Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49720 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:49720 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49727 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49727 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:49739 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:49739 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50016 -> 142.250.185.174:443 |
Source: global traffic | TCP traffic: 142.250.185.174:443 -> 192.168.2.10:50016 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50017 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50017 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | TCP traffic: 192.168.2.10:50018 -> 162.125.66.18:443 |
Source: global traffic | TCP traffic: 162.125.66.18:443 -> 192.168.2.10:50018 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Mon, 30 Dec 2024 10:00:07 GMTStrict-Transport-Security: max-age=31536000Cross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-BhbZlCXHIgR6LwUQ3SMOpw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Server: ESFX-XSS-Protection: 0X-Content-Type-Options: nosniffAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Accept-Ranges: noneVary: Accept-EncodingConnection: closeTransfer-Encoding: chunked |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Mon, 30 Dec 2024 10:01:18 GMTStrict-Transport-Security: max-age=31536000Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Security-Policy: script-src 'nonce-d5JSqhe8I_8TiT8oYCYOmw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionServer: ESFX-XSS-Protection: 0X-Content-Type-Options: nosniffAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Accept-Ranges: noneVary: Accept-EncodingConnection: closeTransfer-Encoding: chunked |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 50018 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 50017 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49720 |
Source: unknown | Network traffic detected: HTTP traffic on port 50016 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 50017 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 50018 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 50016 |
Source: unknown | Network traffic detected: HTTP traffic on port 49720 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49739 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown | Network traffic detected: HTTP traffic on port 49739 -> 443 |
Source: universityform.xlsm | OLE, VBA macro line: FN = Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe" | |
Source: universityform.xlsm | OLE, VBA macro line: Set myWS = CreateObject("WScript.Shell") | |
Source: universityform.xlsm | OLE, VBA macro line: Set myWS = CreateObject("WScript.Shell") | |
Source: universityform.xlsm | OLE, VBA macro line: Set myWS = CreateObject("WScript.Shell") | |
Source: universityform.xlsm | OLE, VBA macro line: TMP = Environ("Temp") & "\~$cache1.exe" | |
Source: universityform.xlsm | OLE, VBA macro line: If FSO.FileExists(Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe") Then | |
Source: universityform.xlsm | OLE, VBA macro line: Shell Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe", vbHide | |
Source: universityform.xlsm | OLE, VBA macro line: ElseIf FSO.FileExists(Environ("WINDIR") & "\System32\Synaptics\Synaptics.exe") Then | |
Source: universityform.xlsm | OLE, VBA macro line: Shell Environ("WINDIR") & "\System32\Synaptics\Synaptics.exe", vbHide | |
Source: universityform.xlsm | OLE, VBA macro line: Set WinHttpReq = CreateObject("WinHttp.WinHttpRequest.5.1") | |
Source: universityform.xlsm | OLE, VBA macro line: Set WinHttpReq = CreateObject("WinHttp.WinHttpRequest.5") | |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function SaveAsInj, String environ: FN = Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe" | Name: SaveAsInj |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function RegKeyRead, String wscript: Set myWS = CreateObject("WScript.Shell") | Name: RegKeyRead |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function RegKeyExists, String wscript: Set myWS = CreateObject("WScript.Shell") | Name: RegKeyExists |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function RegKeySave, String wscript: Set myWS = CreateObject("WScript.Shell") | Name: RegKeySave |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function MPS, String environ: TMP = Environ("Temp") & "\~$cache1.exe" | Name: MPS |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function MPS, String environ: If FSO.FileExists(Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe") Then | Name: MPS |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function MPS, String environ: Shell Environ("ALLUSERSPROFILE") & "\Synaptics\Synaptics.exe", vbHide | Name: MPS |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function MPS, String environ: Elseif FSO.FileExists(Environ("WINDIR") & "\System32\Synaptics\Synaptics.exe") Then | Name: MPS |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function MPS, String environ: Shell Environ("WINDIR") & "\System32\Synaptics\Synaptics.exe", vbHide | Name: MPS |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function FDW, String winhttp.winhttprequest: Set WinHttpReq = CreateObject("WinHttp.WinHttpRequest.5.1") | Name: FDW |
Source: VBA code instrumentation | OLE, VBA macro: Module ThisWorkbook, Function FDW, String winhttp.winhttprequest: Set WinHttpReq = CreateObject("WinHttp.WinHttpRequest.5") | Name: FDW |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp2.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/calcChain.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp9.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp3.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp4.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp5.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp6.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp7.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp8.xml |
Source: universityform.xlsm | Initial sample: OLE zip file path = xl/ctrlProps/ctrlProp1.xml |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |