Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
B317.xlsx

Overview

General Information

Sample name:B317.xlsx
Analysis ID:1590252
MD5:d3d62038201b0d42795c2983d47aca33
SHA1:bc1cf5e7443582a9ed0e15b07cf975ba3f2a90dd
SHA256:06ece98e9271215b6b7a7eb7c13463569c980b12e45565d63ac7e93ce43371a8
Tags:HUNxlsxuser-smica83
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Contains an external reference to another file
Detected non-DNS traffic on DNS port
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Unable to load, office file is protected or invalid

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 2772 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 6700 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 3608 cmdline: MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: B317.xlsxVirustotal: Detection: 14%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: global trafficDNS query: name: 15.164.165.52.in-addr.arpa
Source: global trafficTCP traffic: 192.168.2.8:59164 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.8:59164
Source: global trafficTCP traffic: 192.168.2.8:59164 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.8:59164
Source: global trafficTCP traffic: 192.168.2.8:59164 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.8:59164
Source: global trafficTCP traffic: 192.168.2.8:59164 -> 162.159.36.2:53
Source: excel.exeMemory has grown: Private usage: 1MB later: 116MB
Source: global trafficTCP traffic: 192.168.2.8:59164 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: 15.164.165.52.in-addr.arpa
Source: B317.xlsxOLE, VBA macro line: Private Sub Workbook_Open()
Source: B317.xls.0.drOLE, VBA macro line: Private Sub Workbook_Open()
Source: B317.xlsxOLE indicator, VBA macros: true
Source: B317.xlsxOLE indicator, VBA macros: true
Source: B317.xlsxOLE indicator, VBA macros: true
Source: B317.xls.0.drOLE indicator, VBA macros: true
Source: B317.xls.0.drOLE indicator, VBA macros: true
Source: B317.xls.0.drOLE indicator, VBA macros: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'b317.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal52.evad.winXLSX@4/5@1/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$B317.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{946CCE71-E462-4D8B-ABC8-A49E0DA057A7} - OProcSessId.datJump to behavior
Source: B317.xlsxOLE indicator, Workbook stream: true
Source: B317.xlsxOLE indicator, Workbook stream: true
Source: B317.xlsxOLE indicator, Workbook stream: true
Source: B317.xls.0.drOLE indicator, Workbook stream: true
Source: B317.xls.0.drOLE indicator, Workbook stream: true
Source: B317.xls.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: B317.xlsxVirustotal: Detection: 14%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet4.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet5.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet6.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet7.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet8.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet9.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet10.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet11.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet12.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/sheet13.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet11.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet13.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/drawings/vmlDrawing2.vml
Source: B317.xlsxInitial sample: OLE zip file path = xl/drawings/_rels/vmlDrawing4.vml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet8.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/drawings/vmlDrawing4.vml
Source: B317.xlsxInitial sample: OLE zip file path = xl/media/image3.emf
Source: B317.xlsxInitial sample: OLE zip file path = xl/media/image4.emf
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet6.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet7.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/worksheets/_rels/sheet9.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/drawings/vmlDrawing3.vml
Source: B317.xlsxInitial sample: OLE zip file path = xl/media/image2.png
Source: B317.xlsxInitial sample: OLE zip file path = xl/externalLinks/externalLink1.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/metadata.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings4.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings5.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings6.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp1.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp2.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp3.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp4.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp5.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp6.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp7.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp8.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp9.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings7.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings8.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings9.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/comments2.xml
Source: B317.xlsxInitial sample: OLE zip file path = customXml/item2.xml
Source: B317.xlsxInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: B317.xlsxInitial sample: OLE zip file path = customXml/item3.xml
Source: B317.xlsxInitial sample: OLE zip file path = customXml/itemProps3.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings14.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/revisionHeaders.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/revisionLog4.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/userNames.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings12.bin
Source: B317.xlsxInitial sample: OLE zip file path = docProps/custom.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings11.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings10.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings15.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/comments3.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings13.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/comments1.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings16.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings17.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/printerSettings/printerSettings18.bin
Source: B317.xlsxInitial sample: OLE zip file path = xl/externalLinks/_rels/externalLink1.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/calcChain.xml
Source: B317.xlsxInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = customXml/_rels/item3.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/_rels/revisionHeaders.xml.rels
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/revisionLog1.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/revisionLog3.xml
Source: B317.xlsxInitial sample: OLE zip file path = xl/revisions/revisionLog2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet4.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet5.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet6.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet7.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet8.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet9.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet10.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet11.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet12.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/sheet13.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/media/image2.png
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet11.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet13.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/drawings/_rels/vmlDrawing4.vml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/drawings/vmlDrawing2.vml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet6.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/drawings/vmlDrawing3.vml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/drawings/drawing2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/drawings/vmlDrawing4.vml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/media/image3.emf
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/media/image4.emf
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet7.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet8.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/worksheets/_rels/sheet9.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/externalLinks/externalLink1.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/metadata.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings4.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings5.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings6.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings7.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings8.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp1.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp3.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp4.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp5.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp6.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp7.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp8.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/comments1.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings9.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings10.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings11.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings12.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings23.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings24.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/calcChain.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = customXml/item2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings20.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionHeaders.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings14.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/userNames.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = docProps/custom.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings13.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/comments2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings16.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/ctrlProps/ctrlProp9.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/comments3.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings17.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings18.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings15.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings19.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/externalLinks/_rels/externalLink1.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings21.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/printerSettings/printerSettings22.bin
Source: B317.xls.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/_rels/revisionHeaders.xml.rels
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionLog5.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionLog3.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionLog2.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionLog1.xml
Source: B317.xls.0.drInitial sample: OLE zip file path = xl/revisions/revisionLog4.xml
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: B317.xlsxStatic file information: File size 3694114 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior

Persistence and Installation Behavior

barindex
Source: externalLink1.xml.relsExtracted files from sample: https://ntsit-my.sharepoint.com/personal/danielle_white_nqa_com/documents/microsoft%20teams%20chat%20files/nqa%20contract%20review%20-%20single%20site%20-%20issue%204%20draft%20release.xlsm
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 1824Jump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 8098Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts2
Exploitation for Client Execution
2
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
B317.xlsx14%VirustotalBrowse
B317.xlsx8%ReversingLabsScript-Macro.Malware.Amphitryon
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0017.t-0009.t-msedge.net
13.107.246.45
truefalse
    high
    15.164.165.52.in-addr.arpa
    unknown
    unknownfalse
      high
      No contacted IP infos
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1590252
      Start date and time:2025-01-13 20:31:12 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 12m 28s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsofficecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:13
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Sample name:B317.xlsx
      Detection:MAL
      Classification:mal52.evad.winXLSX@4/5@1/0
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .xlsx
      • Found Word or Excel or PowerPoint or XPS Viewer
      • Attach to Office via COM
      • Active ActiveX Object
      • Active ActiveX Object
      • Scroll down
      • Close Viewer
      • Override analysis time to -10384.5276 for current running targets taking high CPU consumption
      • Override analysis time to -20769.0552 for current running targets taking high CPU consumption
      • Override analysis time to -41538.1104 for current running targets taking high CPU consumption
      • Override analysis time to -83076.2208 for current running targets taking high CPU consumption
      • Override analysis time to -166152.4416 for current running targets taking high CPU consumption
      • Override analysis time to -332304.8832 for current running targets taking high CPU consumption
      • Override analysis time to -664609.7664 for current running targets taking high CPU consumption
      • Override analysis time to -1329219.5328 for current running targets taking high CPU consumption
      • Override analysis time to -2658439.0656 for current running targets taking high CPU consumption
      • Override analysis time to -5316878.1312 for current running targets taking high CPU consumption
      • Override analysis time to -10633756.2624 for current running targets taking high CPU consumption
      • Override analysis time to -21267512.5248 for current running targets taking high CPU consumption
      • Override analysis time to -42535025.0496 for current running targets taking high CPU consumption
      • Override analysis time to -85070050.0992 for current running targets taking high CPU consumption
      • Override analysis time to -170140100.1984 for current running targets taking high CPU consumption
      • Override analysis time to -340280200.3968 for current running targets taking high CPU consumption
      • Override analysis time to -680560400.7936 for current running targets taking high CPU consumption
      • Override analysis time to -1361120801.5872 for current running targets taking high CPU consumption
      • Override analysis time to -2722241603.1744 for current running targets taking high CPU consumption
      • Override analysis time to -5444483206.3488 for current running targets taking high CPU consumption
      • Override analysis time to -10888966412.6976 for current running targets taking high CPU consumption
      • Override analysis time to -21777932825.3952 for current running targets taking high CPU consumption
      • Override analysis time to -43555865650.7904 for current running targets taking high CPU consumption
      • Override analysis time to -87111731301.5808 for current running targets taking high CPU consumption
      • Override analysis time to -174223462603.162 for current running targets taking high CPU consumption
      • Override analysis time to -348446925206.323 for current running targets taking high CPU consumption
      • Override analysis time to -696893850412.646 for current running targets taking high CPU consumption
      • Override analysis time to -1393787700825.29 for current running targets taking high CPU consumption
      • Override analysis time to -2787575401650.59 for current running targets taking high CPU consumption
      • Override analysis time to -5575150803301.17 for current running targets taking high CPU consumption
      • Override analysis time to -11150301606602.3 for current running targets taking high CPU consumption
      • Override analysis time to -22300603213204.7 for current running targets taking high CPU consumption
      • Override analysis time to -44601206426409.4 for current running targets taking high CPU consumption
      • Override analysis time to -89202412852818.8 for current running targets taking high CPU consumption
      • Override analysis time to -178404825705638 for current running targets taking high CPU consumption
      • Override analysis time to -356809651411275 for current running targets taking high CPU consumption
      • Override analysis time to -713619302822550 for current running targets taking high CPU consumption
      • Override analysis time to -1.4272386056451e+15 for current running targets taking high CPU consumption
      • Override analysis time to -2.8544772112902e+15 for current running targets taking high CPU consumption
      • Override analysis time to -5.7089544225804e+15 for current running targets taking high CPU consumption
      • Override analysis time to -1.14179088451608e+16 for current running targets taking high CPU consumption
      • Override analysis time to -2.28358176903216e+16 for current running targets taking high CPU consumption
      • Override analysis time to -4.56716353806432e+16 for current running targets taking high CPU consumption
      • Override analysis time to -9.13432707612864e+16 for current running targets taking high CPU consumption
      • Override analysis time to -1.82686541522573e+17 for current running targets taking high CPU consumption
      • Override analysis time to -3.65373083045146e+17 for current running targets taking high CPU consumption
      • Override analysis time to -7.30746166090291e+17 for current running targets taking high CPU consumption
      • Override analysis time to -1.46149233218058e+18 for current running targets taking high CPU consumption
      • Override analysis time to -2.92298466436116e+18 for current running targets taking high CPU consumption
      • Override analysis time to -5.84596932872233e+18 for current running targets taking high CPU consumption
      • Override analysis time to -1.16919386574447e+19 for current running targets taking high CPU consumption
      • Override analysis time to -2.33838773148893e+19 for current running targets taking high CPU consumption
      • Override analysis time to -4.67677546297786e+19 for current running targets taking high CPU consumption
      • Override analysis time to -9.35355092595573e+19 for current running targets taking high CPU consumption
      • Override analysis time to -1.87071018519115e+20 for current running targets taking high CPU consumption
      • Override analysis time to -3.74142037038229e+20 for current running targets taking high CPU consumption
      • Override analysis time to -7.48284074076458e+20 for current running targets taking high CPU consumption
      • Override analysis time to -1.49656814815292e+21 for current running targets taking high CPU consumption
      • Override analysis time to -2.99313629630583e+21 for current running targets taking high CPU consumption
      • Override analysis time to -5.98627259261167e+21 for current running targets taking high CPU consumption
      • Override analysis time to -1.19725451852233e+22 for current running targets taking high CPU consumption
      • Override analysis time to -2.39450903704467e+22 for current running targets taking high CPU consumption
      • Override analysis time to -4.78901807408933e+22 for current running targets taking high CPU consumption
      • Override analysis time to -9.57803614817866e+22 for current running targets taking high CPU consumption
      • Override analysis time to -1.91560722963573e+23 for current running targets taking high CPU consumption
      • Override analysis time to -3.83121445927147e+23 for current running targets taking high CPU consumption
      • Override analysis time to -7.66242891854293e+23 for current running targets taking high CPU consumption
      • Override analysis time to -1.53248578370859e+24 for current running targets taking high CPU consumption
      • Override analysis time to -3.06497156741717e+24 for current running targets taking high CPU consumption
      • Override analysis time to -6.12994313483435e+24 for current running targets taking high CPU consumption
      • Override analysis time to -1.22598862696687e+25 for current running targets taking high CPU consumption
      • Override analysis time to -2.45197725393374e+25 for current running targets taking high CPU consumption
      • Override analysis time to -4.90395450786748e+25 for current running targets taking high CPU consumption
      • Override analysis time to -9.80790901573495e+25 for current running targets taking high CPU consumption
      • Override analysis time to -1.96158180314699e+26 for current running targets taking high CPU consumption
      • Override analysis time to -3.92316360629398e+26 for current running targets taking high CPU consumption
      • Override analysis time to -7.84632721258796e+26 for current running targets taking high CPU consumption
      • Override analysis time to -1.56926544251759e+27 for current running targets taking high CPU consumption
      • Override analysis time to -3.13853088503518e+27 for current running targets taking high CPU consumption
      • Override analysis time to -6.27706177007037e+27 for current running targets taking high CPU consumption
      • Override analysis time to -1.25541235401407e+28 for current running targets taking high CPU consumption
      • Override analysis time to -2.51082470802815e+28 for current running targets taking high CPU consumption
      • Override analysis time to -5.0216494160563e+28 for current running targets taking high CPU consumption
      • Override analysis time to -1.00432988321126e+29 for current running targets taking high CPU consumption
      • Override analysis time to -2.00865976642252e+29 for current running targets taking high CPU consumption
      • Override analysis time to -4.01731953284504e+29 for current running targets taking high CPU consumption
      • Override analysis time to -8.03463906569007e+29 for current running targets taking high CPU consumption
      • Override analysis time to -1.60692781313801e+30 for current running targets taking high CPU consumption
      • Override analysis time to -3.21385562627603e+30 for current running targets taking high CPU consumption
      • Override analysis time to -6.42771125255206e+30 for current running targets taking high CPU consumption
      • Override analysis time to -1.28554225051041e+31 for current running targets taking high CPU consumption
      • Override analysis time to -2.57108450102082e+31 for current running targets taking high CPU consumption
      • Override analysis time to -5.14216900204165e+31 for current running targets taking high CPU consumption
      • Override analysis time to -1.02843380040833e+32 for current running targets taking high CPU consumption
      • Override analysis time to -2.05686760081666e+32 for current running targets taking high CPU consumption
      • Override analysis time to -4.11373520163332e+32 for current running targets taking high CPU consumption
      • Override analysis time to -8.22747040326664e+32 for current running targets taking high CPU consumption
      • Override analysis time to -1.64549408065333e+33 for current running targets taking high CPU consumption
      • Override analysis time to -3.29098816130665e+33 for current running targets taking high CPU consumption
      • Override analysis time to -6.58197632261331e+33 for current running targets taking high CPU consumption
      • Override analysis time to -1.31639526452266e+34 for current running targets taking high CPU consumption
      • Override analysis time to -2.63279052904532e+34 for current running targets taking high CPU consumption
      • Override analysis time to -5.26558105809065e+34 for current running targets taking high CPU consumption
      • Override analysis time to -1.05311621161813e+35 for current running targets taking high CPU consumption
      • Override analysis time to -2.10623242323626e+35 for current running targets taking high CPU consumption
      • Override analysis time to -4.21246484647252e+35 for current running targets taking high CPU consumption
      • Override analysis time to -8.42492969294503e+35 for current running targets taking high CPU consumption
      • Override analysis time to -1.68498593858901e+36 for current running targets taking high CPU consumption
      • Override analysis time to -3.36997187717801e+36 for current running targets taking high CPU consumption
      • Override analysis time to -6.73994375435603e+36 for current running targets taking high CPU consumption
      • Override analysis time to -1.34798875087121e+37 for current running targets taking high CPU consumption
      • Override analysis time to -2.69597750174241e+37 for current running targets taking high CPU consumption
      • Override analysis time to -5.39195500348482e+37 for current running targets taking high CPU consumption
      • Override analysis time to -1.07839100069696e+38 for current running targets taking high CPU consumption
      • Override analysis time to -2.15678200139393e+38 for current running targets taking high CPU consumption
      • Override analysis time to -4.31356400278786e+38 for current running targets taking high CPU consumption
      • Override analysis time to -8.62712800557572e+38 for current running targets taking high CPU consumption
      • Override analysis time to -1.72542560111514e+39 for current running targets taking high CPU consumption
      • Override analysis time to -3.45085120223029e+39 for current running targets taking high CPU consumption
      • Override analysis time to -6.90170240446057e+39 for current running targets taking high CPU consumption
      • Override analysis time to -1.38034048089211e+40 for current running targets taking high CPU consumption
      • Override analysis time to -2.76068096178423e+40 for current running targets taking high CPU consumption
      • Override analysis time to -5.52136192356846e+40 for current running targets taking high CPU consumption
      • Override analysis time to -1.10427238471369e+41 for current running targets taking high CPU consumption
      • Override analysis time to -2.20854476942738e+41 for current running targets taking high CPU consumption
      • Override analysis time to -4.41708953885477e+41 for current running targets taking high CPU consumption
      • Override analysis time to -8.83417907770953e+41 for current running targets taking high CPU consumption
      • Override analysis time to -1.76683581554191e+42 for current running targets taking high CPU consumption
      • Override analysis time to -3.53367163108381e+42 for current running targets taking high CPU consumption
      • Override analysis time to -7.06734326216763e+42 for current running targets taking high CPU consumption
      • Override analysis time to -1.41346865243353e+43 for current running targets taking high CPU consumption
      • Override analysis time to -2.82693730486705e+43 for current running targets taking high CPU consumption
      • Override analysis time to -5.6538746097341e+43 for current running targets taking high CPU consumption
      • Override analysis time to -1.13077492194682e+44 for current running targets taking high CPU consumption
      • Override analysis time to -2.26154984389364e+44 for current running targets taking high CPU consumption
      • Override analysis time to -4.52309968778728e+44 for current running targets taking high CPU consumption
      • Override analysis time to -9.04619937557456e+44 for current running targets taking high CPU consumption
      • Override analysis time to -1.80923987511491e+45 for current running targets taking high CPU consumption
      • Override analysis time to -3.61847975022982e+45 for current running targets taking high CPU consumption
      • Override analysis time to -7.23695950045965e+45 for current running targets taking high CPU consumption
      • Override analysis time to -1.44739190009193e+46 for current running targets taking high CPU consumption
      • Override analysis time to -2.89478380018386e+46 for current running targets taking high CPU consumption
      • Override analysis time to -5.78956760036772e+46 for current running targets taking high CPU consumption
      • Override analysis time to -1.15791352007354e+47 for current running targets taking high CPU consumption
      • Override analysis time to -2.31582704014709e+47 for current running targets taking high CPU consumption
      • Override analysis time to -4.63165408029418e+47 for current running targets taking high CPU consumption
      • Override analysis time to -9.26330816058835e+47 for current running targets taking high CPU consumption
      • Max analysis timeout: 600s exceeded, the analysis took too long
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 52.109.76.240, 52.109.68.129, 2.23.242.162, 52.113.194.132, 20.189.173.5, 52.109.32.97, 20.42.65.90, 52.168.117.170, 20.109.210.53, 20.190.160.20, 52.165.164.15, 172.202.163.200, 13.107.246.45
      • Excluded domains from analysis (whitelisted): onedscolprdwus04.westus.cloudapp.azure.com, slscr.update.microsoft.com, otelrules.afd.azureedge.net, onedscolprdeus14.eastus.cloudapp.azure.com, eur.roaming1.live.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, e16604.g.akamaiedge.net, frc-azsc-000.roaming.officeapps.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, ukw-azsc-config.officeapps.live.com, onedscolprdeus13.eastus.cloudapp.azure.com, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, osiprod-frc-buff-azsc-000.francecentral.cloudapp.azure.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, neu-azsc-config.officeapps.live.com, s-0005.s-msedge
      • Not all processes where analyzed, report is missing behavior information
      • Report size exceeded maximum capacity and may have missing behavior information.
      • Report size getting too big, too many NtCreateKey calls found.
      • Report size getting too big, too many NtQueryAttributesFile calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtReadVirtualMemory calls found.
      TimeTypeDescription
      14:32:29API Interceptor21808603x Sleep call for process: splwow64.exe modified
      No context
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      s-part-0017.t-0009.t-msedge.nethttps://docusign.legalcloudfiles.com/S06ga?e=clopez@autopistacentral.clGet hashmaliciousHTMLPhisherBrowse
      • 13.107.246.45
      https://maya-lopez.filemail.com/t/XhcWEjoRGet hashmaliciousUnknownBrowse
      • 13.107.246.45
      Handler.exeGet hashmaliciousDanaBot, VidarBrowse
      • 13.107.246.45
      Scan.htmlGet hashmaliciousHTMLPhisherBrowse
      • 13.107.246.45
      JUbmpeT.exeGet hashmaliciousVidarBrowse
      • 13.107.246.45
      https://www.google.ca/url?0g1qta=https://www.flowersgarrett.au&Qg=P4&bg=FN&TA=Z1&bg=PR&TA=UN&q=%2561%256d%2570%2F%2562%2563%2535%256D%2537%2579%252E%2564%2565%256B%2563%2568%256F%2562%2574%2569%2565%2577%252E%2563%256F%256D%252F%256A%256D%2561%257A%256F%2575%2572%2540%2569%256E%256F%2576%2561%256C%256F%256E%252E%2563%256F%256D&opdg=QXY&dUM=MTA&eTY=azMGet hashmaliciousHTMLPhisherBrowse
      • 13.107.246.45
      https://docusign.legalcloudfiles.com/S06ga?e=kelly.wright@sanctuary-housing.co.ukGet hashmaliciousHTMLPhisherBrowse
      • 13.107.246.45
      Invoice and packing list.exeGet hashmaliciousFormBook, PureLog StealerBrowse
      • 13.107.246.45
      http://id1223.adsalliance.xyzGet hashmaliciousUnknownBrowse
      • 13.107.246.45
      Cardfactory Executed Agreement DocsID- Sign & Review..emlGet hashmaliciousHTMLPhisherBrowse
      • 13.107.246.45
      No context
      No context
      No context
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:dropped
      Size (bytes):118
      Entropy (8bit):3.5700810731231707
      Encrypted:false
      SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
      MD5:573220372DA4ED487441611079B623CD
      SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
      SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
      SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
      Malicious:false
      Reputation:high, very likely benign file
      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:Microsoft Excel 2007+
      Category:dropped
      Size (bytes):3710744
      Entropy (8bit):7.949532484957742
      Encrypted:false
      SSDEEP:98304:FS4kaZJjgyniSh8SLTNcKeZbyImD8jMoJk:I4kaZdgyniSh8SeKeZYJj
      MD5:DAFE0C727FAE4BF4947AB8C5CF3F12E7
      SHA1:BD56AF3974914E1511B9B41B73EECE6375E46469
      SHA-256:90E12D4E2E6B847D5AAB6C96370A7C8A9D793B78991CCF4B85AD47D1C300D7BD
      SHA-512:47F74A69C381FD913B360075B779B5516564D5FEB646DAFF2BB99FE748282A0545A5F8B324F6E4E22432F80B092FF4DA024F509216A7D0C50319BC0B011280A5
      Malicious:false
      Reputation:low
      Preview:PK..........!..Q".....C.......[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................Y]o.0.}.....:.C.u.T......R;i....?".P..w...h ....@..sN......J.....Z..a:Hz......_._.gI.:.2*..Q..6..x....9...heG....!..@R.....L....G3%9es:.r2.........c$...0...z7+..T2.*.]...T.....:.J.*.!...3.4[H.Nmn.fv..Hs...sxc6!.. ';.\z.....y.aZ.T....>.._.a@...Q.;.."ev.s..'e...G.....}...#.Y..........n.'.....q?..!+A........A|MI.......J..Qt,..(W...`*"-).......e...>R.IGt......#:N;..SGt.uD......".+;.+[....^.(*n..[..)..m
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:Microsoft Excel 2007+
      Category:dropped
      Size (bytes):3710744
      Entropy (8bit):7.949532484957742
      Encrypted:false
      SSDEEP:98304:FS4kaZJjgyniSh8SLTNcKeZbyImD8jMoJk:I4kaZdgyniSh8SeKeZYJj
      MD5:DAFE0C727FAE4BF4947AB8C5CF3F12E7
      SHA1:BD56AF3974914E1511B9B41B73EECE6375E46469
      SHA-256:90E12D4E2E6B847D5AAB6C96370A7C8A9D793B78991CCF4B85AD47D1C300D7BD
      SHA-512:47F74A69C381FD913B360075B779B5516564D5FEB646DAFF2BB99FE748282A0545A5F8B324F6E4E22432F80B092FF4DA024F509216A7D0C50319BC0B011280A5
      Malicious:false
      Reputation:low
      Preview:PK..........!..Q".....C.......[Content_Types].xml ...(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................Y]o.0.}.....:.C.u.T......R;i....?".P..w...h ....@..sN......J.....Z..a:Hz......_._.gI.:.2*..Q..6..x....9...heG....!..@R.....L....G3%9es:.r2.........c$...0...z7+..T2.*.]...T.....:.J.*.!...3.4[H.Nmn.fv..Hs...sxc6!.. ';.\z.....y.aZ.T....>.._.a@...Q.;.."ev.s..'e...G.....}...#.Y..........n.'.....q?..!+A........A|MI.......J..Qt,..(W...`*"-).......e...>R.IGt......#:N;..SGt.uD......".+;.+[....^.(*n..[..)..m
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:data
      Category:modified
      Size (bytes):165
      Entropy (8bit):1.5231029153786204
      Encrypted:false
      SSDEEP:3:WH25nJFV:WH2/
      MD5:FB5ABAA34A0BB284B640327B9745AAAC
      SHA1:7E1063A0F1DE0E83424399F104C1D3752BFAECDE
      SHA-256:12464C713EE2E0CBBDCF98FACF8AC034D34A9F4D221D7BB7A5C7D458AAEC0AF9
      SHA-512:0FB235A4475D72D9BB6A195F6DFE471152B91F6DE0967D4174298D0A3C228BFF0ED57F0A5F388833A7793BD90F6CA0D5A974D21D795938D8D96C079AB5D99294
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview:.user ..h.u.b.e.r.t. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:data
      Category:dropped
      Size (bytes):165
      Entropy (8bit):1.5231029153786204
      Encrypted:false
      SSDEEP:3:WH25nJFV:WH2/
      MD5:FB5ABAA34A0BB284B640327B9745AAAC
      SHA1:7E1063A0F1DE0E83424399F104C1D3752BFAECDE
      SHA-256:12464C713EE2E0CBBDCF98FACF8AC034D34A9F4D221D7BB7A5C7D458AAEC0AF9
      SHA-512:0FB235A4475D72D9BB6A195F6DFE471152B91F6DE0967D4174298D0A3C228BFF0ED57F0A5F388833A7793BD90F6CA0D5A974D21D795938D8D96C079AB5D99294
      Malicious:true
      Preview:.user ..h.u.b.e.r.t. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      File type:Microsoft Excel 2007+
      Entropy (8bit):7.947143996213106
      TrID:
      • Excel Microsoft Office Open XML Format document with Macro (52504/1) 54.97%
      • Excel Microsoft Office Open XML Format document (35004/1) 36.65%
      • ZIP compressed archive (8000/1) 8.38%
      File name:B317.xlsx
      File size:3'694'114 bytes
      MD5:d3d62038201b0d42795c2983d47aca33
      SHA1:bc1cf5e7443582a9ed0e15b07cf975ba3f2a90dd
      SHA256:06ece98e9271215b6b7a7eb7c13463569c980b12e45565d63ac7e93ce43371a8
      SHA512:ff4d90bd576386cce9356d1b2fc1656f61de694aeea54ca19813f51a53b5ea0c47aa030c010edca627201e822e26ed518ccbf905c7c6949285f97b547dc6b882
      SSDEEP:49152:/VCV7o1bX966pYq27d8e4WDLpVuSe2v+QbnK3d5kKuawmO3ZJRU6jhQNXijM2cj3:9sD+XWX35ncd5kKuawmOpJm8W8jMoJM
      TLSH:760612837EF08342FFC2963C695529F0D98E56621AFFF4176D200D7E8CABC5B2861964
      File Content Preview:PK..........!....~....8.......[Content_Types].xml ...(.........................................................................................................................................................................................................
      Icon Hash:35e58a8c0c8a85b9
      Document Type:OpenXML
      Number of OLE Files:3
      Has Summary Info:
      Application Name:
      Encrypted Document:False
      Contains Word Document Stream:False
      Contains Workbook/Book Stream:True
      Contains PowerPoint Document Stream:False
      Contains Visio Document Stream:False
      Contains ObjectPool Stream:False
      Flash Objects Count:0
      Contains VBA Macros:True
      Code Page:1252
      Title:
      Subject:
      Author:Stephen Barnes
      Keywords:
      Comments:
      Template:
      Last Saved By:Zsolt D.
      Create Time:2013-03-07T11:20:43Z
      Last Saved Time:2024-12-20T12:11:50Z
      Thumbnail:OQ EMFNl8+8VISIODrawingLlMOQPR ??d(L(PRLkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkPPP```ppprrr]]]PPP@@@jjjUUU```]]]VVV@@@jjjUUU```]]]VVV@@@jjjIIIpppwwwwwwwww~~~pppwwwwwwjjjwwwttt^^^ZZZcccjjjMMMcccTTTjjjTTT\\\YYYdddJJJpppZZZ[[[ssspppMMMpppTTTccc<<<MMMcccMMM\\\MMMEEEIII@@@jjjEEE\\\cccEEEMMMcccccceeeccc___MMMtttfffHHH\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\WWW___NNN\\\SSS\\\XXX\\\\\\XXX\\\\\\SSSSSSDDDXXX\\\PPP[[[WWWXXXXXX\\\XXX\\\XXX\\\\\\\\\SSSKKKLLL\\\\\\KKKIII\\\SSS\\\\\\XXX\\\XXX\\\\\\XXXSSSCCCVVV\\\XXXhhhUUU```]]]VVV@@@jjjUUU```{{{]]]VVV===jjjUUU``````]]]UUU666jjjFFF@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@```BBB@@@@@@@@@@@@@@@@@@@@@@@@@@@===@@@@@@@@@@@@CCC```@@@@@@@@@@@@@@@@@@@@@@@@@@@===@@@@@@@@@@@@@@@JJJNNN@@@@@@@@@@@@@@@@@@@@@@@@@@@===@@@@@@@@@@@@@@@lllUUU```qqqsss]]]PPP@@@jjjUUU```]]]VVV@@@jjjUUU```fff]]]VVV666rrrjjjDDD\\\\\\NNN\\\\\\XXX\\\XXX\\\SSSOOOTTT\\\\\\UUU^^^DDD\\\\\\XXX\\\XXX\\\\\\XXXKKKJJJ\\\\\\\\\\\\KKK[[[MMM\\\XXX\\\\\\XXX\\\\\\SSSCCCTTT\\\\\\\\\\\\DDDAAAXXX\\\XXX\\\XXX\\\\\\\\\SSSCCCXXX\\\\\\\\\UUUfffIIIttt]]]XXXYYYZZZqqqIII@@@tttfffUUU```]]]VVV@@@jjjUUU```ggg]]]VVV@@@yyyjjjXXXhhhfffqqq|||bbbwwwlll}}}aaauuuxxx|||]]]IIIqqqrrrFFF@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@hhh@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ddd@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@FFFMMM@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@pppUUUbbb]]]VVV@@@jjjUUUbbb]]]VVV@@@jjjUUUbbb]]]VVV@@@jjjFFF@@@===333:::333666666666111+++000+++@@@@@@@@@aaaHHHWWW===OOOFFFKKKKKKKKKJJJKKKCCCFFF555OOOWWWIIIZZZQQQJJJKKKNNNKKKKKK===KKKJJJFFFFFF777>>>WWWWWWFFFFFFWWWBBBFFFJJJKKKFFFBBBNNNKKKKKKFFF<<<CCCWWWQQQfffPPP```eeeggg[[[MMM@@@gggUUU```]]]VVV@@@jjjQQQ```mmm]]]VVV:::jjjIIIwwwcccjjjEEEccc\\\MMM^^^QQQTTTJJJttt]]]MMMwww~~~wwwwwwjjj~~~wwwxxxeeecccwww~~~wwwwwwZZZ[[[]]]~~~wwwwwwwwwwww~~~wwwpppZZZpppwwwwwwwwwwwwIII:::www~~~wwwwwwjjj~~~wwwqqqwwwSSSxxxwwwwwwwwwooofffIII\\\\\\SSS\\\XXXXXX\\\\\\SSSPPPXXXOOO\\\\\\WWWaaaNNN\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\PPP\\\WWW\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\LLLFFF\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\XXXlllUUU```]]]VVV@@@jjjUUU```{{{]]]VVV===jjjPPP___SSSqqq]]]nnn|||PPP666rrriiiMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMeeeLLLMMMMMMMMMMMMMMMMMMMMMMMMMMMIIIMMMMMMMMMMMMMMMcccMMMMMMMMMMMMMMMMMMMMMMMMMMMIIIMMMMMMMMMMMMMMMTTTPPPMMMMMMMMMMMMMMMMMMMMMMMMMMMIIIMMMMMMMMMMMMMMMtttUUU```]]]VVV@@@jjjUUU```]]]VVV@@@jjjUUU```fff]]]VVV@@@jjjGGG\\\\\\\\\\\\\\\SSS\\\\\\SSS\\\\\\\\\\\\\\\UUU___DDD\\\\\\XXX\\\XXX\\\\\\XXXKKKJJJ\\\\\\\\\\\\KKK[[[UUUJJJAAAOOOFFFJJJ666FFFJJJAAAFFF333777]]]\\\GGGCCC\\\AAA;;;FFFJJJ;;;AAAOOOJJJKKKFFF???;;;\\\UUUiiiIIIttt^^^XXXYYY[[[qqqyyyIII@@@xxxtttgggUUU```]]]VVV@@@jjjUUU```]]]VVV@@@jjjKKKxxx``````ooovvvVVVppp^^^vvv___gggdddnnnRRR~~~```]]]UUU___pppDDDVVVoooVVVgggVVVMMMKKK@@@wwwMMMgggoooMMMUUUooopppqqqoooiiiUUUjjjxxx}}}ooo```|||eeeqqqSSSSSSFFFOOOXXXpppppppppppppppppppppppppppppppppppppppppppppCCCgggppppppppppppppppppppppppppppppppppppppppppjjjddd@@@@@@@@@zzzmmmqqqKKKmmmVVVmmm|||UUUmmmUUUpppmmmVVVjjjjjjjjjaaaLLLjjjjjjjjjjjjmmm_________pppwww___www___wwwpppppp___wwweeeKKK@@@```@@@@@@ppppppppppppppp```@@@CCCbbbkkkkkkkkkkkksss@@@qqqmmmKKK===mmmVVV@@@XXXVVVKKKNNNPPP===OOOIII===CCC===ZZZ@@@XXXVVVUUU@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@mmmVVV@@@jjj@@@mmmPPP@@@jjj@@@mmmmmmmmmmmmmmmmmmmmmRRRkkkmmmmmmmmmmmmmmmmmm@@@OOOEEELLLLLLLLLLLLLLLDDD@@@qqqooojjj{{{@@@@@@jjj@@@DDDEEEjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj___ppp@@@mmmKKK@@@mmmVVV@@@XXXrrrVVVVVVVVVmmmVVVmmmeeePPPmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
      Creating Application:Microsoft Excel
      Security:0
      Document Code Page:1252
      Category:
      Thumbnail Scaling Desired:false
      Manager:
      Company:nqa
      Contains Dirty Links:false
      Shared Document:false
      Changed Hyperlinks:false
      Application Version:16.0300
      General
      Stream Path:\x1CompObj
      CLSID:
      File Type:data
      Stream Size:115
      Entropy:4.1863679469808845
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . F . . . . M i c r o s o f t V i s i o D r a w i n g . . . . . V i s i o 1 1 . 0 S h a p e s . . . . . V i s i o . D r a w i n g . 1 1 . 9 q . . . . . . . . . . . .
      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 14 1a 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 18 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 56 69 73 69 6f 20 44 72 61 77 69 6e 67 00 12 00 00 00 56 69 73 69 6f 20 31 31 2e 30 20 53 68 61 70 65 73 00 11 00 00 00 56 69 73 69 6f 2e 44 72 61 77 69 6e 67 2e 31 31 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
      General
      Stream Path:\x1Ole
      CLSID:
      File Type:data
      Stream Size:20
      Entropy:0.5689955935892812
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . .
      Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      General
      Stream Path:\x5DocumentSummaryInformation
      CLSID:
      File Type:data
      Stream Size:492
      Entropy:3.3326255517445897
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , l . . . ( . . . . . . . . . . . ` . . . . . . . h . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P a g e - 1 . N . . . . R e c t a n g l e
      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 6c 01 00 00 28 01 00 00 0b 00 00 00 01 00 00 00 60 00 00 00 02 00 00 00 68 00 00 00 0e 00 00 00 74 00 00 00 0f 00 00 00 80 00 00 00 17 00 00 00 8c 00 00 00 0b 00 00 00 94 00 00 00 10 00 00 00
      General
      Stream Path:\x5SummaryInformation
      CLSID:
      File Type:data
      Stream Size:20284
      Entropy:4.4728917693156465
      Base64 Encoded:True
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . O . . . . . . . . . . ` . . . . . . . h . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N i c k W r i g h t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N i c k W r i g h t . . . . . . . . . M i c r o s o f t V i s i o .
      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 0c 4f 00 00 0b 00 00 00 01 00 00 00 60 00 00 00 02 00 00 00 68 00 00 00 03 00 00 00 74 00 00 00 04 00 00 00 80 00 00 00 05 00 00 00 94 00 00 00 06 00 00 00 a0 00 00 00 07 00 00 00 ac 00 00 00 08 00 00 00 b8 00 00 00 12 00 00 00 cc 00 00 00
      General
      Stream Path:VisioDocument
      CLSID:
      File Type:data
      Stream Size:53975
      Entropy:7.3092529788648255
      Base64 Encoded:True
      Data ASCII:V i s i o ( T M ) D r a w i n g . . . . . . . . . . . . . . . . . . . g \\ . r . . e . . . R . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . f f f . M M M . 3 3 3 . . . . . . . . . @ @ @ . 5 . m . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . U . . . . . J . : D . . T 5 . I . [ . 1 . h . X .
      Data Raw:56 69 73 69 6f 20 28 54 4d 29 20 44 72 61 77 69 6e 67 0d 0a 00 00 00 00 00 00 0b 00 d7 d2 00 00 00 84 01 00 14 00 00 00 e4 67 5c 01 72 d1 00 00 65 01 00 00 52 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 c5 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc d3 33 01 d8 a8 83 04 03 00 00 00 00 d8 c5 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 c5 0b
      General
      Stream Path:VisioInformation
      CLSID:
      File Type:data
      Stream Size:28
      Entropy:0.8773870642966131
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:fe ff 00 00 04 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Has Summary Info:
      Application Name:
      Encrypted Document:False
      Contains Word Document Stream:False
      Contains Workbook/Book Stream:True
      Contains PowerPoint Document Stream:False
      Contains Visio Document Stream:False
      Contains ObjectPool Stream:False
      Flash Objects Count:0
      Contains VBA Macros:True
      Code Page:1252
      Title:
      Subject:
      Author:Stephen Barnes
      Keywords:
      Comments:
      Template:
      Last Saved By:Zsolt D.
      Create Time:2013-03-07T11:20:43Z
      Last Saved Time:2024-12-20T12:11:50Z
      Thumbnail:VKJ EMFOl8+8VISIODrawingLNVKWL ??d(`N(WL`NjjjKKKKKKbbbVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVPPPPPPrrrmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmbbblllmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmxxxzzzmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmlllbbbmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmRRRRRR@@@@@@@@@@@@CCC@@@@@@@@@[[[tttLLLbbbjjj}}}KKKVVVVVVVVVVVVVVVVVVVVVeee{{{eee|||eeeqqqeeePPPmmm]]]mmmmmmmmmmmmhhhmmmmmmmmmmmmffflllmmmmmmmmmhhhmmmhhhmmmmmmaaammmxxx^^^qqqUUUnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn___hhhnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnEEEVVVVVVVVVvvvpppppppppXXXVVVvvvVVVVVVvvvUUUVVVVVVVVVVVV@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@VVVVVVdddOOOAAALLLLLLLLLLLLLLLLLLLLLLLLHHHnnnVVVsssVVVVVVrrrUUUUUUmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm[[[fffmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmKKKmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmVVVVVVVVVdddoooVVVoooVVVVVVVVVVVV@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@KKKzzzxxxjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjQQQ[[[jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjtttVVVQQQVVVVVVVVVVVVVVVVVVRRRXXX@@@@@@@@@@@@@@@@@@ttt@@@@@@@@@@@@@@@@@@@@@@@@VVVVVVVVVVVVVVVVVVVVVuuuUUUjjjKKK
      Creating Application:Microsoft Excel
      Security:0
      Document Code Page:1252
      Category:
      Thumbnail Scaling Desired:false
      Manager:
      Company:nqa
      Contains Dirty Links:false
      Shared Document:false
      Changed Hyperlinks:false
      Application Version:16.0300
      General
      Stream Path:\x1CompObj
      CLSID:
      File Type:data
      Stream Size:115
      Entropy:4.1863679469808845
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . F . . . . M i c r o s o f t V i s i o D r a w i n g . . . . . V i s i o 1 1 . 0 S h a p e s . . . . . V i s i o . D r a w i n g . 1 1 . 9 q . . . . . . . . . . . .
      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 14 1a 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 18 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 56 69 73 69 6f 20 44 72 61 77 69 6e 67 00 12 00 00 00 56 69 73 69 6f 20 31 31 2e 30 20 53 68 61 70 65 73 00 11 00 00 00 56 69 73 69 6f 2e 44 72 61 77 69 6e 67 2e 31 31 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
      General
      Stream Path:\x1Ole
      CLSID:
      File Type:data
      Stream Size:20
      Entropy:0.5689955935892812
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . .
      Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      General
      Stream Path:\x3EPRINT
      CLSID:
      File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
      Stream Size:54204
      Entropy:3.9790690762216863
      Base64 Encoded:True
      Data ASCII:. . . . l . . . . . . . . . . . . . . . . . . . . . . . . . . 5 . . . . . E M F . . . . . . W . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . + . . . . . . . . . . . . . . . 8 . . . . . F . . . , . . . . . . E M F + . @ . . . . . . . . . . . . . . . . ` . . . ` . . . F . . . . . . . . . E M F + 0 @ . . . . . . . . . . . . ? . @ . . . . . . . . . . . @ . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . * @ . . $ . . . . . . . . . B . . . . . . . . . . B j w C y & B . @ . . 4 . . . ( .
      Data Raw:01 00 00 00 6c 00 00 00 00 00 00 00 00 00 00 00 ea 01 00 00 ae 01 00 00 00 00 00 00 00 00 00 00 12 35 00 00 a4 2e 00 00 20 45 4d 46 00 00 01 00 bc d3 00 00 57 04 00 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 07 00 00 38 04 00 00 13 02 00 00 2b 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 1a 08 00 f8 8f 04 00 46 00 00 00 2c 00 00 00 20 00 00 00 45 4d 46 2b 01 40 01 00
      General
      Stream Path:\x3ObjInfo
      CLSID:
      File Type:data
      Stream Size:6
      Entropy:1.2516291673878228
      Base64 Encoded:False
      Data ASCII:. . . . . .
      Data Raw:00 00 03 00 0d 00
      General
      Stream Path:\x5DocumentSummaryInformation
      CLSID:
      File Type:data
      Stream Size:492
      Entropy:3.3326255517445897
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , l . . . ( . . . . . . . . . . . ` . . . . . . . h . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P a g e - 1 . N . . . . R e c t a n g l e
      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 6c 01 00 00 28 01 00 00 0b 00 00 00 01 00 00 00 60 00 00 00 02 00 00 00 68 00 00 00 0e 00 00 00 74 00 00 00 0f 00 00 00 80 00 00 00 17 00 00 00 8c 00 00 00 0b 00 00 00 94 00 00 00 10 00 00 00
      General
      Stream Path:\x5SummaryInformation
      CLSID:
      File Type:data
      Stream Size:20668
      Entropy:2.7984902058481667
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . P . . . . . . . . . . ` . . . . . . . h . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N i c k W r i g h t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N i c k W r i g h t . . . . . . . . . M i c r o s o f t V i s i o . @
      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 8c 50 00 00 0b 00 00 00 01 00 00 00 60 00 00 00 02 00 00 00 68 00 00 00 03 00 00 00 74 00 00 00 04 00 00 00 80 00 00 00 05 00 00 00 94 00 00 00 06 00 00 00 a0 00 00 00 07 00 00 00 ac 00 00 00 08 00 00 00 b8 00 00 00 12 00 00 00 cc 00 00 00
      General
      Stream Path:VisioDocument
      CLSID:
      File Type:data
      Stream Size:33240
      Entropy:7.081609952224548
      Base64 Encoded:True
      Data ASCII:V i s i o ( T M ) D r a w i n g . . . . . . . . . . . . . . . . . . . . l Y b . p . . h . . . R . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . l . . . . . . . . . . . . . . . . . . ! . . f f f . M M M . 3 3 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . U . . . . . J . : D . . T 5 . I . [ . 1 . h . X .
      Data Raw:56 69 73 69 6f 20 28 54 4d 29 20 44 72 61 77 69 6e 67 0d 0a 00 00 00 00 00 00 0b 00 d8 81 00 00 00 84 01 00 14 00 00 00 6c 59 62 01 70 80 00 00 68 01 00 00 52 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 c5 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc d3 33 01 d8 a8 83 04 03 00 00 00 00 d8 c5 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d8 c5 0b
      General
      Stream Path:VisioInformation
      CLSID:
      File Type:data
      Stream Size:28
      Entropy:0.8773870642966131
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:fe ff 00 00 04 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Has Summary Info:
      Application Name:
      Encrypted Document:False
      Contains Word Document Stream:False
      Contains Workbook/Book Stream:True
      Contains PowerPoint Document Stream:False
      Contains Visio Document Stream:False
      Contains ObjectPool Stream:False
      Flash Objects Count:0
      Contains VBA Macros:True
      Author:Stephen Barnes
      Last Saved By:Zsolt D.
      Create Time:2013-03-07T11:20:43Z
      Last Saved Time:2024-12-20T12:11:50Z
      Creating Application:Microsoft Excel
      Security:0
      Thumbnail Scaling Desired:false
      Company:nqa
      Contains Dirty Links:false
      Shared Document:false
      Changed Hyperlinks:false
      Application Version:16.0300
      General
      Stream Path:VBA/Class1
      VBA File Name:Class1
      Stream Size:999
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S < . . . . S < . . . . S < . . . . . < . . . . . . . . . . N . 0 . { . F . C . F . B . 3 . D . 2 . A .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e ce 01 00 00 ff ff 01 00 00 00 80 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Class1"
      Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = False
      Attribute VB_Exposed = False
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = False
      

      General
      Stream Path:VBA/Module1
      VBA File Name:Module1
      Stream Size:681
      Data ASCII:. . . . . . . . " . . . . . . . . . ) . . . } . . . . . . . . . . . k n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:01 16 03 00 00 f0 00 00 00 22 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 29 02 00 00 7d 02 00 00 00 00 00 00 01 00 00 00 6b 6e 95 89 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Module1"
      

      General
      Stream Path:VBA/Module2
      VBA File Name:Module2
      Stream Size:1068
      Data ASCII:. . . . . . . . z . . . . . . . . . . . . m . . . . . . . . . . . k n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ` . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:01 16 03 00 00 f0 00 00 00 7a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 81 02 00 00 6d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 98 ab 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Module2"
      Private Sub Workbook_Open()
          With Worksheets("Justification")
              .EnableOutlining = True
              .Protect UserInterfaceOnly:=True
          End With
      End Sub
      

      General
      Stream Path:VBA/Module3
      VBA File Name:Module3
      Stream Size:9779
      Data ASCII:. . . . . . . . * . . . . . . . . . 2 . . . . . . . . . . . . . . . k n N . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . < X . . . . . . < . . . . . . . < . . . . . . . < . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:01 16 03 00 00 f0 00 00 00 2a 04 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 32 04 00 00 1e 1b 00 00 00 00 00 00 01 00 00 00 6b 6e 9e 4e 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Module3"
      Sub RemoveProtection()
      Dim dialogBox As FileDialog
      Dim sourceFullName As String
      Dim sourceFilePath As String
      Dim sourceFileName As String
      Dim sourceFileType As String
      Dim newFileName As Variant
      Dim tempFileName As String
      Dim zipFilePath As Variant
      Dim oApp As Object
      Dim FSO As Object
      Dim xmlSheetFile As String
      Dim xmlFile As Integer
      Dim xmlFileContent As String
      Dim xmlStartProtectionCode As Double
      Dim xmlEndProtectionCode As Double
      Dim xmlProtectionString As String
      
      'Open dialog box to select a file
      Set dialogBox = Application.FileDialog(msoFileDialogFilePicker)
      dialogBox.AllowMultiSelect = False
      dialogBox.Title = "Select file to remove protection from"
      
      If dialogBox.Show = -1 Then
          sourceFullName = dialogBox.SelectedItems(1)
      Else
          Exit Sub
      End If
      
      'Get folder path, file type and file name from the sourceFullName
      sourceFilePath = Left(sourceFullName, InStrRev(sourceFullName, "\"))
      sourceFileType = Mid(sourceFullName, InStrRev(sourceFullName, ".") + 1)
      sourceFileName = Mid(sourceFullName, Len(sourceFilePath) + 1)
      sourceFileName = Left(sourceFileName, InStrRev(sourceFileName, ".") - 1)
      
      'Use the date and time to create a unique file name
      tempFileName = "Temp" & Format(Now, " dd-mmm-yy h-mm-ss")
      
      'Copy and rename original file to a zip file with a unique name
      newFileName = sourceFilePath & tempFileName & ".zip"
      On Error Resume Next
      FileCopy sourceFullName, newFileName
      
      If Err.Number <> 0 Then
          MsgBox "Unable to copy " & sourceFullName & vbNewLine         & "Check the file is closed and try again"
          Exit Sub
      End If
      On Error GoTo 0
      
      'Create folder to unzip to
      zipFilePath = sourceFilePath & tempFileName & "\"
      MkDir zipFilePath
      
      'Extract the files into the newly created folder
      Set oApp = CreateObject("Shell.Application")
      oApp.Namespace(zipFilePath).CopyHere oApp.Namespace(newFileName).items
      
      'loop through each file in the \xl\worksheets folder of the unzipped file
      xmlSheetFile = Dir(zipFilePath & "\xl\worksheets\*.xml*")
      Do While xmlSheetFile <> ""
      
          'Read text of the file to a variable
          xmlFile = FreeFile
          Open zipFilePath & "xl\worksheets\" & xmlSheetFile For Input As xmlFile
          xmlFileContent = Input(LOF(xmlFile), xmlFile)
          Close xmlFile
          'Manipulate the text in the file
          xmlStartProtectionCode = 0
          xmlStartProtectionCode = InStr(1, xmlFileContent, "<sheetProtection")
      
          If xmlStartProtectionCode > 0 Then
      
              xmlEndProtectionCode = InStr(xmlStartProtectionCode,             xmlFileContent, "/>") + 2 '"/>" is 2 characters long
              xmlProtectionString = Mid(xmlFileContent, xmlStartProtectionCode,             xmlEndProtectionCode - xmlStartProtectionCode)
              xmlFileContent = Replace(xmlFileContent, xmlProtectionString, "")
      
          End If
      
          'Remove Range Protection
          xmlStartProtectionCode = 0
          xmlStartProtectionCode = InStr(1, xmlFileContent, "<protectedRanges")
      
          If xmlStartProtectionCode > 0 Then
      
              xmlEndProtectionCode = InStr(xmlStartProtectionCode,             xmlFileContent, "</protectedRanges>") + 18 '"</protectedRanges>" is 18 characters long
              xmlProtectionString = Mid(xmlFileContent, xmlStartProtectionCode,             xmlEndProtectionCode - xmlStartProtectionCode)
              xmlFileContent = Replace(xmlFileContent, xmlProtectionString, "")
      
          End If
      
          'Output the text of the variable to the file
          xmlFile = FreeFile
          Open zipFilePath & "xl\worksheets\" & xmlSheetFile For Output As xmlFile
          Print #xmlFile, xmlFileContent
          Close xmlFile
      
          'Loop to next xmlFile in directory
          xmlSheetFile = Dir
      
      Loop
      
      'Read text of the xl\workbook.xml file to a variable
      xmlFile = FreeFile
      Open zipFilePath & "xl\workbook.xml" For Input As xmlFile
      xmlFileContent = Input(LOF(xmlFile), xmlFile)
      Close xmlFile
      
      'Manipulate the text in the file to remove the workbook protection
      xmlStartProtectionCode = 0
      xmlStartProtectionCode = InStr(1, xmlFileContent, "<workbookProtection")
      If xmlStartProtectionCode > 0 Then
      
          xmlEndProtectionCode = InStr(xmlStartProtectionCode,         xmlFileContent, "/>") + 2 ''"/>" is 2 characters long
          xmlProtectionString = Mid(xmlFileContent, xmlStartProtectionCode,         xmlEndProtectionCode - xmlStartProtectionCode)
          xmlFileContent = Replace(xmlFileContent, xmlProtectionString, "")
      
      End If
      
      'Manipulate the text in the file to remove the modify password
      xmlStartProtectionCode = 0
      xmlStartProtectionCode = InStr(1, xmlFileContent, "<fileSharing")
      If xmlStartProtectionCode > 0 Then
      
          xmlEndProtectionCode = InStr(xmlStartProtectionCode, xmlFileContent,         "/>") + 2 '"/>" is 2 characters long
          xmlProtectionString = Mid(xmlFileContent, xmlStartProtectionCode,         xmlEndProtectionCode - xmlStartProtectionCode)
          xmlFileContent = Replace(xmlFileContent, xmlProtectionString, "")
      
      End If
      
      'Output the text of the variable to the file
      xmlFile = FreeFile
      Open zipFilePath & "xl\workbook.xml" & xmlSheetFile For Output As xmlFile
      Print #xmlFile, xmlFileContent
      Close xmlFile
      
      'Create empty Zip File
      Open sourceFilePath & tempFileName & ".zip" For Output As #1
      Print #1, Chr$(80) & Chr$(75) & Chr$(5) & Chr$(6) & String(18, 0)
      Close #1
      
      'Move files into the zip file
      oApp.Namespace(sourceFilePath & tempFileName & ".zip").CopyHere oApp.Namespace(zipFilePath).items
      'Keep script waiting until Compressing is done
      On Error Resume Next
      Do Until oApp.Namespace(sourceFilePath & tempFileName & ".zip").items.Count =     oApp.Namespace(zipFilePath).items.Count
          Application.Wait (Now + TimeValue("0:00:01"))
      Loop
      On Error GoTo 0
      
      'Delete the files & folders created during the sub
      Set FSO = CreateObject("scripting.filesystemobject")
      FSO.deletefolder sourceFilePath & tempFileName
      
      'Rename the final file back to an xlsx file
      Name sourceFilePath & tempFileName & ".zip" As sourceFilePath & sourceFileName & "_" & Format(Now, "dd-mmm-yy h-mm-ss") & "." & sourceFileType
      
      'Show message box
      MsgBox "The workbook and worksheet protection passwords have been removed.", vbInformation + vbOKOnly, Title:="Password protection"
      
      End Sub
      
      
      
      
      

      General
      Stream Path:VBA/Sheet1
      VBA File Name:Sheet1
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e f7 f7 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet1"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet10
      VBA File Name:Sheet10
      Stream Size:992
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n 4 # . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 34 23 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet10"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet2
      VBA File Name:Sheet2
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n % . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 25 bf 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet2"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet3
      VBA File Name:Sheet3
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n ? . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 3f ad 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet3"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet31
      VBA File Name:Sheet31
      Stream Size:992
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 02 a1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet31"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet4
      VBA File Name:Sheet4
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n 6 . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 36 06 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet4"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet41
      VBA File Name:Sheet41
      Stream Size:992
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n \\ . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e be 5c 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet41"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet5
      VBA File Name:Sheet5
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n / . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 2f 10 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet5"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet51
      VBA File Name:Sheet51
      Stream Size:992
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n 0 . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 30 08 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet51"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet6
      VBA File Name:Sheet6
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n \\ d . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 5c 64 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet6"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet7
      VBA File Name:Sheet7
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 92 d0 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet7"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet8
      VBA File Name:Sheet8
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 98 fa 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet8"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/Sheet9
      VBA File Name:Sheet9
      Stream Size:991
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n % . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 25 e1 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "Sheet9"
      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:VBA/ThisWorkbook
      VBA File Name:ThisWorkbook
      Stream Size:999
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . k n ? K . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 .
      Data Raw:01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 6b 6e 3f 4b 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
      Attribute VB_Name = "ThisWorkbook"
      Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
      Attribute VB_GlobalNameSpace = False
      Attribute VB_Creatable = False
      Attribute VB_PredeclaredId = True
      Attribute VB_Exposed = True
      Attribute VB_TemplateDerived = False
      Attribute VB_Customizable = True
      

      General
      Stream Path:PROJECT
      CLSID:
      File Type:ASCII text, with CRLF line terminators
      Stream Size:1219
      Entropy:4.970533407409681
      Base64 Encoded:True
      Data ASCII:I D = " { 2 B 2 B B D 0 9 - 7 6 1 3 - 4 3 6 2 - 8 6 3 F - C 9 0 0 7 E 7 7 C 4 4 C } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 5 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 6 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 4 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e
      Data Raw:49 44 3d 22 7b 32 42 32 42 42 44 30 39 2d 37 36 31 33 2d 34 33 36 32 2d 38 36 33 46 2d 43 39 30 30 37 45 37 37 43 34 34 43 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 33 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 35 31 2f 26 48 30
      General
      Stream Path:PROJECTwm
      CLSID:
      File Type:data
      Stream Size:419
      Entropy:3.2348415716894836
      Base64 Encoded:False
      Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 3 1 . S . h . e . e . t . 3 . 1 . . . S h e e t 5 1 . S . h . e . e . t . 5 . 1 . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 6 . S . h . e . e . t . 6 . . . S h e e t 4 1 . S . h . e . e . t . 4 . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 4 . S . h . e . e . t . 4 . . . S h e e t 5 . S . h . e . e . t . 5 . . . S h e e t 7 . S . h . e . e . t . 7 . . . S h e e t 1 0 . S . h . e . e . t . 1
      Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 33 31 00 53 00 68 00 65 00 65 00 74 00 33 00 31 00 00 00 53 68 65 65 74 35 31 00 53 00 68 00 65 00 65 00 74 00 35 00 31 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 36 00 53 00 68 00 65 00 65 00 74 00 36 00 00
      General
      Stream Path:VBA/_VBA_PROJECT
      CLSID:
      File Type:data
      Stream Size:5526
      Entropy:4.7177706228741165
      Base64 Encoded:True
      Data ASCII:a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 . . . D .
      Data Raw:cc 61 b5 00 00 03 00 ff 0e 04 00 00 09 04 00 00 e2 04 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 20 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
      General
      Stream Path:VBA/dir
      CLSID:
      File Type:data
      Stream Size:943
      Entropy:6.838020096555018
      Base64 Encoded:True
      Data ASCII:. . . . . . . . . 0 J . . . H . . H . . " . . H . . . . d . . . . . . . V B A P @ r o j e c t . . D . @ . & . . . . . = . . . . r . . . . . . . . l . i . . . . J . < . . . . 9 s t d o . l e > . . s . t . . d . o . l . e . ( . . h . % ^ . . * \\ . G { 0 0 0 2 0 4 3 0 - . . . . C . . . . . . . 0 0 4 6 } # 2 . . 0 # 0 # C : \\ . W i n d o w s \\ . S y s t e m 3 2 . \\ . e 2 . t l b # . O L E A u t o m a t i o n . 0 . . A E O f f i c E O D . f . i . c E . . . E 2 D F 8 . D 0 4 C - 5 B F . A - 1 0 1 B - B H D E 5
      Data Raw:01 ab b3 80 01 00 04 00 00 00 03 00 30 aa 4a 02 90 05 00 48 02 02 48 09 00 c0 22 14 06 48 03 00 02 00 64 e2 04 08 04 00 0a 00 1c 56 42 41 50 40 72 6f 6a 65 63 74 01 bc 00 44 00 40 00 26 00 00 06 02 0a 3d ad 02 0a 07 02 72 01 14 08 06 12 09 02 12 80 b1 6c 07 69 01 00 0c 02 4a 0a 3c 02 0a 16 02 39 73 74 64 6f 08 6c 65 3e 02 19 73 00 74 00 00 64 00 6f 00 6c 00 65 00 28 0d 00 68 00 25
      TimestampSource PortDest PortSource IPDest IP
      Jan 13, 2025 20:32:41.436259985 CET5916453192.168.2.8162.159.36.2
      Jan 13, 2025 20:32:41.441075087 CET5359164162.159.36.2192.168.2.8
      Jan 13, 2025 20:32:41.441143036 CET5916453192.168.2.8162.159.36.2
      Jan 13, 2025 20:32:41.445940018 CET5359164162.159.36.2192.168.2.8
      Jan 13, 2025 20:32:41.886543036 CET5916453192.168.2.8162.159.36.2
      Jan 13, 2025 20:32:41.891510010 CET5359164162.159.36.2192.168.2.8
      Jan 13, 2025 20:32:41.891571999 CET5916453192.168.2.8162.159.36.2
      TimestampSource PortDest PortSource IPDest IP
      Jan 13, 2025 20:32:41.435755014 CET5354719162.159.36.2192.168.2.8
      Jan 13, 2025 20:32:41.917545080 CET6097053192.168.2.81.1.1.1
      Jan 13, 2025 20:32:41.924896002 CET53609701.1.1.1192.168.2.8
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 13, 2025 20:32:41.917545080 CET192.168.2.81.1.1.10x5538Standard query (0)15.164.165.52.in-addr.arpaPTR (Pointer record)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 13, 2025 20:32:41.924896002 CET1.1.1.1192.168.2.80x5538Name error (3)15.164.165.52.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
      Jan 13, 2025 20:33:33.831003904 CET1.1.1.1192.168.2.80xd37No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
      Jan 13, 2025 20:33:33.831003904 CET1.1.1.1192.168.2.80xd37No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false

      Click to jump to process

      Click to jump to process

      Click to dive into process behavior distribution

      Click to jump to process

      Target ID:0
      Start time:14:32:24
      Start date:13/01/2025
      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      Wow64 process (32bit):true
      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
      Imagebase:0x5e0000
      File size:53'161'064 bytes
      MD5 hash:4A871771235598812032C822E6F68F19
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:5
      Start time:14:32:29
      Start date:13/01/2025
      Path:C:\Windows\splwow64.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\splwow64.exe 12288
      Imagebase:0x7ff6e5270000
      File size:163'840 bytes
      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:12
      Start time:14:34:37
      Start date:13/01/2025
      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      Wow64 process (32bit):
      Commandline:
      Imagebase:
      File size:53'161'064 bytes
      MD5 hash:4A871771235598812032C822E6F68F19
      Has elevated privileges:
      Has administrator privileges:
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      No disassembly