Edit tour

Windows Analysis Report
PURCHASE ORDER - PO#267759.xlam.xlsx

Overview

General Information

Sample name:PURCHASE ORDER - PO#267759.xlam.xlsx
Analysis ID:1646987
MD5:9e6cd3ab7762a50813fb25b114e2b162
SHA1:df4651b08187b62b0a6c43d60e73d3e6374af545
SHA256:8700acf7f7771cfc2e0f8b56f76286e12e2a40016db0d41a3bce914b05f464a9
Tags:AgentTeslaxlamxlsxuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Document contains OLE streams with names of living off the land binaries
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • EXCEL.EXE (PID: 7876 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 8432 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
sheet1.xmlINDICATOR_XML_LegacyDrawing_AutoLoad_Documentdetects AutoLoad documents using LegacyDrawingditekSHen
  • 0x24c3:$s1: <legacyDrawing r:id="
  • 0x24eb:$s2: <oleObject progId="
  • 0x2528:$s3: autoLoad="true"

System Summary

barindex
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 13.107.246.40, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7876, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49739
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.4, DestinationIsIpv6: false, DestinationPort: 49739, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7876, Protocol: tcp, SourceIp: 13.107.246.40, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-24T13:38:39.196627+010020283713Unknown Traffic192.168.2.44973913.107.246.40443TCP
2025-03-24T13:38:44.820092+010020283713Unknown Traffic192.168.2.44974013.107.246.40443TCP
2025-03-24T13:38:44.821357+010020283713Unknown Traffic192.168.2.44974113.107.246.40443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: PURCHASE ORDER - PO#267759.xlam.xlsxAvira: detected
Source: PURCHASE ORDER - PO#267759.xlam.xlsxVirustotal: Detection: 58%Perma Link
Source: PURCHASE ORDER - PO#267759.xlam.xlsxReversingLabs: Detection: 69%
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49739 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49739
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49740 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49740
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: global trafficTCP traffic: 192.168.2.4:49741 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.4:49741
Source: excel.exeMemory has grown: Private usage: 2MB later: 89MB
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49739 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49740 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.4:49741 -> 13.107.246.40:443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /rules/excel.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.4:49739 version: TLS 1.2

System Summary

barindex
Source: sheet1.xml, type: SAMPLEMatched rule: detects AutoLoad documents using LegacyDrawing Author: ditekSHen
Source: PURCHASE ORDER - PO#267759.xlam.xlsxStream path '\x1oLe10nAtIVe' : ..Q$\..<E.F7w|.8O.3W.NLxM-SBD..\q8W.8.g9u....^9Q.u.be!"JS2z.5;.WM.KV.d.)>.$.r.0t.W.l5K#M.r.jf.1...YahCL.:...Io!..gNTbU.gr.2He%n.,..N#q}Oxc~.Vt...E$X<.VOwQ"w9zL9}cA'S?.r.(.7.7[$l-Lu).T<<IfR*=z)I`|.T%>+.|+k..GC.%eY. ...cUZdWKUV.).szr.*\.m...J~}..L~K./Ng$.W.6Rz&i.K._1r.7x.8R!In~7].i12)~.,~..t0.*.ok)?M%z.`.j/".J$-.Bi..r8.6.(..H~k1PR-....WWS.J..=z..T..[__W.-[-q_NZ..S@..-Zf..8..WW5.......N[..S[...V^__.W_VVZ..#...y^..1]..2\..^^....ZX ..qj.he!k.if./x1.*...._..W.".B.j6......PQYX.PS.TH._R-L9...c...H..Z[X.VV^9r,Ejn..xK).:qk=.g,(8. {0N~uq_0LN1'.J#^..^hB.9...,.&z-.N/O.*r%0(CK+@k(.iz.Q..^k.{)*.`.B8Y$.=\..{L.#....c1C.31Cv..mg.l"O.[nRwj47L.l.k{..)Ii1?.....T5..PK3.#f3@ck..f[..dy#m.=..H`Dj_.X.zuy="..5+C>_6F.>GG|.<. j?.O.F.1&d.(K+JZ3+C.9~.-1.c.AQ..7.}=.q[C.RmQy.!W Iy,6G[..ep.#,r7..l..^=.a.~_rRnw=$Ib;RM].)....9mR.*\R.by=T"y....7ex85m=O.......zbNe/'z<Ds.Ec."q..10e.E.kprw/X{R@>`..Emgp...`JH.../s8Guxmpt.+[:W].{2nQ.iA QGJ+D%.M...z?c0.AW\GtP4EO.t|'..Y0UjmU6Rp#.Pt*j\f..8<.O.;^.U'Q4@QrY$..ip.W.q*.ZH.j.s.Gd.Uasd$...].|.j5=nFkM>?JIo.6>?L1)..J3(~i. ..i-i1.nb.wXf.l[..+."wOx`PIA`................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Source: PURCHASE ORDER - PO#267759.xlam.xlsxOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: sheet1.xml, type: SAMPLEMatched rule: INDICATOR_XML_LegacyDrawing_AutoLoad_Document author = ditekSHen, description = detects AutoLoad documents using LegacyDrawing
