Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
sample20220124-01.xls

Overview

General Information

Sample Name:sample20220124-01.xls
Analysis ID:558645
MD5:4e8ec74a93b831a92a1b016722e79365
SHA1:330af52281a3a9ae4836062f98f77fe5f8a834e4
SHA256:e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f
Tags:BRTgoziisfbursnifxls
Infos:

Detection

Ursnif Dropper
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected Italy targeted Ursnif dropper document
Document contains an embedded VBA macro with suspicious strings
Document contains embedded VBA macros
Document misses a certain OLE stream usually present in this Microsoft Office document type

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 3480 cmdline: "C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding MD5: 5D6638F2C8F8571C593999C58866007E)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sample20220124-01.xlsAvira: detected
Source: sample20220124-01.xlsVirustotal: Detection: 10%Perma Link
Source: sample20220124-01.xlsReversingLabs: Detection: 11%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.aadrm.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.aadrm.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.cortana.ai
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.office.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.onedrive.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://augloop.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cdn.entity.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://clients.config.office.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://config.edge.skype.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cortana.ai
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cortana.ai/api
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://cr.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dev.cortana.ai
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://devnull.onenote.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://directory.services.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://edu-mathreco-prod.trafficmanager.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://edu-mathsolver-prod.trafficmanager.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://graph.windows.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://graph.windows.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://invites.office.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://lifecycle.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://login.windows.local
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://management.azure.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://management.azure.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://messaging.office.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ncus.contentsync.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://officeapps.live.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://onedrive.live.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://osi.office.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://otelrules.azureedge.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office365.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office365.com/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://roaming.edog.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://settings.outlook.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://staging.cortana.ai
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://tasks.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://wus2.contentsync.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 958B8392-5DD4-4333-8B8D-A800E81F435C.0.drString found in binary or memory: https://www.odwebp.svc.ms

E-Banking Fraud

barindex
Source: Initial sampleOLE, VBA macro line: Ursnif specific tokens

System Summary

barindex
Source: sample20220124-01.xlsOLE, VBA macro line: Workbooks.Application.DisplayAlerts = False: Application.Quit
Source: sample20220124-01.xlsOLE, VBA macro line: ActiveSheet.Visible = 0
Source: sample20220124-01.xlsOLE indicator, VBA macros: true
Source: ~DF4020A80B58AC9E01.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: sample20220124-01.xlsVirustotal: Detection: 10%
Source: sample20220124-01.xlsReversingLabs: Detection: 11%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{DEB129E4-420D-4814-BB08-1CE664F2C768} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
Source: sample20220124-01.xlsOLE indicator, Workbook stream: true
Source: classification engineClassification label: mal68.bank.expl.winXLS@1/3@0/1
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCacheJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: sample20220124-01.xlsInitial sample: OLE summary comments = DATA ORA
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dll
Source: ~DF4020A80B58AC9E01.TMP.0.drInitial sample: OLE indicators vbamacros = False
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts11
Scripting
Path InterceptionPath Interception1
Masquerading
OS Credential Dumping1
File and Directory Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
Scripting
LSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sample20220124-01.xls11%VirustotalBrowse
sample20220124-01.xls12%ReversingLabsScript-Macro.Downloader.Heuristic
sample20220124-01.xls100%AviraHEUR/Macro.Downloader.MRAJM.Gen
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://roaming.edog.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://api.aadrm.com0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://asgsmsproxyapi.azurewebsites.net/0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
    high
    https://login.microsoftonline.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
      high
      https://shell.suite.office.com:1443958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
          high
          https://autodiscover-s.outlook.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
            high
            https://roaming.edog.958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
            • URL Reputation: safe
            unknown
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
              high
              https://cdn.entity.958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/query958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkey958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                    high
                    https://powerlift.acompli.net958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                      high
                      https://cortana.ai958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspx958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                high
                                https://api.aadrm.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                      high
                                      https://cr.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                        high
                                        https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                        • Avira URL Cloud: safe
                                        low
                                        https://portal.office.com/account/?ref=ClientMeControl958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                          high
                                          https://graph.ppe.windows.net958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                            high
                                            https://res.getmicrosoftkey.com/api/redemptionevents958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://powerlift-frontdesk.acompli.net958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://tasks.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                              high
                                              https://officeci.azurewebsites.net/api/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://sr.outlook.office.net/ws/speech/recognize/assistant/work958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                high
                                                https://store.office.cn/addinstemplate958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                • URL Reputation: safe
                                                unknown
                                                https://api.aadrm.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                • URL Reputation: safe
                                                unknown
                                                https://outlook.office.com/autosuggest/api/v1/init?cvid=958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                  high
                                                  https://globaldisco.crm.dynamics.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                    high
                                                    https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                      high
                                                      https://dev0-api.acompli.net/autodetect958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://www.odwebp.svc.ms958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://api.diagnosticssdf.office.com/v2/feedback958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                        high
                                                        https://api.powerbi.com/v1.0/myorg/groups958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                            high
                                                            https://api.addins.store.officeppe.com/addinstemplate958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                            • URL Reputation: safe
                                                            unknown
                                                            https://graph.windows.net958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/api958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetect958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.json958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspx958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                    high
                                                                                    https://management.azure.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                      high
                                                                                      https://outlook.office365.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                        high
                                                                                        https://wus2.contentsync.958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        https://incidents.diagnostics.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                          high
                                                                                          https://clients.config.office.net/user/v1.0/ios958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                            high
                                                                                            https://insertmedia.bing.office.net/odc/insertmedia958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                              high
                                                                                              https://o365auditrealtimeingestion.manage.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                high
                                                                                                https://outlook.office365.com/api/v1.0/me/Activities958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                  high
                                                                                                  https://api.office.net958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                    high
                                                                                                    https://incidents.diagnosticssdf.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                      high
                                                                                                      https://asgsmsproxyapi.azurewebsites.net/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                      • URL Reputation: safe
                                                                                                      unknown
                                                                                                      https://clients.config.office.net/user/v1.0/android/policies958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                        high
                                                                                                        https://entitlement.diagnostics.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                          high
                                                                                                          https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                            high
                                                                                                            https://substrate.office.com/search/api/v2/init958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                              high
                                                                                                              https://outlook.office.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                high
                                                                                                                https://storage.live.com/clientlogs/uploadlocation958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                  high
                                                                                                                  https://outlook.office365.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                    high
                                                                                                                    https://webshell.suite.office.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                      high
                                                                                                                      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                        high
                                                                                                                        https://substrate.office.com/search/api/v1/SearchHistory958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                          high
                                                                                                                          https://management.azure.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                            high
                                                                                                                            https://login.windows.net/common/oauth2/authorize958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                              high
                                                                                                                              https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://graph.windows.net/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                high
                                                                                                                                https://api.powerbi.com/beta/myorg/imports958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://devnull.onenote.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://ncus.pagecontentsync.958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://messaging.office.com/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://augloop.office.com/v2958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://skyapi.live.net/Activity/958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              https://clients.config.office.net/user/v1.0/mac958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://dataservice.o365filtering.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://api.cortana.ai958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://onedrive.live.com958B8392-5DD4-4333-8B8D-A800E81F435C.0.drfalse
                                                                                                                                                  high
                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs
                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  IP
                                                                                                                                                  192.168.2.1
                                                                                                                                                  Joe Sandbox Version:34.0.0 Boulder Opal
                                                                                                                                                  Analysis ID:558645
                                                                                                                                                  Start date:24.01.2022
                                                                                                                                                  Start time:11:02:10
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 4m 12s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:light
                                                                                                                                                  Sample file name:sample20220124-01.xls
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:15
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal68.bank.expl.winXLS@1/3@0/1
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HDC Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .xls
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Active Picture Object
                                                                                                                                                  • Active AutoShape Object
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer
                                                                                                                                                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 51.11.168.232, 204.79.197.200, 13.107.21.200, 52.109.76.68, 52.109.8.25, 52.109.8.23
                                                                                                                                                  • Excluded domains from analysis (whitelisted): www.bing.com, prod-w.nexus.live.com.akadns.net, dual-a-0001.a-msedge.net, prod.configsvc1.live.com.akadns.net, ctldl.windowsupdate.com, settings-win.data.microsoft.com, arc.msn.com, settingsfd-geo.trafficmanager.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, www-bing-com.dual-a-0001.a-msedge.net, nexus.officeapps.live.com, displaycatalog.mp.microsoft.com, officeclient.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                  • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                                                                                                  No simulations
                                                                                                                                                  No context
                                                                                                                                                  No context
                                                                                                                                                  No context
                                                                                                                                                  No context
                                                                                                                                                  No context
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):142029
                                                                                                                                                  Entropy (8bit):5.3548353197232235
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:1536:4cQIfgxrBdA3guwQ/Q9DQW+zUk4F77nXmvidZXPE5LWmE9:k8Q9DQW+zwX8U
                                                                                                                                                  MD5:62D881B39D40CEF1EA070FC02A1335D5
                                                                                                                                                  SHA1:01FDA93F70F5892827C214B8E6956A4AF04D1AA9
                                                                                                                                                  SHA-256:174464597474F0185BC2C643D81690DAD379DBE34A55A4CFA9AAB21B094E7472
                                                                                                                                                  SHA-512:C280A8B00885F934A78A19469A987C4B09ADCF5366C03E462BD5750A0C9451CA52A05155A90C127D182DE8C35AB985EC1D9704C73C991B3E6CD4FFF76F653BBC
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2022-01-24T10:03:07">.. Build: 16.0.14917.30526-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):32768
                                                                                                                                                  Entropy (8bit):2.50184198199847
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:192:9WGdmsidTUOe/vWwPCbmPLodNjX0usxdR9qjqXFa5aF:9Pdmsije/vY7NT0uadRP
                                                                                                                                                  MD5:1C0E0503819787346E36EDF5C640EE55
                                                                                                                                                  SHA1:C0A1A236138D94A114B6F6ACF7848B1425AA7C26
                                                                                                                                                  SHA-256:22EE0E4631674DA1D967A9414FBDA68493D575727339307DAC058CE5EFBA6966
                                                                                                                                                  SHA-512:F70DAC6C64E4DF49AB569D61E9BEC216A855B6C9259ACD02DF4C4CF6BEA7C47C6C4AAE76D5E650A7639DD4BEB7008C890655A73CEF90FA7C9F20FC720A24B72F
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:low
                                                                                                                                                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  File Type:data
                                                                                                                                                  Category:dropped
                                                                                                                                                  Size (bytes):512
                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                  Encrypted:false
                                                                                                                                                  SSDEEP:3::
                                                                                                                                                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                                                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                                                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                                                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                                                  Malicious:false
                                                                                                                                                  Reputation:high, very likely benign file
                                                                                                                                                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: VETTORE BRT S.P.A., Create Time/Date: Mon Jan 24 08:04:38 2022, Last Saved Time/Date: Mon Jan 24 08:04:41 2022, Security: 0, Comments: DATA ORA
                                                                                                                                                  Entropy (8bit):5.4276709427017735
                                                                                                                                                  TrID:
                                                                                                                                                  • Microsoft Excel sheet (30009/1) 78.94%
                                                                                                                                                  • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                                                                                                                                                  File name:sample20220124-01.xls
                                                                                                                                                  File size:51200
                                                                                                                                                  MD5:4e8ec74a93b831a92a1b016722e79365
                                                                                                                                                  SHA1:330af52281a3a9ae4836062f98f77fe5f8a834e4
                                                                                                                                                  SHA256:e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f
                                                                                                                                                  SHA512:68dfa7849da02bd108d78a14686a7c7eded8e45206208fd8afda9886262b12dfafda475c0ed1dfef46dd48c41f9e5048364d158a0a82279d8fedaf226cd5aa22
                                                                                                                                                  SSDEEP:1536:fsQlYkEIbSkKBEqEXPgsRZmbaoFhZhR0cixIHm0hs4avxDdmsicY:fhlYkEIuPm3fNRZmbaoFhZhR0cixIHmg
                                                                                                                                                  File Content Preview:........................>...................................;..................................................................................................................................................................................................
                                                                                                                                                  Icon Hash:74ecd4c6c3c6c4d8
                                                                                                                                                  Document Type:OLE
                                                                                                                                                  Number of OLE Files:1
                                                                                                                                                  Has Summary Info:True
                                                                                                                                                  Application Name:unknown
                                                                                                                                                  Encrypted Document:False
                                                                                                                                                  Contains Word Document Stream:False
                                                                                                                                                  Contains Workbook/Book Stream:True
                                                                                                                                                  Contains PowerPoint Document Stream:False
                                                                                                                                                  Contains Visio Document Stream:False
                                                                                                                                                  Contains ObjectPool Stream:
                                                                                                                                                  Flash Objects Count:
                                                                                                                                                  Contains VBA Macros:True
                                                                                                                                                  Code Page:1252
                                                                                                                                                  Author:VETTORE BRT S.P.A.
                                                                                                                                                  Comments:DATA ORA
                                                                                                                                                  Last Saved By:
                                                                                                                                                  Create Time:2022-01-24 08:04:38.805000
                                                                                                                                                  Last Saved Time:2022-01-24 08:04:41
                                                                                                                                                  Security:0
                                                                                                                                                  Document Code Page:1252
                                                                                                                                                  Thumbnail Scaling Desired:False
                                                                                                                                                  Company:
                                                                                                                                                  Contains Dirty Links:False
                                                                                                                                                  Shared Document:False
                                                                                                                                                  Changed Hyperlinks:False
                                                                                                                                                  Application Version:1048576
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/Foglio1
                                                                                                                                                  VBA File Name:Foglio1
                                                                                                                                                  Stream Size:992
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . B z v . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 42 7a 76 de 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/Questa_cartella_di_lavoro
                                                                                                                                                  VBA File Name:Questa_cartella_di_lavoro
                                                                                                                                                  Stream Size:5151
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . ( . . . 6 . . . J . . . . . . . . . . . B z Z . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . P . . . t q I . y . g . . ) 3 . . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . } . . s . . O . . . . . p ] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . } . . s . . O . . . . . p ] . . P . . . t q I . y . g . . ) 3 . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 16 03 00 06 00 01 00 00 fa 09 00 00 e4 00 00 00 10 02 00 00 28 0a 00 00 36 0a 00 00 4a 10 00 00 0d 00 00 00 01 00 00 00 42 7a 5a b4 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 18 50 85 cb 92 74 71 49 b1 79 e9 67 11 bc 29 33 19 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00

                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x1CompObj
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:118
                                                                                                                                                  Entropy:4.32915524493
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . F * . . . ( F o g l i o d i l a v o r o d i M i c r o s o f t E x c e l 2 0 0 3 . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . . 9 . q . . . . . . . . . . . .
                                                                                                                                                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 2a 00 00 00 28 46 6f 67 6c 69 6f 20 64 69 20 6c 61 76 6f 72 6f 20 64 69 20 4d 69 63 72 6f 73 6f 66 74 20 45 78 63 65 6c 20 32 30 30 33 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x5DocumentSummaryInformation
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:268
                                                                                                                                                  Entropy:3.12865032743
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D O C U M E N T O D I T R A S P O R T O . . . . . . . . . . . . . . . . . F o g l i d i l a v o r
                                                                                                                                                  Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 dc 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 b2 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:\x5SummaryInformation
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:212
                                                                                                                                                  Entropy:3.34308045596
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . l . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . @ . . . P . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . D A T A O R A . . . . . . . . . . . . V E T T O R E B R T S . P . A . . .
                                                                                                                                                  Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a4 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 88 00 00 00 08 00 00 00 48 00 00 00 0c 00 00 00 54 00 00 00 0d 00 00 00 60 00 00 00 13 00 00 00 6c 00 00 00 06 00 00 00 74 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:Workbook
                                                                                                                                                  File Type:Applesoft BASIC program data, first line number 16
                                                                                                                                                  Stream Size:28393
                                                                                                                                                  Entropy:6.49607410091
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . Z O . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . . a . . . . . . . . . = . . . . . . . . . . . . . . . . Q u e s t a _ c a r t e l l a _ d i _ l a v o r o . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . C
                                                                                                                                                  Data Raw:09 08 10 00 00 06 05 00 5a 4f cd 07 c9 00 02 00 06 08 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/PROJECT
                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                  Stream Size:452
                                                                                                                                                  Entropy:5.40119884402
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:I D = " { 2 F 2 C 6 4 B F - 5 E 3 3 - 4 F 7 E - 9 6 2 B - D 1 1 3 A A 1 9 7 8 8 C } " . . D o c u m e n t = Q u e s t a _ c a r t e l l a _ d i _ l a v o r o / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = F o g l i o 1 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " F A F 8 0 E 9 2 8 8 9 6 8 8 9 6 8 8 9 6 8 8 9 6 " . . D P B = " 7 8 7 A 8 C 6 F 8 D 6 F 8 D 6 F " . . G C = " F 6 F 4
                                                                                                                                                  Data Raw:49 44 3d 22 7b 32 46 32 43 36 34 42 46 2d 35 45 33 33 2d 34 46 37 45 2d 39 36 32 42 2d 44 31 31 33 41 41 31 39 37 38 38 43 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 51 75 65 73 74 61 5f 63 61 72 74 65 6c 6c 61 5f 64 69 5f 6c 61 76 6f 72 6f 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 46 6f 67 6c 69 6f 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4e 61 6d 65 3d 22 56
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:104
                                                                                                                                                  Entropy:3.33133492199
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:Q u e s t a _ c a r t e l l a _ d i _ l a v o r o . Q . u . e . s . t . a . _ . c . a . r . t . e . l . l . a . _ . d . i . _ . l . a . v . o . r . o . . . F o g l i o 1 . F . o . g . l . i . o . 1 . . . . .
                                                                                                                                                  Data Raw:51 75 65 73 74 61 5f 63 61 72 74 65 6c 6c 61 5f 64 69 5f 6c 61 76 6f 72 6f 00 51 00 75 00 65 00 73 00 74 00 61 00 5f 00 63 00 61 00 72 00 74 00 65 00 6c 00 6c 00 61 00 5f 00 64 00 69 00 5f 00 6c 00 61 00 76 00 6f 00 72 00 6f 00 00 00 46 6f 67 6c 69 6f 31 00 46 00 6f 00 67 00 6c 00 69 00 6f 00 31 00 00 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:3023
                                                                                                                                                  Entropy:4.45469940064
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 .
                                                                                                                                                  Data Raw:cc 61 b5 00 00 03 00 ff 10 04 00 00 09 04 00 00 e4 04 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_0
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:2012
                                                                                                                                                  Entropy:3.39576153821
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:. K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ Z . . . . . . . . . . . . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . . d . . . . 8 G . . . o S W . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:93 4b 2a b5 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 00 00 00 00 00 00 01 00 02 00 00 00 00 00 00 00 01 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 00 00 72 55 c0 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 06 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_1
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:252
                                                                                                                                                  Entropy:1.8302935157
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . e d . . . . . . . . . . . . . . . . s . . . . . . . . . . . . . . . . b i R . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:72 55 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 7e 7a 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 12 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 ff ff ff ff ff ff ff ff 06 00 00 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_2
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:2641
                                                                                                                                                  Entropy:1.97225478766
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U . . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 . ` . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:72 55 c0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 d0 00 00 00 00 00 00 00 00 00 00 00 0d 00 0d 00 00 00 00 00 01 00 01 00 00 00 01 00 d1 03 00 00 00 00 00 00 00 00 00 00 11 08 00 00 00 00 00 00 00 00 00 00 41 08
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/__SRP_3
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:926
                                                                                                                                                  Entropy:2.47413380681
                                                                                                                                                  Base64 Encoded:False
                                                                                                                                                  Data ASCII:r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . @ . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P . @ . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O . @ . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                                                  Data Raw:72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 40 00 e1 01 00 00 00 00 00 00 00 00 02 00 00 00 03 60 04 01 d9 08 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00
                                                                                                                                                  General
                                                                                                                                                  Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                                                                                                                                  File Type:data
                                                                                                                                                  Stream Size:562
                                                                                                                                                  Entropy:6.2614646746
                                                                                                                                                  Base64 Encoded:True
                                                                                                                                                  Data ASCII:. . . . . . . . . . . . 0 . J . . . . H . . H . . . . . . H . . . d . . . . . . . . V B A P r @ o j e c t . . . . T . @ . . . . . = . . . + . r . . . . . . . . 7 . . . c . . . . J < . . . . . . 9 s t d o l . e > . . s . t . d . . o . l . e . . . . h . % ^ . . * \\ G . { 0 0 0 2 0 4 3 . 0 - . . . . C . . . . . . . 0 0 4 6 } # 2 . . 0 # 0 # C : \\ W . i n d o w s \\ S . y s t e m 3 2 \\ . . e 2 . t l b # O . L E A u t o m . a t i o n . 0 . . . E O f f i c . E O . . f . . i . c . E . . . . . . . . E 2 D F 8 D
                                                                                                                                                  Data Raw:01 2e b2 80 01 00 04 00 00 00 03 00 30 aa 4a 02 90 02 00 48 02 02 48 09 00 c0 12 14 06 48 03 00 01 64 e4 04 04 04 00 0a 00 84 56 42 41 50 72 40 6f 6a 65 63 74 05 00 1a 00 54 00 40 02 0a 06 02 0a 3d 02 0a 07 2b 02 72 01 14 08 06 12 09 02 12 37 08 a0 e3 63 0d 00 0c 02 4a 3c 02 0a 04 16 00 01 39 73 74 64 6f 6c 04 65 3e 02 19 73 00 74 00 64 00 00 6f 00 6c 00 65 00 0d 14 00 68 00 25 5e
                                                                                                                                                  No network behavior found
                                                                                                                                                  No statistics
                                                                                                                                                  Start time:11:03:04
                                                                                                                                                  Start date:24/01/2022
                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding
                                                                                                                                                  Imagebase:0xe80000
                                                                                                                                                  File size:27110184 bytes
                                                                                                                                                  MD5 hash:5D6638F2C8F8571C593999C58866007E
                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                  Reputation:high

                                                                                                                                                  No disassembly