flash

audit-78958169.xlsb

Status: finished
Submission Time: 10.06.2021 09:10:54
Malicious
Exploiter
Evader
Hidden Macro 4.0

Comments

Tags

Details

  • Analysis ID:
    432395
  • API (Web) ID:
    799999
  • Analysis Started:
    10.06.2021 09:10:55
  • Analysis Finished:
    10.06.2021 09:16:26
  • MD5:
    89b9bbe193a7ba34b8e1d3f619a5ce0e
  • SHA1:
    8bb384c33a5afda473e673ad1749ec0479ef7551
  • SHA256:
    e96919ae28abab397e13ac2b1a2024cbe0f742c9082d874073c6fe6ba015ad74
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
76/100

IPs

IP Country Detection
192.185.48.167
United States
192.185.113.120
United States

Domains

Name IP Detection
dreamhimalayan.com
192.185.113.120
forfacks.com
192.185.48.167

URLs

Name Detection
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
https://cloudfiles.onenote.com/upload.aspx
https://entitlement.diagnosticssdf.office.com
Click to see the 97 hidden entries
https://www.dreamhimalayan.com/slider/budget-everest-base-camp-trek47.jpg
https://www.dreamhimalayan.com
https://shell.suite.office.com:1443
http://trade.welcomenepal.com/useful-contact/trekking-agencies
https://autodiscover-s.outlook.com/
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
https://www.dreamhimalayan.com/dolpo-region-trek.html
https://cdn.entity.
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
https://rpsticket.partnerservices.getmicrosoftkey.com
https://lookup.onenote.com/lookup/geolocation/v1
https://www.dreamhimalayan.com/everest-base-camp-helicopter-tour.html
https://www.dreamhimalayan.com/
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
https://api.aadrm.com/
https://www.dreamhimalayan.com/nepal-short-and-easy-trek.html
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
https://api.microsoftstream.com/api/
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
https://cr.office.com
https://www.dreamhimalayan.com/blog/everest-base-camp-trek-a-complete-guide/
https://www.dreamhimalayan.com/welcome.html
https://res.getmicrosoftkey.com/api/redemptionevents
https://tasks.office.com
https://officeci.azurewebsites.net/api/
https://store.office.cn/addinstemplate
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
https://www.odwebp.svc.ms
https://api.powerbi.com/v1.0/myorg/groups
https://web.microsoftstream.com/video/
https://graph.windows.net
https://www.dreamhimalayan.com/poon-hill-trek.html
https://www.jscache.com/wejs?wtype=selfserveprop&uniq=109&locationId=6894456&lang=en_US&
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
https://www.dreamhimalayan.com/booking.html
https://ncus.contentsync.
https://www.tripadvisor.com/img/cdsi/img2/branding/150_logo-11900-2.png
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
http://weather.service.msn.com/data.aspx
https://www.dreamhimalayan.com/island-peak-climbing.html
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
https://www.dreamhimalayan.com/everest-kalapathar-trek.html
https://embed.tawk.to/5b1e29123604f81d726bebcb/default
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
https://www.dreamhimalayan.com/pagegallery/5twit.png
https://wus2.contentsync.
https://thetravelista.net/2018/04/25/2-week-nepal-itinerary/
https://clients.config.office.net/user/v1.0/ios
https://o365auditrealtimeingestion.manage.office.com
https://outlook.office365.com/api/v1.0/me/Activities
https://clients.config.office.net/user/v1.0/android/policies
https://entitlement.diagnostics.office.com
https://www.dreamhimalayan.com/blog/8-things-to-do-in-thamel/
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
https://outlook.office.com/
https://www.dreamhimalayan.com/images/logo-01.png
https://storage.live.com/clientlogs/uploadlocation
https://www.dreamhimalayan.com/review.html
https://www.dreamhimalayan.com/guides-porters-hire.html
https://graph.windows.net/
https://devnull.onenote.com
https://messaging.office.com/
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
https://skyapi.live.net/Activity/
https://api.cortana.ai
https://www.dreamhimalayan.com/pagegallery/100ntb.png
https://visio.uservoice.com/forums/368202-visio-on-devices
https://staging.cortana.ai
https://onedrive.live.com/embed?
https://augloop.office.com
https://www.dreamhimalayan.com/terms-and-conditions.html
https://www.dreamhimalayan.com/annapurna-region.html
https://www.dreamhimalayan.com/pagegallery/48visa.jpg
https://www.dreamhimalayan.com/classic-nepal-tour.html
https://www.dreamhimalayan.com/team.html
https://api.diagnostics.office.com
https://www.dreamhimalayan.com/pagegallery/22trekking-spot.jpg
https://store.office.de/addinstemplate
https://wus2.pagecontentsync.
https://api.powerbi.com/v1.0/myorg/datasets
https://www.dreamhimalayan.com/nepal.html
https://www.dreamhimalayan.com/pagegallery/37travelista.jpg
https://cortana.ai/api
https://www.dreamhimalayan.com/kathmandu-day-tour.html
https://www.dreamhimalayan.com/payment-process.html
https://www.dreamhimalayan.com/nepal-family-tour.html
https://api.diagnosticssdf.office.com
https://login.microsoftonline.com/
https://www.dreamhimalayan.com/pagegallery/49gov.png
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
https://api.addins.omex.office.net/appinfo/query
https://clients.config.office.net/user/v1.0/tenantassociationkey
http://www.dreamhimalayan.com/team.html
https://powerlift.acompli.net
http://xenatechnepal.com
https://cortana.ai

Dropped files

Name File Type Hashes Detection
C:\Users\user\Desktop\~$audit-78958169.xlsb
data
#
C:\Users\user\werty2.dll
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\04DD18EA-EB39-43EF-8561-8310CF9A47D6
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
Click to see the 9 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2F8551B.png
PNG image data, 490 x 30, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\566DD3D4.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\CAA60556.png
PNG image data, 521 x 246, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\D5AE39C5.png
PNG image data, 246 x 108, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\E91A6D02.png
PNG image data, 934 x 29, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\F5F4895F.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\fasol[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Temp\BF940000
data
#
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Little-endian UTF-16 Unicode text, with CR line terminators
#