Source: classification engineClassification label: mal68.winXLSX@3/3@1/1
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$PURCHASE ORDER - PO#267759.xlam.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{E454F52B-F677-4D14-9051-A2EA1D3D92D7} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: PURCHASE ORDER - PO#267759.xlam.xlsxVirustotal: Detection: 58%
Source: PURCHASE ORDER - PO#267759.xlam.xlsxReversingLabs: Detection: 69%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: PURCHASE ORDER - PO#267759.xlam.xlsxInitial sample: OLE zip file path = xl/media/image1.jpg
Source: PURCHASE ORDER - PO#267759.xlam.xlsxInitial sample: OLE zip file path = xl/calcChain.xml
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: PURCHASE ORDER - PO#267759.xlam.xlsxInitial sample: OLE indicators vbamacros = False
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 908Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts3
Exploitation for Client Execution
Path Interception1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture3
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1646987 Sample: PURCHASE ORDER - PO#267759.... Startdate: 24/03/2025 Architecture: WINDOWS Score: 68 15 star-azurefd-prod.trafficmanager.net 2->15 17 shed.dual-low.s-part-0012.t-0009.t-msedge.net 2->17 19 3 other IPs or domains 2->19 23 Malicious sample detected (through community Yara rule) 2->23 25 Antivirus / Scanner detection for submitted sample 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Document contains OLE streams with names of living off the land binaries 2->29 7 EXCEL.EXE 190 56 2->7         started        signatures3 process4 dnsIp5 21 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49739, 49740 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 7->21 13 C:\...\~$PURCHASE ORDER - PO#267759.xlam.xlsx, data 7->13 dropped 11 splwow64.exe 7->11         started        file6 process7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
PURCHASE ORDER - PO#267759.xlam.xlsx58%VirustotalBrowse
PURCHASE ORDER - PO#267759.xlam.xlsx69%ReversingLabsDocument-Office.Exploit.CVE-2017-11882
PURCHASE ORDER - PO#267759.xlam.xlsx100%AviraEXP/CVE-2017-11882.Gen
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0012.t-0009.t-msedge.net
13.107.246.40
truefalse
    high
    s-0005.dual-s-msedge.net
    52.123.129.14
    truefalse
      high
      otelrules.svc.static.microsoft
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://otelrules.svc.static.microsoft/rules/excel.exe-Production-v19.bundlefalse
          high
          https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
            high
            https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              13.107.246.40
              s-part-0012.t-0009.t-msedge.netUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1646987
              Start date and time:2025-03-24 13:36:27 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 4m 55s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsofficecookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:21
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:PURCHASE ORDER - PO#267759.xlam.xlsx
              Detection:MAL
              Classification:mal68.winXLSX@3/3@1/1
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .xlsx
              • Found Word or Excel or PowerPoint or XPS Viewer
              • Attach to Office via COM
              • Active ActiveX Object
              • Scroll down
              • Close Viewer
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 52.109.20.38, 184.31.69.3, 52.109.16.112, 20.189.173.9, 52.123.129.14, 20.190.152.22, 4.175.87.197
              • Excluded domains from analysis (whitelisted): onedscolprdwus08.westus.cloudapp.azure.com, slscr.update.microsoft.com, scus-azsc-config.officeapps.live.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, osiprod-ncus-buff-azsc-000.northcentralus.cloudapp.azure.com, ncus-azsc-000.roaming.officeapps.live.com, roaming.officeapps.live.com, dual-s-0005-office.config.skype.com, ocsp.digicert.com, login.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, fe3cr.delivery.mp.microsoft.com, us1.roaming1.live.com.akadns.net, config.officeapps.live.com, us.configsvc1.live.com.akadns.net, ecs.office.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtCreateKey calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
              TimeTypeDescription
              08:38:33API Interceptor938x Sleep call for process: splwow64.exe modified
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              13.107.246.40Payment Transfer Receipt.shtmlGet hashmaliciousHTMLPhisherBrowse
              • www.aib.gov.uk/
              NEW ORDER.xlsGet hashmaliciousUnknownBrowse
              • 2s.gg/3zs
              PO_OCF 408.xlsGet hashmaliciousUnknownBrowse
              • 2s.gg/42Q
              06836722_218 Aluplast.docx.docGet hashmaliciousUnknownBrowse
              • 2s.gg/3zk
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 2s.gg/3zM
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              s-0005.dual-s-msedge.netsample.docGet hashmaliciousUnknownBrowse
              • 52.123.128.14
              Medical GmbH Order.xlsGet hashmaliciousUnknownBrowse
              • 52.123.128.14
              sample.docGet hashmaliciousUnknownBrowse
              • 52.123.129.14
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 52.123.129.14
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 52.123.128.14
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 52.123.129.14
              D#U00e9bito Direto 202503104423..msgGet hashmaliciousUnknownBrowse
              • 52.123.128.14
              message__20250324021254_635CB2FE009599FD_quiltercheviot_com_.emlGet hashmaliciousHTMLPhisherBrowse
              • 52.123.128.14
              PO NO. 2500510 COLORSTAR CHEMICAL INDUSTRIAL CORPORATION.msgGet hashmaliciousSnake KeyloggerBrowse
              • 52.123.129.14
              ENQUIRY - RFQ 674441-76450.xla.xlsxGet hashmaliciousUnknownBrowse
              • 52.123.129.14
              s-part-0012.t-0009.t-msedge.netQuotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              message__20250324021254_635CB2FE009599FD_quiltercheviot_com_.emlGet hashmaliciousHTMLPhisherBrowse
              • 13.107.246.40
              http://www.bing.com/search?q=&form=WMSAUT&ao=1&qs=UT&cvid=baf755dc3b5048988d4e50556017abad&pq=%3C&cc=PT&setlang=pt-PT&wsso=Moderate&qfig=2ce3b160a1de445eae6675508853de5e&addfeaturesnoexpansion=wsbcobaltGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              https://pkns.sidhtech.com/m/?c3Y9bzM2NV8xX29uZSZyYW5kPWRIQnlhM2M9JnVpZD1VU0VSMTUwMzIwMjVVMjIwMzE1Mjk=Get hashmaliciousUnknownBrowse
              • 13.107.246.40
              auuu.xhtmlGet hashmaliciousHTMLPhisherBrowse
              • 13.107.246.40
              ENQUIRY - RFQ 674441-76450.xla.xlsxGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              ENQUIRY - RFQ 674441-76450.xla.xlsxGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              https://waimao-north-star-mail.qiye.163.com/api/j/html?c=https%3A%2F%2F1drv.ms%2Fo%2Fs!AjlMaeoI5pi7f_GXm50IY_RD-sw%3Fe%3DEsmwj4%3Fcid%3Dsite_nqmm3LQS7c9jn-2FWvVcVpMl0NsyUA8yUApYElnaeUm2Ly_xlUzBpbEuLGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              https://offce365.auramisteriosafyr.it.com/CM4kN/Get hashmaliciousHTMLPhisherBrowse
              • 13.107.246.40
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              MICROSOFT-CORP-MSN-AS-BLOCKUSMedical GmbH Order.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.38
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.38
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              http://email.mg.versatilev.com/c/eJwczMFtxSAMANBp4BgZ28Rw4NBL9gDH9CPlt1GCoo5ftQO8txdtHLp4K0EYOWVI4l-l7mnFGljyHiCAUYtkGKW2Hlfp7EdBwAiEEFZmlkWppZyjMWmutIpjeH8uj113neOwZ9Hvtz_Ka87zdvThcHO4hZpISBmtZU3aCSzFnZc5jmZf-vOHHG7-Kuc11E7HcNeh_9dT8DcAAP__O8c2mAGet hashmaliciousHTMLPhisherBrowse
              • 13.107.42.14
              g4za.mips.elfGet hashmaliciousMiraiBrowse
              • 20.95.97.164
              g4za.arm7.elfGet hashmaliciousMiraiBrowse
              • 40.66.156.238
              g4za.arm.elfGet hashmaliciousMiraiBrowse
              • 40.78.204.91
              g4za.spc.elfGet hashmaliciousMiraiBrowse
              • 163.228.96.235
              g4za.sh4.elfGet hashmaliciousMiraiBrowse
              • 20.183.227.44
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              a0e9f5d64349fb13191bc781f81f42e1Medical GmbH Order.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              Quotation.xlsGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              USOE43wtyO.exeGet hashmaliciousDarkVision RatBrowse
              • 13.107.246.40
              HTu5eF4VeI.exeGet hashmaliciousDarkVision RatBrowse
              • 13.107.246.40
              ENQUIRY - RFQ 674441-76450.xla.xlsxGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              ENQUIRY - RFQ 674441-76450.xla.xlsxGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              random(12).exeGet hashmaliciousLummaC StealerBrowse
              • 13.107.246.40
              Payment Advice 24-03-2025.docx.docGet hashmaliciousUnknownBrowse
              • 13.107.246.40
              random(11).exeGet hashmaliciousLummaC StealerBrowse
              • 13.107.246.40
              No context
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
              Category:dropped
              Size (bytes):118
              Entropy (8bit):3.5700810731231707
              Encrypted:false
              SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
              MD5:573220372DA4ED487441611079B623CD
              SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
              SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
              SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
              Malicious:false
              Reputation:high, very likely benign file
              Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              File Type:data
              Category:dropped
              Size (bytes):165
              Entropy (8bit):1.4377382811115937
              Encrypted:false
              SSDEEP:3:KVC+cAmltV:KVC+cR
              MD5:9C7132B2A8CABF27097749F4D8447635
              SHA1:71D7F78718A7AFC3EAB22ED395321F6CBE2F9899
              SHA-256:7029AE5479F0CD98D892F570A22B2AE8302747DCFF3465B2DE64D974AE815A83
              SHA-512:333AC8A4987CC7DF5981AE81238A77D123996DB2C4C97053E8BD2048A64FDCF33E1245DEE6839358161F6B5EEA6BFD8D2358BC4A9188D786295C22F79E2D635E
              Malicious:false
              Reputation:moderate, very likely benign file
              Preview:.user ..j.o.n.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              File Type:data
              Category:dropped
              Size (bytes):165
              Entropy (8bit):1.4377382811115937
              Encrypted:false
              SSDEEP:3:KVC+cAmltV:KVC+cR
              MD5:9C7132B2A8CABF27097749F4D8447635
              SHA1:71D7F78718A7AFC3EAB22ED395321F6CBE2F9899
              SHA-256:7029AE5479F0CD98D892F570A22B2AE8302747DCFF3465B2DE64D974AE815A83
              SHA-512:333AC8A4987CC7DF5981AE81238A77D123996DB2C4C97053E8BD2048A64FDCF33E1245DEE6839358161F6B5EEA6BFD8D2358BC4A9188D786295C22F79E2D635E
              Malicious:true
              Reputation:moderate, very likely benign file
              Preview:.user ..j.o.n.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
              File type:Microsoft Excel 2007+
              Entropy (8bit):7.99804727386034
              TrID:
              • Excel Microsoft Office Open XML Format document (35004/1) 81.40%
              • ZIP compressed archive (8000/1) 18.60%
              File name:PURCHASE ORDER - PO#267759.xlam.xlsx
              File size:654'572 bytes
              MD5:9e6cd3ab7762a50813fb25b114e2b162
              SHA1:df4651b08187b62b0a6c43d60e73d3e6374af545
              SHA256:8700acf7f7771cfc2e0f8b56f76286e12e2a40016db0d41a3bce914b05f464a9
              SHA512:d9181b87416a441e1dc42c9f23cd0162e5c71893b6f747146eb28c74ea742cc13c76e56be11681707fc1e8c374601cc1c1a96681a957afcbb2069661b8888410
              SSDEEP:12288:oknWOYjc44cbx8G3EtPEnGyR/KPAnZOtY4/kNoAZgVyq4X5Udw/WYGHnXVSz:FiN4chUtPmGUyPAZEt/koAZ5q4p0BDHa
              TLSH:92D4238D506FD385EECB4AF34E1A52CC89646E7180ABA6072FDD2CCC09DE68A505C57F
              File Content Preview:PK........~.xZ................[Content_Types].xmlUT......g...g...g.U.n.0....?..........C...&E..X.k.6_ ....w).F..V.......p......b.!*gkv^MX.V8.l[...../......,.l..]_}.4}^{...m.Y....y......h)2s.@...r.b.-......g..T......8......}.*i.e.....j..k% Q./.|'R..L..N...
