56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 55 73 65 72 46 6f 72 6d 32 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 55 52 4c 44 6f 77 6e 6c 6f 61 64 54 6f 46 69 6c 65 41 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/UserForm2/f, File Type: data, Stream Size: 226
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/UserForm2/f
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:226
                                                                                                                                                  Entropy:3.01175231218
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . } . . k . . . . . . . . . . . . . . . . . . . . . . . . . . . . l . . ( . . . . . . . . . . . . . 2 . . . H . . . . . . . L a b e l 1 ) . . . . . . . . . . . ( . . . . . . . . . . . . . 2 . . . 8 . . . . . . . L a b e l 2 . . . . . . . . . . . . ( . . . . . . . . . . . . . 2 . . . H . . . . . . . L a b e l 3 . . . . . . . . . . . . ( . . . . . . . . . . . . . 2 . . . H . . . . . . . L a b e l 4 . . . . . . . . . .
                                                                                                                                                  Data Raw:00 04 20 00 08 0c 00 0c 0a 00 00 00 10 00 00 00 00 7d 00 00 6b 1f 00 00 c6 14 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 b4 00 00 00 00 84 01 6c 00 00 28 00 f5 01 00 00 06 00 00 80 07 00 00 00 32 00 00 00 48 00 00 00 00 00 15 00 4c 61 62 65 6c 31 29 00 d4 00 00 00 d4 00 00 00 00 00 28 00 f5 01 00 00 06 00 00 80 08 00 00 00 32 00 00 00 38 00 00 00 01 00 15 00 4c 61 62 65 6c 32
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/UserForm2/o, File Type: data, Stream Size: 272
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/UserForm2/o
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:272
                                                                                                                                                  Entropy:3.6318384866
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . ( . ( . . . . . . . h t t p : / / 1 9 0 . 1 4 . 3 7 . 1 7 8 / . . . . . . . . . . . . . . . 5 . . . . . . . . . . . . . . . T a h o m a . . . . . . ( . . . . . . . u R l M o n . . . . . . . . . . . . . . 5 . . . . . . . . . . . . . . . T a h o m a . . . . ( . ( . . . . . . . h t t p : / / 1 8 5 . 1 8 3 . 9 6 . 6 7 / . . . . . . . . . . . . . . . 5 . . . . . . . . . . . . . . . T a h o m a . . . . ( . ( . . . . . . . h t t p : / / 1 8 5 . 2 5 0 . 1 4 8 . 2 1 3 / . . . . . . . . . . . . . 5 . . . . . . .
                                                                                                                                                  Data Raw:00 02 28 00 28 00 00 00 15 00 00 80 68 74 74 70 3a 2f 2f 31 39 30 2e 31 34 2e 33 37 2e 31 37 38 2f 01 00 00 00 00 00 00 00 00 00 00 00 02 18 00 35 00 00 00 06 00 00 80 a5 00 00 00 cc 02 00 00 54 61 68 6f 6d 61 00 00 00 02 18 00 28 00 00 00 06 00 00 80 75 52 6c 4d 6f 6e 00 00 00 00 00 00 00 00 00 00 00 02 18 00 35 00 00 00 06 00 00 80 a5 00 00 00 cc 02 00 00 54 61 68 6f 6d 61 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/_VBA_PROJECT, File Type: data, Stream Size: 4332
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:4332
                                                                                                                                                  Entropy:4.42025024054
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                  Data Raw:cc 61 b5 00 00 03 00 ff 19 04 00 00 09 04 00 00 e3 04 03 00 00 00 00 00 00 00 00 00 01 00 06 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_0, File Type: data, Stream Size: 2461
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_0
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:2461
                                                                                                                                                  Entropy:3.4974013905
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ P . . . . . . . . . . . . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . . . 3 . . d . A
                                                                                                                                                  Data Raw:93 4b 2a b5 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 03 00 00 00 00 00 01 00 02 00 03 00 00 00 00 00 01 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 00 00 72 55 00 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 06 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_1, File Type: data, Stream Size: 138
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_1
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:138
                                                                                                                                                  Entropy:1.48462480805
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . j . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 12 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 11 00 00 00 00 00 00 00 00 00 03 00 6a 00 00 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_2, File Type: data, Stream Size: 264
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_2
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:264
                                                                                                                                                  Entropy:1.9985725068
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Z . . . N . . . . . . .
                                                                                                                                                  Data Raw:72 55 80 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 10 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_3, File Type: data, Stream Size: 256
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_3
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:256
                                                                                                                                                  Entropy:1.80540314317
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . a . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 38 00 f1 00 00 00 00 00 00 00 00 00 02 00 00 00 00 60 00 00 fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00
                                                                                                                                                  Stream Path: _VBA_PROJECT_CUR/VBA/dir, File Type: data, Stream Size: 1047
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:1047
                                                                                                                                                  Entropy:6.66117755603
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . 0 . J . . . . H . . H . . . . . . H . . . d . . . . . . . . V B A P r @ o j e c t . . . . T . @ . . . . . = . . . + . r . . . . . . . . . . . H c . . . . J < . . . . . . 9 s t d o l . e > . . s . t . d . . o . l . e . . . . h . % ^ . . * \\ G . { 0 0 0 2 0 4 3 . 0 - . . . . C . . . . . . . 0 0 4 6 } # 2 . . 0 # 0 # C : \\ W . i n d o w s \\ S . y s t e m 3 2 \\ . . e 2 . t l b # O . L E A u t o m . a t i o n . 0 . . . E O f f i c . E O . . f . . i . c . E . . . . . . . . E 2 D F 8 D
                                                                                                                                                  Data Raw:01 13 b4 80 01 00 04 00 00 00 03 00 30 aa 4a 02 90 02 00 48 02 02 48 09 00 c0 12 14 06 48 03 00 01 64 e3 04 04 04 00 0a 00 84 56 42 41 50 72 40 6f 6a 65 63 74 05 00 1a 00 54 00 40 02 0a 06 02 0a 3d 02 0a 07 2b 02 72 01 14 08 06 12 09 02 12 cc 07 a0 48 63 06 00 0c 02 4a 3c 02 0a 04 16 00 01 39 73 74 64 6f 6c 04 65 3e 02 19 73 00 74 00 64 00 00 6f 00 6c 00 65 00 0d 14 00 68 00 25 5e

                                                                                                                                                  Network Behavior

                                                                                                                                                  Snort IDS Alerts

                                                                                                                                                  TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                  09/29/21-08:59:05.747980ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22
                                                                                                                                                  09/29/21-08:59:08.746802ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22
                                                                                                                                                  09/29/21-08:59:15.659776ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22
                                                                                                                                                  09/29/21-08:59:26.247443ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22
                                                                                                                                                  09/29/21-08:59:29.258176ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22
                                                                                                                                                  09/29/21-08:59:37.377441ICMP399ICMP Destination Unreachable Host Unreachable186.148.101.114192.168.2.22

                                                                                                                                                  Network Port Distribution

                                                                                                                                                  TCP Packets

                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                  Sep 29, 2021 09:09:19.506577015 CEST4975680192.168.2.4190.14.37.178
                                                                                                                                                  Sep 29, 2021 09:09:22.514975071 CEST4975680192.168.2.4190.14.37.178
                                                                                                                                                  Sep 29, 2021 09:09:28.515467882 CEST4975680192.168.2.4190.14.37.178
                                                                                                                                                  Sep 29, 2021 09:09:40.536407948 CEST4977580192.168.2.4185.183.96.67
                                                                                                                                                  Sep 29, 2021 09:09:43.548150063 CEST4977580192.168.2.4185.183.96.67
                                                                                                                                                  Sep 29, 2021 09:09:49.567857027 CEST4977580192.168.2.4185.183.96.67
                                                                                                                                                  Sep 29, 2021 09:10:01.587445974 CEST4979180192.168.2.4185.250.148.213
                                                                                                                                                  Sep 29, 2021 09:10:04.596741915 CEST4979180192.168.2.4185.250.148.213
                                                                                                                                                  Sep 29, 2021 09:10:10.597716093 CEST4979180192.168.2.4185.250.148.213

                                                                                                                                                  UDP Packets

                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                  Sep 29, 2021 09:09:06.095823050 CEST5170353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:06.116482019 CEST53517038.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:06.197745085 CEST6524853192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:06.226886988 CEST53652488.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:08.424562931 CEST5372353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:08.473438025 CEST53537238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:12.974328041 CEST6464653192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:13.002919912 CEST53646468.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:15.647701025 CEST6529853192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:15.683064938 CEST53652988.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:16.308161974 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:16.347337961 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:17.366040945 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:17.387420893 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:18.425321102 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:18.445004940 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:20.452496052 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:20.472348928 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:24.499649048 CEST5912353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:24.519722939 CEST53591238.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:43.429328918 CEST5453153192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:43.455192089 CEST53545318.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:58.402230024 CEST4971453192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:58.423288107 CEST53497148.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:58.988568068 CEST5802853192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:59.023643970 CEST53580288.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:09:59.784437895 CEST5309753192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:09:59.804421902 CEST53530978.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:00.218899965 CEST4925753192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:00.255233049 CEST53492578.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:00.319169044 CEST6238953192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:00.339206934 CEST53623898.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:00.679137945 CEST4991053192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:00.715506077 CEST53499108.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:01.230732918 CEST5585453192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:01.264661074 CEST53558548.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:01.847023964 CEST6454953192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:01.867253065 CEST53645498.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:02.296154976 CEST6315353192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:02.349137068 CEST53631538.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:03.101843119 CEST5299153192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:03.121411085 CEST53529918.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:03.953861952 CEST5370053192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:03.974118948 CEST53537008.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:04.399389029 CEST5172653192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:04.417128086 CEST53517268.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:19.086343050 CEST5679453192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:19.105824947 CEST53567948.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:19.168026924 CEST5653453192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:19.195688963 CEST53565348.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:22.744348049 CEST5662753192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:22.765989065 CEST53566278.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:54.209764957 CEST5662153192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:54.231076002 CEST53566218.8.8.8192.168.2.4
                                                                                                                                                  Sep 29, 2021 09:10:55.016330957 CEST6311653192.168.2.48.8.8.8
                                                                                                                                                  Sep 29, 2021 09:10:55.044337988 CEST53631168.8.8.8192.168.2.4

                                                                                                                                                  DNS Queries

                                                                                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                  Sep 29, 2021 09:09:06.197745085 CEST192.168.2.48.8.8.80xfe57Standard query (0)clientconfig.passport.netA (IP address)IN (0x0001)

                                                                                                                                                  DNS Answers

                                                                                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                  Sep 29, 2021 09:09:06.226886988 CEST8.8.8.8192.168.2.40xfe57No error (0)clientconfig.passport.netauthgfx.msa.akadns6.netCNAME (Canonical name)IN (0x0001)

                                                                                                                                                  Code Manipulations

                                                                                                                                                  Statistics

                                                                                                                                                  Behavior

                                                                                                                                                  Click to jump to process

                                                                                                                                                  System Behavior

                                                                                                                                                  General

                                                                                                                                                  Start time:09:09:14
                                                                                                                                                  Start date:29/09/2021
                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                  Imagebase:0xdd0000
                                                                                                                                                  File size:27110184 bytes
                                                                                                                                                  MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  General

                                                                                                                                                  Start time:09:10:23
                                                                                                                                                  Start date:29/09/2021
                                                                                                                                                  Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:regsvr32 -silent ..\Drezd.red
                                                                                                                                                  Imagebase:0xbb0000
                                                                                                                                                  File size:20992 bytes
                                                                                                                                                  MD5 hash:426E7499F6A7346F0410DEAD0805586B
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  General

                                                                                                                                                  Start time:09:10:23
                                                                                                                                                  Start date:29/09/2021
                                                                                                                                                  Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:regsvr32 -silent ..\Drezd1.red
                                                                                                                                                  Imagebase:0xbb0000
                                                                                                                                                  File size:20992 bytes
                                                                                                                                                  MD5 hash:426E7499F6A7346F0410DEAD0805586B
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  General

                                                                                                                                                  Start time:09:10:24
                                                                                                                                                  Start date:29/09/2021
                                                                                                                                                  Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:regsvr32 -silent ..\Drezd2.red
                                                                                                                                                  Imagebase:0xbb0000
                                                                                                                                                  File size:20992 bytes
                                                                                                                                                  MD5 hash:426E7499F6A7346F0410DEAD0805586B
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  Disassembly

                                                                                                                                                  Code Analysis

                                                                                                                                                  Reset < >