              Icon Hash:35e58a8c0c8a85b9
              Document Type:OpenXML
              Number of OLE Files:1
              Has Summary Info:
              Application Name:
              Encrypted Document:False
              Contains Word Document Stream:False
              Contains Workbook/Book Stream:False
              Contains PowerPoint Document Stream:False
              Contains Visio Document Stream:False
              Contains ObjectPool Stream:False
              Flash Objects Count:0
              Contains VBA Macros:False
              Author:SHINY
              Last Saved By:X10LUXURY
              Create Time:2010-06-04T08:55:28Z
              Last Saved Time:2023-07-30T22:56:25Z
              Creating Application:Microsoft Excel
              Security:0
              Thumbnail Scaling Desired:false
              Company:Grizli777
              Contains Dirty Links:false
              Shared Document:false
              Changed Hyperlinks:false
              Application Version:15.0300
              General
              Stream Path:\x1oLe10nAtIVe
              CLSID:
              File Type:OpenPGP Public Key
              Stream Size:906170
              Entropy:5.9103421598640855
              Base64 Encoded:False
              Data ASCII:. . Q $ \\ . . < E . F 7 w | . 8 O . 3 W . N L x M - S B D . . \\ q 8 W . 8 . g 9 u . . . . ^ 9 Q . u . b e ! " J S 2 z . 5 ; . W M . K V . d . ) > . $ . r . 0 t . W . l 5 K # M . r . j f . 1 . . . Y a h C L . : . . . I o ! . . g N T b U . g r . 2 H e % n . , . . N # q } O x c ~ . V t . . . E $ X < . V O w Q " w 9 z L 9 } c A ' S ? . r . ( . 7 . 7 [ $ l - L u ) . T < < I f R * = z ) I ` | . T % > + . | + k . . G C . % e Y . . . . c U Z d W K U V . ) . s z r . * \\ . m . . . J ~ } . . L ~ K . / N g $ . W . 6
              Data Raw:98 ff 97 01 03 51 c1 24 80 5c 01 08 3c 45 be 05 46 9f 83 81 c6 37 77 a6 7c 8b 06 8b 38 bb 4f 98 b9 ff f7 d3 8b 33 57 ff d6 83 c0 4e ff e0 4c 8a cc 78 4d 2d 81 d0 53 9e 42 94 92 b8 44 00 14 a6 5c 71 88 38 57 ac be a9 f1 15 38 1b 67 9c 39 b6 75 14 e9 fe 01 00 00 ef ff 5e 39 51 0b 75 da a1 62 98 fa 65 21 c6 e8 22 9c 9b 4a a2 94 9f 53 32 85 7a 12 e8 dd 35 a5 d5 3b 84 7f 57 b5 f8 a8 4d
              General
              Stream Path:k3hD
              CLSID:
              File Type:empty
              Stream Size:0
              Entropy:0.0
              Base64 Encoded:False
              Data ASCII:
              Data Raw:

              Download Network PCAP: filteredfull

              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
              2025-03-24T13:38:39.196627+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.44973913.107.246.40443TCP
              2025-03-24T13:38:44.820092+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.44974013.107.246.40443TCP
              2025-03-24T13:38:44.821357+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.44974113.107.246.40443TCP
              • Total Packets: 204
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Mar 24, 2025 13:38:38.890388966 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:38.890439987 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:38.890789032 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:38.891268015 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:38.891288996 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.196511984 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.196626902 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.200536966 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.200552940 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.200941086 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.211062908 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.252331972 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.492630959 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.492650032 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.492691994 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.492810965 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.492835045 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.492861986 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.492901087 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.522404909 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.522437096 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.522491932 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.522514105 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.522536039 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.522561073 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.595979929 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.596060991 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.596081018 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.596106052 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.596136093 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.596163034 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.616660118 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.616687059 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.616735935 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.616769075 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.616780996 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.616815090 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.630773067 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.630831957 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.630865097 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.630897045 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.630911112 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.630934000 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.697076082 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.697130919 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.697185040 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.697216034 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.697244883 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.697307110 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.721657038 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.721678019 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.721739054 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.721749067 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.721802950 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.721828938 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.744580984 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.744612932 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.744766951 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.744795084 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.744926929 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.770571947 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.770603895 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.770659924 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.770678997 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.770718098 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.770756006 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.818581104 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.818608999 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.818670034 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.818694115 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.818736076 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.818768024 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.839684963 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.839710951 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.839752913 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.839766026 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.839812994 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.839843035 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.867564917 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.867594004 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.867654085 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.867686033 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.867743969 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.867743969 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.907254934 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.907282114 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.907361031 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.907392025 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.907428980 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.907450914 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.931265116 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.931291103 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.931366920 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.931400061 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.931417942 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.931670904 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.959578991 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.959606886 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.959661961 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.959697008 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.959741116 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.959767103 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.982126951 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.982156038 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.982229948 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.982259035 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:39.982285976 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:39.982306957 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.010179996 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.010231018 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.010267019 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.010298014 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.010330915 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.010361910 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.029877901 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.029923916 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.029952049 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.029983044 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.029999018 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.030038118 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.059056997 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.059082985 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.059149027 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.059179068 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.059348106 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.083647966 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.083713055 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.083729982 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.083761930 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.083781004 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.083975077 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.108700037 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.108748913 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.108777046 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.108788967 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.108839035 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.108854055 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.127698898 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.127726078 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.127774954 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.127784967 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.127805948 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.127825022 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.158883095 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.158909082 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.159029961 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.159066916 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.159081936 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.159113884 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.180461884 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.180486917 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.180548906 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.180582047 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.180924892 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.197985888 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.198013067 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.198061943 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.198095083 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.198108912 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.198177099 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.219594955 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.219620943 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.219690084 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.219728947 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.219743967 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.219816923 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.248418093 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.248444080 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.248516083 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.248549938 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.248584032 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.248598099 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.270163059 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.270190001 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.270267963 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.270302057 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.270358086 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.293307066 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.293335915 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.293396950 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.293435097 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.293529034 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.312896013 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.312921047 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.312977076 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.313004971 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.313025951 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.313050985 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.332787037 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.332813025 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.332874060 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.332906008 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.332933903 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.332952976 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.357327938 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.357394934 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.357435942 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.357469082 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.357501030 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.357517958 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.376848936 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.376878023 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.376964092 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.377002001 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.377161980 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.399092913 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.399122953 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.399178982 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.399210930 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.399240017 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.399262905 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.417231083 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.417262077 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.417330027 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.417361021 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.417402983 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.417428970 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.440188885 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.440226078 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.440274000 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.440303087 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.440337896 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.440361977 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.461431980 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.461479902 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.461662054 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.461692095 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.462009907 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.480496883 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.480530977 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.480648041 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.480676889 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.480743885 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.498898983 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.498931885 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.498989105 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.499017000 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.499042988 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.499068975 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.514336109 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.514377117 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.514422894 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.514445066 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.514508009 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.543648005 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.543684959 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.543777943 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.543802977 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.544074059 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.558589935 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.558628082 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.558706999 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.558728933 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.558895111 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.581671953 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.581743956 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.581777096 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.581799984 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.581845999 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.598995924 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.599069118 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.599107981 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.599139929 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.599179983 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.599246979 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.613246918 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.613285065 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.613320112 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.613348961 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.613393068 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.613415003 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.633554935 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.633616924 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.633661985 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.633691072 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.633722067 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.633747101 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.646286011 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.646311998 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.646356106 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.646389008 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.646423101 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.646447897 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.668370962 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.668394089 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.668462992 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.668495893 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.668551922 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.686531067 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.686562061 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.686600924 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.686629057 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.686662912 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.686688900 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.702079058 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.702100992 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.702183008 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.702209949 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.702297926 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.718192101 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.718205929 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.718477964 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.718507051 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.718574047 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.735241890 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.735264063 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.735362053 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.735383987 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.735534906 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.752077103 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.752095938 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.752176046 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.752187967 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.752221107 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.769618034 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.769644976 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.769689083 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.769705057 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.769757032 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.783806086 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.783823967 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.783859015 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.783869982 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.783881903 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.783900976 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.804403067 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.804420948 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.804449081 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.804460049 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.804490089 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.804506063 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.817306042 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.817337990 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.817421913 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.817421913 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.817436934 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.817570925 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.832325935 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.832348108 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.832395077 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.832411051 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.832531929 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.851725101 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.851743937 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.851797104 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.851813078 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.851870060 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.865017891 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.865050077 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.865078926 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.865092993 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.865115881 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.865142107 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.880373001 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.880393028 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.880434036 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.880449057 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.880485058 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.880500078 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.897850990 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.897866011 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.897918940 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.897948980 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.897996902 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.912529945 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.912547112 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.912605047 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.912616968 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.912739992 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.926522017 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.926537037 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.926625967 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.926640987 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.926721096 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.944000006 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.944015980 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.944077015 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.944087982 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.944123983 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.957182884 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.957199097 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.957266092 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.957282066 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.957408905 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.972382069 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.972398043 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.972470045 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.972491980 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.972557068 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989520073 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989536047 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989563942 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989598036 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989614964 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989625931 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989634991 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989737988 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989928961 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989943981 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:40.989959002 CET49739443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:40.989964962 CET4434973913.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.527641058 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.527704954 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.528032064 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.528091908 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.528096914 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.528167009 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.528358936 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.528367043 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.528388977 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.528408051 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.819561005 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.820091963 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.820133924 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.820962906 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.821001053 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.821008921 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.821357012 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.821386099 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:44.822350025 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:44.822355986 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.007827044 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.007937908 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.008234024 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.008280993 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.008280993 CET49740443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.008313894 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.008333921 CET4434974013.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.011827946 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.011847019 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.011910915 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.011917114 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.012204885 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.012259007 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.012281895 CET4434974113.107.246.40192.168.2.4
              Mar 24, 2025 13:38:45.012291908 CET49741443192.168.2.413.107.246.40
              Mar 24, 2025 13:38:45.012298107 CET4434974113.107.246.40192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Mar 24, 2025 13:38:38.777064085 CET5857553192.168.2.41.1.1.1
              Mar 24, 2025 13:38:38.889446020 CET53585751.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 24, 2025 13:38:38.777064085 CET192.168.2.41.1.1.10xed75Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 24, 2025 13:37:33.963956118 CET1.1.1.1192.168.2.40xae05No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
              Mar 24, 2025 13:37:33.963956118 CET1.1.1.1192.168.2.40xae05No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
              Mar 24, 2025 13:37:33.963956118 CET1.1.1.1192.168.2.40xae05No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
              Mar 24, 2025 13:38:38.889446020 CET1.1.1.1192.168.2.40xed75No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
              Mar 24, 2025 13:38:38.889446020 CET1.1.1.1192.168.2.40xed75No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
              Mar 24, 2025 13:38:38.889446020 CET1.1.1.1192.168.2.40xed75No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
              Mar 24, 2025 13:38:38.889446020 CET1.1.1.1192.168.2.40xed75No error (0)shed.dual-low.s-part-0012.t-0009.t-msedge.nets-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
              Mar 24, 2025 13:38:38.889446020 CET1.1.1.1192.168.2.40xed75No error (0)s-part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
              • otelrules.svc.static.microsoft
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973913.107.246.404437876C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              TimestampBytes transferredDirectionData
              2025-03-24 12:38:39 UTC226OUTGET /rules/excel.exe-Production-v19.bundle HTTP/1.1
              Connection: Keep-Alive
              Accept-Encoding: gzip
              User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
              Host: otelrules.svc.static.microsoft
              2025-03-24 12:38:39 UTC493INHTTP/1.1 200 OK
              Date: Mon, 24 Mar 2025 12:38:39 GMT
              Content-Type: text/plain
              Content-Length: 1114783
              Connection: close
              Vary: Accept-Encoding
              Cache-Control: public
              Last-Modified: Sat, 22 Mar 2025 04:56:33 GMT
              ETag: "0x8DD68FDEB406397"
              x-ms-request-id: 1e99e20f-501e-005b-7c62-9cd7f7000000
              x-ms-version: 2018-03-28
              x-azure-ref: 20250324T123839Z-17cccd5449blprb2hC1EWRvwmn0000000asg0000000038u0
              x-fd-int-roxy-purgeid: 0
              X-Cache-Info: L1_T2
              X-Cache: TCP_HIT
              Accept-Ranges: bytes
              2025-03-24 12:38:39 UTC15891INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
              Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
              2025-03-24 12:38:39 UTC16384INData Raw: 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 30 31 31 37 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 38 79 6c 6c 66 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 56 20 56 3d 22 43 6c 69 63 6b 22 20 54 3d 22 57 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32
              Data Ascii: /> </T></R><$!#>100117v0+<?xml version="1.0" encoding="utf-8"?><R Id="100117" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="8yllf" /> </S> <C T="W" I="0" O="false"> <V V="Click" T="W" /> </C> <C T="U32
              2025-03-24 12:38:39 UTC16384INData Raw: 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 37 38 31 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 37 38 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 67 6f 34 74 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 68 6c 76 79 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 49 33 32
              Data Ascii: </C> <T> <S T="2" /> <S T="3" /> </T></R><$!#>10781v1+<?xml version="1.0" encoding="utf-8"?><R Id="10781" V="1" DC="SM" T="Subrule" xmlns=""> <S> <UTS T="1" Id="bgo4t" /> <UTS T="2" Id="bhlvy" /> </S> <C T="I32
              2025-03-24 12:38:39 UTC16384INData Raw: 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
              Data Ascii: <L> <O T="GT"> <L> <S T="1" F="0" /> </L> <R> <V V="1000" T="U32" /> </R> </O> </L> <R> <O T="LE"> <
              2025-03-24 12:38:39 UTC16384INData Raw: 20 49 3d 22 32 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 56 69 64 65 6f 43 61 6c 6c 56 69 64 65 6f 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 53 61 53 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 4f 76 65 72 66 6c 6f 77 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54
              Data Ascii: I="22" O="false" N="FlyoutVideoCallVideo"> <C> <S T="26" /> </C> </C> <C T="U32" I="23" O="false" N="FlyoutSaS"> <C> <S T="27" /> </C> </C> <C T="U32" I="24" O="false" N="FlyoutOverflow"> <C> <S T
              2025-03-24 12:38:39 UTC16384INData Raw: 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 39 30 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 4e 44 42 2e 55 6e 6b 6e 6f 77 6e 2e 43 6f 72 72 75 70 74 69 6f 6e 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 53 3d 22 31 30 30 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 33 39 35 22 20 47 3d 22 7b 32 61 64 66 38 65 32 33 2d 30 61 66 39 2d
              Data Ascii: coding="utf-8"?><R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns=""> <S> <Etw T="1" E="395" G="{2adf8e23-0af9-
              2025-03-24 12:38:39 UTC16384INData Raw: 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 33 22 20 49 64 3d 22 62 70 66 79 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 50 68 6f 74 6f 53 69 7a 65 49 6e 42 79 74 65 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55
              Data Ascii: "TelemetryShutdown" /> <UTS T="3" Id="bpfy1" /> <F T="4"> <O T="GT"> <L> <S T="3" F="PhotoSizeInBytes" /> </L> <R> <V V="0" T="U64" /> </R> </O> </F> </S> <C T="U
              2025-03-24 12:38:39 UTC16384INData Raw: 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 65 76 65 6e 74 49 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 33 35 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 74 63 69 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20
              Data Ascii: <L> <S T="4" F="eventId" /> </L> <R> <V V="135" T="I32" /> </R> </O> </F> <F T="7"> <O T="EQ"> <L> <S T="5" F="tcid" /> </L> <R> <V
              2025-03-24 12:38:39 UTC16384INData Raw: 0d 0a 20 20 20 20 3c 46 20 54 3d 22 31 30 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 46 69 6c 65 50 72 6f 74 65 63 74 69 6f 6e 53 74 61 74 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 35 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 4f 66 54 68 72 6f 77 6e 45 78 63 65 70 74 69 6f 6e 22 3e 0d
              Data Ascii: <F T="10"> <O T="EQ"> <L> <S T="3" F="FileProtectionState" /> </L> <R> <V V="5" T="U32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="CountOfThrownException">
              2025-03-24 12:38:39 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 72 65 73 75 6c 74 73 5f 49 73 4e 75 6c 6c 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20
              Data Ascii: <S T="5" F="results_IsNull" /> </L> <R> <V V="false" T="B" /> </R> </O> </L> <R> <O T="EQ"> <L>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44974013.107.246.404437876C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              TimestampBytes transferredDirectionData
              2025-03-24 12:38:44 UTC214OUTGET /rules/rule120607v1s19.xml HTTP/1.1
              Connection: Keep-Alive
              Accept-Encoding: gzip
              User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
              Host: otelrules.svc.static.microsoft
              2025-03-24 12:38:45 UTC470INHTTP/1.1 200 OK
              Date: Mon, 24 Mar 2025 12:38:44 GMT
              Content-Type: text/xml
              Content-Length: 204
              Connection: close
              Cache-Control: public, max-age=604800, immutable
              Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
              ETag: "0x8DC582BB6C8527A"
              x-ms-request-id: cb52e497-801e-0035-58da-9b752a000000
              x-ms-version: 2018-03-28
              x-azure-ref: 20250324T123844Z-17cccd5449bzw64jhC1EWRz2340000000asg000000003866
              x-fd-int-roxy-purgeid: 0
              X-Cache: TCP_HIT
              Accept-Ranges: bytes
              2025-03-24 12:38:45 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
              Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974113.107.246.404437876C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              TimestampBytes transferredDirectionData
              2025-03-24 12:38:44 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
              Connection: Keep-Alive
              Accept-Encoding: gzip
              User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
              Host: otelrules.svc.static.microsoft
              2025-03-24 12:38:45 UTC494INHTTP/1.1 200 OK
              Date: Mon, 24 Mar 2025 12:38:44 GMT
              Content-Type: text/xml
              Content-Length: 2128
              Connection: close
              Vary: Accept-Encoding
              Cache-Control: public, max-age=604800, immutable
              Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
              ETag: "0x8DC582BA41F3C62"
              x-ms-request-id: 0fe88ecf-101e-007a-32da-9b047e000000
              x-ms-version: 2018-03-28
              x-azure-ref: 20250324T123844Z-17cccd5449b6sxz8hC1EWRrtxw0000000am000000000ergd
              x-fd-int-roxy-purgeid: 0
              X-Cache: TCP_HIT
              Accept-Ranges: bytes
              2025-03-24 12:38:45 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
              Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


              050100s020406080100

              Click to jump to process

              050100s0.0050100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:1
              Start time:08:37:29
              Start date:24/03/2025
              Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
              Wow64 process (32bit):true
              Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
              Imagebase:0x330000
              File size:53'161'064 bytes
              MD5 hash:4A871771235598812032C822E6F68F19
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:false
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:16
              Start time:08:38:33
              Start date:24/03/2025
              Path:C:\Windows\splwow64.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\splwow64.exe 12288
              Imagebase:0x7ff76e030000
              File size:163'840 bytes
              MD5 hash:77DE7761B037061C7C112FD3C5B91E73
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:false
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly